Effective Date: 01/02/2025
Approved By: President, KPG99 Inc.
The purpose of this policy is to ensure that all information security, data protection, and operational incidents at KPG99 Inc. are promptly identified, reported, investigated, and resolved in a structured and effective manner. The objective is to minimize business disruption, protect client and company data, and prevent recurrence through corrective and preventive measures.
This policy applies to all employees, contractors, subcontractors, and vendors of KPG99 Inc. who have access to company or client information systems. It covers all incidents related to security breaches, data loss, policy violations, or system disruptions.
KPG99 Inc. maintains a formal and proactive approach to managing incidents that may impact business operations, information assets, or compliance obligations. All personnel are required to report any suspected or confirmed incidents immediately to ensure timely containment and resolution.
An incident is any event that may compromise:
If an incident affects client data or services, the Compliance & Operations Team will:
All incidents and investigations will be documented and retained for a minimum of 12 months from the date of resolution. Records include incident reports, root cause analyses, communications, and corrective actions.
KPG99 Inc. tests its incident response process at least once every 12 months through tabletop exercises or simulated scenarios to ensure readiness and continuous improvement.
This policy will be reviewed annually to ensure it remains effective, aligned with industry standards, and compliant with client and regulatory requirements.
Approved and Authorized by:
Puneet Gulati
President, KPG99 Inc.
Date: 01/02/2025