Skip to main content

INCIDENT RESPONSE AND VULNERABILITY MANAGEMENT POLICY

ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland

Version: 1.0
Effective Date: 16 June 2026


1. Purpose

The purpose of this Incident Response and Vulnerability Management Policy is to establish procedures for identifying, reporting, investigating, responding to and resolving security incidents and vulnerabilities affecting ECOMMIGO GROUP Sp. z o.o.

The Company recognizes that effective incident management is essential to protecting customer information, maintaining service availability and minimizing operational risk.


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Consultants
  • Management Board members
  • Service providers with access to Company systems

The policy covers:

  • Cloud infrastructure
  • Applications
  • Databases
  • End-user devices
  • Internal networks
  • Customer-facing services
  • Third-party integrations

3. Definitions

Security Incident

A security incident is any event that may compromise the confidentiality, integrity or availability of information assets.

Examples include:

  • Unauthorized access
  • Credential compromise
  • Malware infections
  • Data leakage
  • Infrastructure attacks
  • Denial-of-service attacks
  • Suspicious account activity
  • Accidental exposure of sensitive information

Vulnerability

A vulnerability is a weakness in software, hardware, processes or configurations that could be exploited to compromise security.


4. Incident Reporting

All personnel are required to report suspected security incidents immediately upon discovery.

Examples of reportable events include:

  • Suspicious login activity
  • Unexpected system behavior
  • Security alerts
  • Data exposure
  • Unauthorized access attempts
  • Malware detections

Reports shall be escalated to Company management for review and assessment.


5. Incident Response Process

The Company follows a structured response process.

Identification

Potential incidents are identified through:

  • Monitoring systems
  • Automated alerts
  • User reports
  • Infrastructure logs
  • Operational reviews

Assessment

The incident is evaluated to determine:

  • Severity
  • Business impact
  • Scope
  • Urgency

Containment

Actions are taken to limit further impact and prevent escalation.

Containment actions may include:

  • Disabling accounts
  • Restricting access
  • Isolating systems
  • Blocking malicious traffic

Eradication

The root cause of the incident is identified and removed.

This may include:

  • Removing malicious software
  • Resetting credentials
  • Applying security patches
  • Correcting misconfigurations

Recovery

Affected systems are restored to normal operation.

Recovery activities may include:

  • Restoring backups
  • Re-enabling services
  • Monitoring for recurring activity

Lessons Learned

Following resolution, incidents are reviewed to identify improvements and corrective actions.


6. Vulnerability Management

The Company maintains procedures for identifying and addressing security vulnerabilities.

Activities include:

  • Software updates
  • Security patch management
  • Infrastructure reviews
  • Configuration assessments
  • Access reviews
  • Security monitoring

Known vulnerabilities are prioritized according to risk and business impact.

Critical vulnerabilities are addressed as quickly as reasonably practicable.


7. Logging and Monitoring

The Company maintains monitoring mechanisms designed to detect abnormal or suspicious activities.

Logs may include:

  • Authentication events
  • Administrative actions
  • Infrastructure events
  • Application activity
  • Security alerts

Log information may be reviewed during investigations and security assessments.


8. Third-Party Risks

The Company recognizes that suppliers and service providers may introduce security risks.

Reasonable efforts are made to ensure that third-party providers maintain appropriate security standards.

Security incidents involving third parties are handled according to this policy whenever Company information may be affected.


9. Business Continuity

The Company maintains backup and recovery capabilities intended to support business continuity in the event of technical failures, cyber incidents or operational disruptions.

Business continuity measures are periodically reviewed.


10. Policy Review

This policy shall be reviewed annually or following significant security incidents, organizational changes or technological changes.


Approval

Prepared and approved by:

Mateusz Michał Śliwka
President of the Management Board