Cybersecurity Incident Response & Data Breach Policy
How security incidents and personal-data breaches are detected, contained and notified.
DRAFT — SUBJECT TO REVIEW BY QUALIFIED EGYPTIAN LEGAL COUNSEL BEFORE PRODUCTION USE.
Version
0.1.0
Effective date
2026-08-24
Last updated
2026-08-24
Document owner
Egypt One — Information Security
Approval status
DRAFT
Applicable languages
EN, AR
Category
Security & resilience
Counsel review
Required
1.Detection and triage
Monitoring and reports feed a severity-graded triage. A named incident commander is assigned for high-severity events.
2.Containment and recovery
Containment, eradication, recovery from verified backups, and a post-incident review with corrective actions.
3.Notification
Where a personal-data breach is likely to affect individuals, notification to those individuals and any competent authority follows the timelines applicable under Egyptian law, to be confirmed by counsel.
Change history
v0.1.0 · 2026-08-24 — Initial draft prepared for legal review.