Incident Response
Junipa maintains an Incident Response Plan and a Data Breach Response Plan. This page summarises how we handle security incidents.
Incident Classification
| Severity | Description | Response time |
|---|---|---|
| Critical | Active data breach or total service outage | Within 1 hour |
| High | Potential data exposure or partial outage | Within 4 hours |
| Medium | Contained security event, no data exposure | Within 24 hours |
| Low | Minor event, no impact | Within 72 hours |
Detection
Junipa monitors for security incidents through:
- GCP Cloud Monitoring (uptime, error rates, anomalies)
- Firebase Authentication anomaly detection
- Cloudflare WAF alerts
- Firestore audit logs
- User reports via info@junipa.com.au
- Dependency vulnerability alerts
Response Process
- Detect -- Identify and log the incident
- Contain -- Isolate affected systems, preserve evidence
- Investigate -- Determine root cause, scope, and data impact
- Notify -- Inform affected schools within 24 hours of confirming a data breach
- Remediate -- Fix the vulnerability, deploy patches, verify
- Review -- Post-incident review within 7 days, update controls
School Notification
If a data breach involves personal information:
- Affected schools are notified by email within 24 hours
- The notification includes what happened, what data was affected, and what actions are being taken
- Ongoing updates are provided until the incident is fully resolved
Regulatory Notification
If a breach meets the threshold for an eligible data breach under the Notifiable Data Breaches (NDB) scheme:
- The Office of the Australian Information Commissioner (OAIC) is notified within 30 days
- Affected individuals are notified (via schools, as data controllers)
Insurance
Junipa holds Professional Indemnity ($5M) and Broadform Liability ($20M) insurance through CGU (Insurance Australia Limited), providing breach response support including legal and forensics.
Reporting a Concern
If you suspect a security issue or data breach, contact us immediately:
Email: privacy@vastpuddle.com.au
General support: info@junipa.com.au