For publication
This document is the property of Tangoo S.r.l. with registered offices in Via Lentasio 9, 20122, Milano, Tax Code/VAT No. IT02143630685
The purpose of this policy is to establish requirements and responsibilities to detect, report, analyze and respond to information security incidents in a more coordinated, timely, and effective manner.
This version of the policy is functional to publication to the benefit of vendors, clients and/or other counterparts.
This document should be consulted in conjunction with Tangoo S.r.l. Data Breach Policy, as it clarifies and provides adequate instructions in relation to events involving personal data, and on the actions to be taken in the event of a Data Breach. For more information and/or to consult the Data Breach Policy, please contact: privacy@tangoo.com.
This policy applies to all Tangoo S.r.l and its entities staff/users that are directly or indirectly employed by and third parties including data processing and process control systems, that have or using information and/or facilities owned by Tangoo S.r.l and its entities.
Note: This policy applies to both enterprise and cloud platforms.
Each role involved in this policy shall have main responsibilities as follows:
Information Security Steering Committee
IT Department
Legal Team
Corporate Communication
Department Managers
This policy shall be applied as soon as information assets or information systems are suspected to be or are affected by an adverse event that is likely to lead to a security incident.
The requirements for Cybersecurity incidents and threat management shall be reviewed periodically by IT Department.
An information security incident may include, but not limited to:
4.1 Reporting Information Security Events
4.1.1. All users shall understand and be able to identify that any unexpected or unusual behavior on the workstation could potentially be a software malfunction. Security events may include, but are not limited to:
4.1.2. All users shall immediately report all suspected security events to the IT Team. The following information shall be supplied, but not limited to:
4.1.3. IT Department in coordination with HR Department – Shared Services shall conduct information security awareness for users as part of the induction and periodic basis during job tenure to make employees aware of how to report any detected information security event.
4.2 Reporting Information Security Weaknesses
4.2.1. All Tangoo S.r.l and its entities’ employees and contractors shall report any observed or suspected information security weaknesses in systems or services.
4.2.2. Information security weaknesses shall be reported to the IT Team as quickly as possible and the incident response and escalation procedure shall be followed. Security weaknesses may include, but are not limited to:
4.3 Incident Response Procedures
4.3.1. The IT Department shall establish information security incident response plans and escalation procedures.
4.3.2. Management responsibilities and appropriate procedures shall be established to ensure an effective response against information security events.
4.3.3. The IT Department shall have overall responsibility and accountability to build an efficient and effective information security incident response capability at Tangoo S.r.l.
4.3.4. Ensure that security incidents response plans and contact information within the Tangoo S.r.l and Its entities in a way that is compatible with the telework situation and to ensure the ability to communicate and the preparedness of the incident response teams.
4.3.5. The IT Department shall decide when events are classified as an incident and determine the most appropriate response.
4.3.6. All Tangoo S.r.l and Its entities employees and contractors shall understand their responsibility towards reporting security incidents that have known or potential impact on information security.
4.3.7. Information security incidents should be responded to following the documented procedure that may include but not limited to:
4.3.8. The IT Department shall develop an information security incident management process and procedure. This process shall include, but not limited to:
4.3.9. Staff with incident management responsibilities shall be appropriately trained and qualified.
4.3.10. IT Department members shall be aware of processes for securing potential evidence such as technology assets (e.g., PCs), audit logs, audit trails, voice mail, and e-mail accounts for analysis and as potential evidence in legal proceedings.
4.3.11. The actions required to recover from the information security incident shall be under formal control. Only identified and authorized staff shall have access to the affected information systems during the incident, and all the remedial actions shall be documented in as much detail as possible.
4.3.12. The incident response procedure shall be a seamless continuation of the event reporting process and shall include contingency plans to ensure the continuing operation of Tangoo S.r.l and its entities during the incident.
4.3.13. All incidents shall be logged in the IT system with adequate details to establish a quick response mechanism to information security incidents.
4.3.14. Tangoo S.r.l and its entities shall deploy, where possible, a monitoring control system to detect any information security incidents.
4.3.15. In case a major incident is identified such as breach of sensitive data, Hacking, criminal activity; Tangoo S.r.l and its entities with help of the Legal team may notify appropriate law enforcement authorities
4.3.16. On the resolution of an information security incident or weakness, the IT Department shall prepare a report that includes detailed problem analysis, action(s) taken, and recommendations for corrective action or improvements.
4.3.17. If public disclosure of an information security incident is required, then such information shall only be released by the Tangoo S.r.l Management.
4.4 Information Security Incidents Analysis
4.4.1. The IT Department shall establish criteria for information incident qualification, classification, and prioritization.
4.4.2. The IT Team shall evaluate each reported information security event using the agreed information security incident and event classification criteria and decide whether the event should be classified as an information security incident.
4.4.3. Potential information security incidents shall be communicated to relevant personnel who shall assist in corrective actions to be taken.
4.4.4. The IT Team shall be responsible for keeping track of the status of the incident by following up with relevant parties or people and handling queries related to the status of an incident. All security incidents shall be recorded and allocated, an incident number for tracking and future reference. The record may include, but not limited to:
4.4.5. IT Department shall develop a plan to recover the organization’s social media accounts and to deal with cyber incidents
4.4.6. The post-incident information for critical incidents shall be collated and reviewed regularly by the information Security Steering Committee. Any changes to the process made as a result of the post-incident review shall be formally noted.
4.4.7. Tangoo S.r.l and its entities shall consider information held within a cloud service, which can serve as evidence. When agreed, Tangoo S.r.l shall:
4.5 Learning From Information Security Incidents
4.5.1. The IT Department shall evaluate information gained from the information security incident to identify possible sources of incidents.
4.5.2. The information gained from the evaluation of information security incidents shall be used to enhance or add new controls to limit the frequency, damage, and cost of future occurrences.
4.5.3. A process of continual improvement shall be applied to the response, to monitor, evaluate, and overall management of information security incidents
4.5 Learning From Information Security Incidents
4.6.1. The IT Department shall hire Digital Forensics resources that can identify, document, and maintain rules for collection, retention, and presentation of evidence laid down in the relevant jurisdictions.
4.6.2. If an incident may require information to be collected for an investigation, strict rules shall be adhered to. The collection of evidence for a potential investigation shall be approached with care.
4.6.3. The evidence rules shall cover:
4.6.4. Digital Forensics resources shall be contacted immediately for guidance and strict processes shall be followed for the collection of forensic evidence.
4.6.5. The original media and the log (if this is not possible, at least one mirror image or copy) shall be kept securely and untouched.
4.6.6. Any forensic work shall only be performed on copies of the evidential material. The integrity of evidential material shall be protected.
4.6.7. Proper chain of custody of evidence shall be maintained from the incident reporting till the end of prosecution and return of the evidence to the owner/custodian.
Compliance with this policy is mandatory and Tangoo S.r.l and its entities department managers shall ensure continuous compliance monitoring within their department. Compliance with the statements of this policy is a matter of periodic review.
Any breach of this policy may constitute a security violation and gives Tangoo S.r.l and its entities the right to conduct disciplinary and/or legal action, up to and including termination of employment or business relationship.
Disciplinary action will be dependent upon the severity of the violation which will be determined by the investigations.
Disclaimer
This document constitutes the public version of the Incident Management Policy adopted by Tangoo S.r.l. Its content has been prepared for information and transparency purposes towards clients, partners, data subjects and stakeholders, and sets out exclusively the general principles, objectives and guiding criteria of the incident management process.
For security and confidentiality reasons, this version does not include detailed operational procedures, references to infrastructure, systems and technical configurations, the names and contact details of response team members, escalation thresholds, runbooks, or any further information whose disclosure could compromise the effectiveness of the security measures in place.
This document does not constitute an assumption of contractual obligations nor a guarantee of specific service levels, save as otherwise agreed in separate agreements. Tangoo S.r.l. reserves the right to amend this policy at any time; the version published at https://www.tangoo.com/security-incident-management shall prevail, the version number and date of last update of which are set out below.
Version 1.1 — Last updated: 24/07/2026