• Email Address : sales@kpgtech.com
  • Office Address : 3240 E State St Ext Hamilton , NJ 08619

Incident Management Policy

Incident Management Policy

Effective Date: 01/02/2025
Approved By: President, KPG99 Inc.


1. Purpose

The purpose of this policy is to ensure that all information security, data protection, and operational incidents at KPG99 Inc. are promptly identified, reported, investigated, and resolved in a structured and effective manner. The objective is to minimize business disruption, protect client and company data, and prevent recurrence through corrective and preventive measures.


2. Scope

This policy applies to all employees, contractors, subcontractors, and vendors of KPG99 Inc. who have access to company or client information systems. It covers all incidents related to security breaches, data loss, policy violations, or system disruptions.


3. Policy Statement

KPG99 Inc. maintains a formal and proactive approach to managing incidents that may impact business operations, information assets, or compliance obligations. All personnel are required to report any suspected or confirmed incidents immediately to ensure timely containment and resolution.


4. Definition of an Incident

An incident is any event that may compromise:

  • The confidentiality, integrity, or availability of data.
  • The normal functioning of IT systems or services.
  • Compliance with laws, client contracts, or internal policies.
  • The company’s or clients’ reputation or business operations.

5. Incident Reporting

  • All suspected or confirmed incidents must be reported immediately to the Compliance & Operations Team at compliance@kpgtech.com.
  • Reports should include details such as the nature of the incident, systems affected, date/time of discovery, and actions taken so far.
  • Anonymous reporting is permitted through the whistleblower mechanism, where applicable.

6. Client Notification

If an incident affects client data or services, the Compliance & Operations Team will:

  • Notify the client promptly with details of the incident.
  • Provide a summary of impact and mitigation steps.
  • Keep the client informed until the issue is fully resolved.

7. Documentation & Retention

All incidents and investigations will be documented and retained for a minimum of 12 months from the date of resolution. Records include incident reports, root cause analyses, communications, and corrective actions.


8. Testing

KPG99 Inc. tests its incident response process at least once every 12 months through tabletop exercises or simulated scenarios to ensure readiness and continuous improvement.


9. Responsibilities

  • Compliance & Operations Team: Oversight, investigation, and reporting.
  • IT Department: Containment, recovery, and technical analysis.
  • Department Heads: Support investigation and implement corrective measures.
  • All Employees: Prompt reporting and cooperation during investigations.

10. Review

This policy will be reviewed annually to ensure it remains effective, aligned with industry standards, and compliant with client and regulatory requirements.


Approved and Authorized by:
Puneet Gulati
President, KPG99 Inc.
Date: 01/02/2025

A Successful Placement is Only The Beginning