Security Incident Management Policy

For publication

1. Purpose

This document is the property of Tangoo S.r.l. with registered offices in Via Lentasio 9, 20122, Milano, Tax Code/VAT No. IT02143630685

The purpose of this policy is to establish requirements and responsibilities to detect, report, analyze and respond to information security incidents in a more coordinated, timely, and effective manner.

This version of the policy is functional to publication to the benefit of vendors, clients and/or other counterparts.

This document should be consulted in conjunction with Tangoo S.r.l. Data Breach Policy, as it clarifies and provides adequate instructions in relation to events involving personal data, and on the actions to be taken in the event of a Data Breach. For more information and/or to consult the Data Breach Policy, please contact: privacy@tangoo.com.

2. Scope

This policy applies to all Tangoo S.r.l and its entities staff/users that are directly or indirectly employed by and third parties including data processing and process control systems, that have or using information and/or facilities owned by Tangoo S.r.l and its entities.

Note: This policy applies to both enterprise and cloud platforms.

3. Role and Responsibilities

Each role involved in this policy shall have main responsibilities as follows:

Information Security Steering Committee

  • Oversee, approve the Information Security Incident Management Policy and ensure all capabilities exist to guarantee that this policy is implemented
  • Evaluate and support the readiness of incident management
  • Review changes to the Information Security Incident Management Policy prior to final approval
  • Evaluate, review, and approve exceptions (waivers) to this cybersecurity policy
  • Analyse recommendations to update cybersecurity policies received from the Cybersecurity Sector

IT Department

  • Develop, maintain, enforce, and communicate the Information Security Incident Management Policy
  • Coordinate with different departments like HR, Legal etc. in order to make sure the Information Security Incident Management Policy is in alignment with all other policies and procedures and control implementation
  • Monitor information systems and respond to cybersecurity events
  • Establish security orchestration and automation services
  • Contain the impact of an attack or incident, breach preserving forensic evidence, and restoring related business/IT services
  • Coordinate and involve the national authorities and law enforcement agencies when needed for any cybersecurity events
  • Develop a cybersecurity awareness and training program considering the Information Security Incident Management Policy and oversee its implementation with the partnership of Shared Services (HR Department)

Legal Team

  • Ensure that Information Security Incident Management Policy is compliant with the existing legal and contractual requirements
  • Consult with law enforcement agencies if needed
  • Guide the laws, regulations, contractual requirements, or other aspects of the incident to help guide the response.
  • Assist in Cyber forensics court cases and appearances
  • Develop internal procedures with regard to people, process and technology in order to comply with the policy.

Corporate Communication

  • Develop information-disclosure policies and practices
  • Develop internal procedures with regard to people, process and technology in order to comply with the policy.

Department Managers

  • Ensure department internal procedures are aligned with this policy where applicable

4. Policy Statements

This policy shall be applied as soon as information assets or information systems are suspected to be or are affected by an adverse event that is likely to lead to a security incident.

The requirements for Cybersecurity incidents and threat management shall be reviewed periodically by IT Department.

An information security incident may include, but not limited to:

  • The loss or theft of information.
  • Leaking sensitive information to social media websites.
  • The transfer of information to those who are not entitled to receive that information.
  • Attempts (either failed or successful) to gain unauthorized access to information storage or a computer system.
  • Changes to information or information system hardware, firmware, or software characteristics without the relevant Tangoo S.r.l and its entities’ parties knowledge, instruction, or consent;
  • Unwanted disruption or denial of service to an information system.
  • The unauthorized storage of information or use of an information system for the processing by any person.
  • The loss or theft of physical hardware.
  • Denial of Service/Distributed Denial of Service attack
  • Excessive Port Scans
  • Virus Outbreak
  • Firewall Breach
  • Security and Protection Access Control Failure
  • Unauthorized Physical Access
  • Password sharing/compromise, etc.

4.1 Reporting Information Security Events

4.1.1. All users shall understand and be able to identify that any unexpected or unusual behavior on the workstation could potentially be a software malfunction. Security events may include, but are not limited to:

  • Uncontrolled system changes.
  • Access violations (e.g. password sharing).
  • Breaches of Security and Protection.
  • Non-compliance with Tangoo S.r.l and its entities information security policies;
  • Systems being hacked or manipulated.
  • If an event is detected, users shall perform the following:
  • Note the symptoms and any error messages on screen.
  • Disconnect the workstation from the network if an infection is suspected
  • Not using any removable media (for example USB memory sticks) that may also have been infected.

4.1.2. All users shall immediately report all suspected security events to the IT Team. The following information shall be supplied, but not limited to:

  • Contact name and number of people reporting the incident.
  • The type of information or equipment involved.
  • Whether the loss of the information puts any person or other data at risk.
  • Location of the incident.
  • Inventory numbers of any equipment were affected.
  • Date and time the security incident occurred.
  • Location of data or equipment affected.
  • Type and circumstances of the incident.

4.1.3. IT Department in coordination with HR Department – Shared Services shall conduct information security awareness for users as part of the induction and periodic basis during job tenure to make employees aware of how to report any detected information security event.

4.2 Reporting Information Security Weaknesses

4.2.1. All Tangoo S.r.l and its entities’ employees and contractors shall report any observed or suspected information security weaknesses in systems or services.

4.2.2. Information security weaknesses shall be reported to the IT Team as quickly as possible and the incident response and escalation procedure shall be followed. Security weaknesses may include, but are not limited to:

  • Inadequate firewall or antivirus protection.
  • System malfunctions or overloads.
  • Malfunctions of software applications.
  • Human errors.

4.3 Incident Response Procedures

4.3.1. The IT Department shall establish information security incident response plans and escalation procedures.

4.3.2. Management responsibilities and appropriate procedures shall be established to ensure an effective response against information security events.

4.3.3. The IT Department shall have overall responsibility and accountability to build an efficient and effective information security incident response capability at Tangoo S.r.l.

4.3.4. Ensure that security incidents response plans and contact information within the Tangoo S.r.l and Its entities in a way that is compatible with the telework situation and to ensure the ability to communicate and the preparedness of the incident response teams.

4.3.5. The IT Department shall decide when events are classified as an incident and determine the most appropriate response.

4.3.6. All Tangoo S.r.l and Its entities employees and contractors shall understand their responsibility towards reporting security incidents that have known or potential impact on information security.

4.3.7. Information security incidents should be responded to following the documented procedure that may include but not limited to:

  • Collecting evidence as soon as possible after the occurrence.
  • Conducting information security forensics analysis.
  • Escalation, as required.
  • Ensuring that all involved response activities are properly logged for later analysis.
  • Communicating the existence of the information security incident or any relevant details thereof to other internal and external people or organizations with a need-to-know.
  • Dealing with information security weakness(es) found to cause or contribute to the incident.
  • Once the incident has been successfully dealt with, formally closing and recording it.
  • Post-incident analysis to identify the source of the incident.

4.3.8. The IT Department shall develop an information security incident management process and procedure. This process shall include, but not limited to:

  • Identification of the incident, analysis to ascertain its cause and vulnerabilities it exploited.
  • Collecting and handling threat intelligence feeds.
  • Limiting or restricting the further impact of the incident.
  • Tactics for containing the incident.
  • Corrective action to repair and prevent recurrence.
  • Communication across Tangoo S.r.l and its entities to those affected.
  • Collection of any evidence.
  • Roles & Responsibilities of each incident handling team.
  • Level of Authority of each team.
  • Requirements for reporting certain types of incidents.
  • Requirements and guidelines for external communications and information sharing.
  • And the handoff and escalation points in the incident management process.

4.3.9. Staff with incident management responsibilities shall be appropriately trained and qualified.

4.3.10. IT Department members shall be aware of processes for securing potential evidence such as technology assets (e.g., PCs), audit logs, audit trails, voice mail, and e-mail accounts for analysis and as potential evidence in legal proceedings.

4.3.11. The actions required to recover from the information security incident shall be under formal control. Only identified and authorized staff shall have access to the affected information systems during the incident, and all the remedial actions shall be documented in as much detail as possible.

4.3.12. The incident response procedure shall be a seamless continuation of the event reporting process and shall include contingency plans to ensure the continuing operation of Tangoo S.r.l and its entities during the incident.

4.3.13. All incidents shall be logged in the IT system with adequate details to establish a quick response mechanism to information security incidents.

4.3.14. Tangoo S.r.l and its entities shall deploy, where possible, a monitoring control system to detect any information security incidents.

4.3.15. In case a major incident is identified such as breach of sensitive data, Hacking, criminal activity; Tangoo S.r.l and its entities with help of the Legal team may notify appropriate law enforcement authorities

4.3.16. On the resolution of an information security incident or weakness, the IT Department shall prepare a report that includes detailed problem analysis, action(s) taken, and recommendations for corrective action or improvements.

4.3.17. If public disclosure of an information security incident is required, then such information shall only be released by the Tangoo S.r.l Management.

4.4 Information Security Incidents Analysis

4.4.1. The IT Department shall establish criteria for information incident qualification, classification, and prioritization.

4.4.2. The IT Team shall evaluate each reported information security event using the agreed information security incident and event classification criteria and decide whether the event should be classified as an information security incident.

4.4.3. Potential information security incidents shall be communicated to relevant personnel who shall assist in corrective actions to be taken.

4.4.4. The IT Team shall be responsible for keeping track of the status of the incident by following up with relevant parties or people and handling queries related to the status of an incident. All security incidents shall be recorded and allocated, an incident number for tracking and future reference. The record may include, but not limited to:

  • Causes: whether direct and indirect, which led to the incident happening.
  • Impact: which information systems suffered during the incident?
  • Actions are taken by the user and response team to report and manage the incident.
  • Level of damage: what were the losses caused?
  • Date and time of occurrence.

4.4.5. IT Department shall develop a plan to recover the organization’s social media accounts and to deal with cyber incidents

4.4.6. The post-incident information for critical incidents shall be collated and reviewed regularly by the information Security Steering Committee. Any changes to the process made as a result of the post-incident review shall be formally noted.

4.4.7. Tangoo S.r.l and its entities shall consider information held within a cloud service, which can serve as evidence. When agreed, Tangoo S.r.l shall:

  • Document the information that can serve as evidence (and provide such documentation to customers)
  • Establish procedures for retaining such information, including retention period
  • Establish procedures by which a customer can request and obtain access to such information. Where there are costs and charges associated with such access, the customer shall be informed.
  • Ensure compliance of information recording and retention with the requirements of the jurisdiction that applies to the cloud service.
  • Maintain Infrastructure logs (Virtual & Physical).
  • Ensure protection measures against collateral damage during a forensic investigation on shared resources if available.
  • Ensure protection of sensitive information from other tenants during a forensic investigation on shared resources.
  • Ensure availability of competent personnel supporting forensic investigations,
  • Establish procedures and measures to strictly isolate customer-related evidence data if available.

4.5 Learning From Information Security Incidents

4.5.1. The IT Department shall evaluate information gained from the information security incident to identify possible sources of incidents.

4.5.2. The information gained from the evaluation of information security incidents shall be used to enhance or add new controls to limit the frequency, damage, and cost of future occurrences.

4.5.3. A process of continual improvement shall be applied to the response, to monitor, evaluate, and overall management of information security incidents

4.5 Learning From Information Security Incidents

4.6.1. The IT Department shall hire Digital Forensics resources that can identify, document, and maintain rules for collection, retention, and presentation of evidence laid down in the relevant jurisdictions.

4.6.2. If an incident may require information to be collected for an investigation, strict rules shall be adhered to. The collection of evidence for a potential investigation shall be approached with care.

4.6.3. The evidence rules shall cover:

  • Admissibility of evidence: whether or not the evidence can be used in court.
  • Weight of evidence: the quality and completeness of the evidence.

4.6.4. Digital Forensics resources shall be contacted immediately for guidance and strict processes shall be followed for the collection of forensic evidence.

4.6.5. The original media and the log (if this is not possible, at least one mirror image or copy) shall be kept securely and untouched.

4.6.6. Any forensic work shall only be performed on copies of the evidential material. The integrity of evidential material shall be protected.

4.6.7. Proper chain of custody of evidence shall be maintained from the incident reporting till the end of prosecution and return of the evidence to the owner/custodian.

5. Policy Enforcement and Compliance

Compliance with this policy is mandatory and Tangoo S.r.l and its entities department managers shall ensure continuous compliance monitoring within their department. Compliance with the statements of this policy is a matter of periodic review.

Any breach of this policy may constitute a security violation and gives Tangoo S.r.l and its entities the right to conduct disciplinary and/or legal action, up to and including termination of employment or business relationship.

Disciplinary action will be dependent upon the severity of the violation which will be determined by the investigations.

Disclaimer

This document constitutes the public version of the Incident Management Policy adopted by Tangoo S.r.l. Its content has been prepared for information and transparency purposes towards clients, partners, data subjects and stakeholders, and sets out exclusively the general principles, objectives and guiding criteria of the incident management process.

For security and confidentiality reasons, this version does not include detailed operational procedures, references to infrastructure, systems and technical configurations, the names and contact details of response team members, escalation thresholds, runbooks, or any further information whose disclosure could compromise the effectiveness of the security measures in place.

This document does not constitute an assumption of contractual obligations nor a guarantee of specific service levels, save as otherwise agreed in separate agreements. Tangoo S.r.l. reserves the right to amend this policy at any time; the version published at https://www.tangoo.com/security-incident-management shall prevail, the version number and date of last update of which are set out below.

Version 1.1 — Last updated: 24/07/2026