Incident Response Plan

Document Owner Lou Bonvarlet, General Counsel, ScorePlay Inc.
Version 2.0
Effective Date June 2026
Last Reviewed June 2026
Next Scheduled Review June 2027 (annual, or upon material change)
Classification Internal

Purpose

To establish the plan for managing information security incidents and events.

To offer guidance for employees or incident responders who believe they have discovered, or are responding to, a security incident.

Scope

This policy covers all information security or data privacy events or incidents impacting non-public ScorePlay data.

Incident and Event Definitions

A security event is an observable occurrence relevant to the confidentiality, availability, integrity, or privacy of ScorePlay-controlled data, systems, or networks.

A security incident is a security event that results in loss or damage to the confidentiality, availability, integrity, or privacy of ScorePlay-controlled data, systems, or networks.

Incident Reporting and Documentation

Reporting

If a ScorePlay employee or contractor becomes aware of an information security event or incident, possible incident, imminent incident, unauthorised access, policy violation, security weakness, or suspicious activity, they shall immediately report the information using one of the following communication channels:

Reporters should act as good witnesses and behave as if they are reporting a crime. Reports should include specific details about what has been observed or discovered.

Severity

The Security Delegate shall monitor security incident notifications and assign a severity based on the following categories.

S3 / S4. Low and Medium Severity