NicholicIndependent

Security

Incident reports

The format is committed to here in advance, so the first one cannot be shaped to flatter.

No incident reports have been published.

What counts as an incident

  • Unauthorised access to any data held by Nicholic.
  • Accidental disclosure of data to the wrong person, including by Nicholic.
  • Loss of data without a recoverable backup.
  • A vulnerability that was exploited, whether or not anything was taken.
  • A published commitment being broken.

The last item is deliberate. A broken promise is treated as an incident rather than a communications matter.

What happens, and when

Anyone affected is told directly where there is a way to reach them. A public report goes up within seven days of confirming an incident — a target, like the others on this site.

If the full picture is not known within seven days, the report is published anyway, saying what is known and what is not, and updated as it becomes clear. Waiting for a complete story is how disclosure slips indefinitely.

The format every report uses

  1. What happened.
  2. When it happened, and when it was discovered — separately, because the gap matters.
  3. Who and what was affected.
  4. What was done about it.
  5. What changed so it does not happen again.
  6. What is still unknown.