Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Incident Confidential Data Exposure workflow template

The Security Incident - Confidential Data Exposure - Template allows you to perform a series of tasks designed to handle the exposure of sensitive data.

Before you begin

Role required: sn_si.write

About this task

The workflow is triggered when the Category in a security incident is set or changed to Confidential personal identity data exposure. This action causes a response task to be created for the first activity in the workflow.

Image omitted: confid-data-expos-wf-template.png
Confidential Data Exposure Template

Procedure

  1. Open the security incident for which you want to handle the exposure to sensitive data, or create a new security incident.

  2. In Category, select Confidential personal identity data exposure.

  3. Save the record.

  4. Scroll down and open the Response Tasks related list.

    The first of a series of response tasks appears. Each time the record is saved, your response to the previous task either causes the next response task to be created or the flow to end.

Response taskDescriptionResults
Is the data sensitive?Determine whether the data associated with this security incident is sensitive or confidential. In the task, select Yes or No in Outcome.If you selected Yes, the next response task is executed.If you selected No, the flow ends.
Determine root cause and prevent egressDetermine the root cause of the attack and add egress filtering to stop the exfiltration, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed.
Eliminate exposure related to root causeBased on the root cause, perform the steps to eliminate the exposure, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed.
Quarantine residual artifactsPerform the steps to quarantine any residual artifacts, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed.
Legal processPerform the steps to satisfy the legal requirements of this analysis, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed.
PR processPerform the steps to satisfy the PR requirements of this analysis, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the next response task is executed.
Set state to reviewNo action required.The State of the security incident is automatically changed to Review.
Lessons learned meetingConduct a lessons learned meeting to triage the work performed on this sensitive data, updating the State field in the task as appropriate.If you change the state of the task to Closed Complete or Cancelled, the security incident remains in the Review state until you close it.

Parent Topic:Security Incident Response workflow templates

Related topics

Security Incident Denial of Service workflow template

Security Incident Lost Equipment workflow template

Security Incident Malicious Software workflow template

Security Incident Phishing workflow template

Security Incident Policy Violation workflow template

Security Incident Reconnaissance workflow template

Security Incident Rogue Server or Service workflow template

Security Incident Spam workflow template

Security Incident Unauthorized Access workflow template

Security Incident Web/BBS Defacement workflow template