IT-06 Security Incident Reporting
Revision 2 · Effective 2026-02-09
1 Purpose
This procedure explains how to recognize and report a security incident and how IT classifies and responds to it. Fast reporting limits damage; nobody is disciplined for reporting a mistake promptly.
2 Scope
This procedure applies to all employees and contractors and to any event involving Tallgrass accounts, devices, networks, machine-tool controls or data, including personal phones used for company email.
3 Definitions
- Security incident: any event that may threaten the confidentiality, integrity or availability of company systems or data, whether confirmed or only suspected.
- Phishing: an email, text or call that tries to trick you into revealing a password, opening a malicious file or sending money or data.
- Severity level: the S1 to S4 rating IT assigns to set the response target (section 6).
4 Responsibilities
- Everyone reports suspected incidents immediately and follows IT's instructions.
- IT (Sam Kettering, IT Lead; Ava Lund, IT Technician) triages, assigns severity, contains and resolves incidents, and keeps the incident record.
- The IT Lead decides on outside notifications together with the President and, where export-controlled data is involved, the Contracts & Export Compliance Manager.
5 How to report
5.1 Phishing email
Use the Report button in Outlook (desktop, web or the Outlook mobile app) and choose "Phishing". This sends the message to IT and removes it from your inbox. Do not forward the message to coworkers, reply to it, click its links or open attachments. If you already clicked a link, opened an attachment or entered your password, call the help desk at ext. 2210 right away; this is handled as at least an S2 incident.
5.2 Lost or stolen devices
Report a lost or stolen company laptop, company phone, IT-issued encrypted USB drive, FIDO2 security key, or a personal phone that has company email, to IT within 1 hour of noticing it is missing. IT will lock or wipe the device through Intune; for personal phones, only company data in the Outlook and Teams apps is wiped. Stolen devices are also reported to the police and the report number is added to the ticket.
5.3 Everything else
Report other suspected incidents to the help desk at helpdesk@tallgrasspc.com or ext. 2210 during help desk hours. Examples include unexpected MFA prompts, pop-ups demanding payment, files that suddenly will not open or have changed names, a coworker's account sending odd messages, Confidential or Restricted data sent to the wrong person (IT-05), or a stranger plugging equipment into the network.
5.4 After hours
Outside help desk hours (Monday to Friday, 6:00 to 16:30), or whenever the help desk does not answer for an urgent issue, call the IT after-hours on-call number, 316-555-0142. Use it for lost or stolen devices, suspected account compromise, ransomware, and outages affecting production. Routine requests wait for the next business day.
5.5 Do not investigate yourself
Do not try to investigate, clean up or "test" an incident. Do not run antivirus tools, delete emails or files, or log in to other accounts to check them. If you suspect malware, disconnect the computer from the network (unplug the cable or turn off Wi-Fi) but leave it powered on so evidence is preserved, and wait for IT.
5.6 Export-controlled data
If an incident may involve ITAR or other export-controlled data, also report it to the Empowered Official immediately, as required by EXP-01.
6 Severity levels and response targets
IT assigns a severity when the report is received. Response target is the time for IT to begin active work on the incident, at any hour for S1 and S2.
| Level | Description | Examples | Response target |
|---|---|---|---|
| S1 Critical | Active attack, or a stopped business function | Ransomware on any system; ERP or DNC server unavailable due to suspected attack; confirmed theft of export-controlled data | 30 minutes |
| S2 High | Confirmed compromise limited to one user or device | Password entered on a phishing page; lost laptop or phone; Restricted data emailed externally by mistake | 2 hours |
| S3 Medium | Suspicious activity without confirmed compromise | Unexpected MFA prompt that was denied; malware blocked by Defender; Confidential file shared with the wrong coworker | 1 business day |
| S4 Low | Policy issue or reported phishing with no interaction | Phishing reported with the Report button and not clicked; unapproved software found | 3 business days |
IT may raise or lower a severity as facts become known.
7 After an incident
For S1 and S2 incidents, IT holds a post-incident review within 10 business days and records the cause and corrective actions. If Controlled Unclassified Information or covered defense information may have been affected, the IT Lead, with the Contracts & Export Compliance Manager, makes any required DFARS 252.204-7012 report to the Department of Defense within 72 hours of discovery. Customer notifications are decided by the President.
8 Records
Each incident is recorded as a help desk ticket in the "Security Incident" category, including severity, timeline, actions and review findings. Incident tickets are retained for at least 3 years.
9 Revision history
| Rev | Date | Change | Approved by |
|---|---|---|---|
| 1 | 2023-05-15 | First issue. | Sam Kettering |
| 2 | 2026-02-09 | Added Outlook Report button; lost or stolen devices reported within 1 hour; added S1-S4 severity levels with response targets; added after-hours on-call number. | Sam Kettering |