Skip to content
ZK
ZAIN KHALIL KHAN
PORTFOLIO
All projects

Interactive build

Incident Comms | Severity & Notification Clocks

Incident communication planner that derives severity from which of confidentiality, integrity, and availability are affected at what scale, then computes regulatory notification deadlines separately and orders every audience with the content each one should receive.

Live demo readyIncident Response + GDPR
Incident ResponseGDPRComplianceCrisis CommunicationBreach NotificationSecurity GovernanceCase study / interactive demo

Case study

From problem to working system

Problem

Incident communication planner that derives severity from which of confidentiality, integrity, and availability are affected at what scale, then computes regulatory notification deadlines separately and orders every audience with the content each one should receive.

My role

Security engineer and full-stack developer

Solution

Incident communication planner that derives severity from which of confidentiality, integrity, and availability are affected at what scale, then computes regulatory notification deadlines separately and orders every audience with the content each one should receive.

Architecture

The implementation combines the following technologies and system concerns.

Incident ResponseGDPRComplianceCrisis CommunicationBreach NotificationSecurity Governance

How it was built

  • Modelled the GDPR 72-hour obligation, card brand notification, the HHS 500-individual threshold, and state notification statutes as separate triggers with their own conditions.

Security decisions

No project-specific security control is documented in the current project record. The case study avoids claiming controls that were not verified.

Major challenges

  • Derived severity from CIA impact and record scale rather than from a subjective judgement call in the middle of an incident.
  • Computed regulatory clocks independently of severity, because statutory deadlines start at awareness and do not care about internal severity language.
  • Ordered audiences from responders to executives to counsel to customers to regulators, with the timing each one gets at that severity.

Verified evidence

Results and measurable impact

  • Derived severity from CIA impact and record scale rather than from a subjective judgement call in the middle of an incident.

Screenshots and access

Product view

Interactive Demo

A scoped, fully functional recreation of this project's core feature runs below, live in your browser. Reset it, resize it, or expand it to full screen.

Incident Comms

Security platform

Incident CommsWorkspace5 updates
Incident Comms · Severity & Clocksseverity from 3 of 3 CIA dimensions at 42,000 records
SEV1 · 1 clocks

Two things go wrong in incident communication: the wrong people are told first, and the regulatory clock is discovered late. Severity here is derived from which of confidentiality, integrity, and availability are hit and at what scale, while notification deadlines are computed separately, because those clocks start at awareness and are indifferent to your severity language.

Severity

SEV1

3 of 3 CIA dimensions

Records affected

42,000

PII

Containment

active

spread not stopped

Audiences

4

in notification order

Severityactive
SEV13/3 CIA
Impact dimensionsPII

Confidentiality

affected

Integrity

affected

Availability

affected

Severity drives who is woken up. The regulatory clocks below are computed independently, because they start at awareness and ignore internal severity language.

Notification order
1. Incident commander and technical respondersImmediately

Facts only: scope, containment status, next action, no speculation on cause.

2. Executive sponsorWithin 30 minutes

Business impact, containment status, decisions needed, resource asks.

3. Legal and privacy counselWithin 1 hour

Data types and record counts, so notification obligations can be assessed before any external statement.

4. Regulators72 hours from awareness

Statutory content only, filed through counsel.

Regulatory clocks
GDPR supervisory authority72 hours from awareness

Trigger: Personal data of EU residents affected. The clock runs from the moment of awareness, not from containment.

Zain Khalil Khan