About Services Technology Clients Blog Contact
HomeLegal

Information Security Incident Management

Legal documentCourtesy translation — the Spanish version governs · Last updated: March 2026

Purpose

To set out a clear and efficient procedure for identifying, assessing, responding to and resolving information security incidents that could affect the confidentiality, integrity or availability of the data of éxodo bpo and its clients.

Scope

This policy applies to all employees, contractors and suppliers of éxodo bpo who have access to information systems, client data or the company's technology infrastructure.

What counts as an incident

An information security incident is any event that compromises, or could compromise:

  • La confidentiality of personal, commercial or client data.
  • La integrity of the information processed or stored.
  • La availability of operational systems or services.

Examples: unauthorised access, lost or stolen devices, malware, phishing, human error exposing data, or security failures in systems.

Handling procedure

  • Detection and reporting: anyone who detects or suspects an incident must report it immediately to the security team at hola@exodobpo.com or through the designated internal channel.
  • Classification and assessment: the security team classifies the incident by severity (low, medium, high, critical) and assesses the potential impact.
  • Containment: immediate measures are taken to limit the scope of the incident and stop it spreading.
  • Investigation: the root cause, the extent of the impact and the data or systems affected are established.
  • Notification: the affected client is notified without undue delay. Where required, the supervisory authority is notified in accordance with applicable law.
  • Remediation: the corrective actions needed to resolve the incident and prevent recurrence are implemented.
  • Documentation: every incident is documented with its analysis, the actions taken, the lessons learned and the improvements made.

Response times

  • Critical: immediate response (under 1 hour). Client notified within 4 hours.
  • High: response within 2 hours. Client notified within 8 hours.
  • Medium: response within 4 hours. Client notified within 24 hours.
  • Low: response within 24 hours. Reported in the periodic summary.

Continuous improvement

Every incident is examined in a post-incident review to find opportunities to improve processes, technology or training. The findings feed into the information security plan.

Contact

To report a security incident: hola@exodobpo.com

Next document
Ethics and Integrity
Legal — éxodo bpo