Skip to main content

πŸ§ͺ Breach-response drill β€” 2026-Q2-01

SIMULATION β€” not a real incident. No real user data was exposed. Purpose: exercise compliance/breach-response.md, measure elapsed time against SLAs, surface gaps.


Scenario​

An intern accidentally pastes a tennis match video and its signed download URL into a public Slack workspace thread. The URL is valid for 7 days (our export-style download tokens). Slack message is seen by three non-company members of the channel within 20 minutes.


Timeline (simulated)​

Time (UTC)EventWhoArtefact
T+0Intern posts linkInternSlack msg
T+2mSenior engineer notices; alerts on-callEng#acesense-oncall
T+5mOn-call opens incident doc from templateOn-callincidents/2026-Q2-drill-1.md (this file)
T+8mPaging tree notified: Eng Lead + DPO + FounderOn-callPage logs
T+12mContainment: link revoked by patching the Firebase Storage object's firebaseStorageDownloadTokens metadata (nulling the token invalidates the URL)Eng Leadgcloud storage objects update...
T+15mSlack message deleted (on behalf of intern)Eng LeadSlack audit
T+20mAccess logs pulled for the Storage object: 3 distinct non-internal IPs accessed the file while the URL was liveEng LeadCloud Logging export
T+45mAssessment meeting: data = one tennis video; subjects = 1 user; video does not include children; no special categories other than biometric-adjacent pose (derivable from video)DPO + Eng LeadIncident doc Β§Assessment
T+1hDecision: breach β†’ GDPR Art. 33 notification required (since subject is in DE); subject notification required per Art. 34 (high-risk due to biometric-adjacent exposure)DPOSigned decision note
T+3hArt. 33(3) draft completed; internal legal review completeDPODraft attached
T+8hArt. 33 notification submitted to Berlin BfDI via web formDPOConfirmation receipt
T+12hAffected user emailed with the Art. 34 notice (plain-language, action-to-take, contact)DPOSent via Resend
T+18hSlack channel access for interns restricted to a read-only audit logEng LeadSlack admin log
T+24hPost-mortem scheduled for T+48hDPOCalendar

Gaps surfaced​

  1. The paging tree was on-call engineer β†’ manual pings. We should codify a single page-incident alias that fans out to Eng Lead + DPO + Founder in one step. Action: add Slack /remind or PagerDuty rotation. Owner: Eng Lead. Due: end of quarter.

  2. The firebaseStorageDownloadTokens metadata patch to invalidate a live URL is not a documented procedure. Action: add a one-liner to the breach runbook's "Containment" section. Owner: Eng Lead. Due: next doc update.

  3. No automated monitoring detected the URL access pattern (3 new IPs on a single object in a short window). Action: log-based metric + alert on Storage read-count anomalies. Owner: Eng Lead. Due: Q3.

  4. The intern had edit access to the Slack workspace by default. No security training onboarding exists. Action: stand up a short-form "what can go on Slack" briefing for new joiners. Owner: Ops. Due: before next intern joins.

  5. The simulated Art. 34 email copy referenced technical terms ("signed URL", "storage object"). Action: rewrite the subject-notification template in plain language. Owner: DPO. Due: next doc update.


Time vs SLA​

SLATargetActual (simulated)Status
Discoverer β†’ on-call paged≀ 10 min2 min🟒
Containment≀ 1 h12 min🟒
Full assessment≀ 24 h1 h🟒
Art. 33 submitted≀ 72 h8 h🟒
Subject notification≀ "high risk β†’ without undue delay"12 h🟒

All SLAs met. The gaps identified above are process-improvement items, not timeline failures.


Participants (simulated)​

  • Discoverer: Senior engineer
  • On-call: Eng
  • Incident commander: Eng Lead
  • Communications: DPO
  • Observer / note-taker: Founder

Closure​

  • Containment complete
  • Notifications simulated (no real messages sent)
  • Gaps logged as action items above
  • Post-mortem scheduled at T+48h (simulated)
  • Action items closed (target: end of 2026-Q3)

Drill authenticity statement​

This document is a simulation of an incident for training purposes. No production data was exposed. No real notifications were submitted to any supervisory authority. No user email was sent. Storage object mentioned does not correspond to any real file. The drill was run on 2026-04-24 as part of the compliance readiness programme introduced in compliance/overview.md.

Signed (not yet countersigned):

  • Incident commander (simulated role) β€” AceSense Eng Lead
  • DPO (simulated role) β€” AceSense DPO