| Document Owner | Lou Bonvarlet, General Counsel, ScorePlay Inc. |
| Version | 2.0 |
| Effective Date | June 2026 |
| Last Reviewed | June 2026 |
| Next Scheduled Review | June 2027 (annual, or upon material change) |
| Classification | Internal |
To establish the plan for managing information security incidents and events.
To offer guidance for employees or incident responders who believe they have discovered, or are responding to, a security incident.
This policy covers all information security or data privacy events or incidents impacting non-public ScorePlay data.
A security event is an observable occurrence relevant to the confidentiality, availability, integrity, or privacy of ScorePlay-controlled data, systems, or networks.
A security incident is a security event that results in loss or damage to the confidentiality, availability, integrity, or privacy of ScorePlay-controlled data, systems, or networks.
If a ScorePlay employee or contractor becomes aware of an information security event or incident, possible incident, imminent incident, unauthorised access, policy violation, security weakness, or suspicious activity, they shall immediately report the information using one of the following communication channels:
Reporters should act as good witnesses and behave as if they are reporting a crime. Reports should include specific details about what has been observed or discovered.
The Security Delegate shall monitor security incident notifications and assign a severity based on the following categories.
S3 / S4. Low and Medium Severity