Incident

Expand All

Helpful Videos for You

Need help? Check out videos for quick assistance!

Welcome to the Incident Management User Guide. Incident Management is a critical component of any organisation's risk and governance strategy. In today’s digital landscape, effective incident management is essential for protecting personal data, ensuring business continuity, and maintaining trust. Organisations must be prepared to identify, respond to, and resolve incidents such as data breaches, system outages, or security threats that could disrupt operations or compromise sensitive information.

With the growing complexity of cyber threats, incident management plays a vital role in addressing potential risks, implementing corrective actions, and safeguarding data. By ensuring a structured approach to incident resolution, organisation’s can mitigate the impact of incidents, protect critical assets, and comply with legal obligations. Failure to manage incidents effectively can result in significant penalties, making it crucial to have a proactive and secure approach to both incident management and data protection.

Access to Incident Management is included as part of 9ine’s Privacy Platform and Incident Platform licences. For further information contact [email protected]. 

Accessing Incident

Upon purchasing 9ine’s Privacy Platform or Incident Platform and its associated features, users can be granted access to Incident. Your organisation’s administrator(s) have the option to allocate permission via  User Management, available to administrators in the header.

Granting access to this feature does not automatically provide access to all incidents. However, it allows users to log a new incident. Users must be added as the data protection, IT lead, members, notified user, attachment reviewer of the incident to gain edit access. Owners and members of any risks, issues, lessons or tasks are also granted edit access if the item is associated with the incident. Incidents can be deleted by the owner or your 9ine Platform account administrators. An incident's permissions include:[c1]

  • Owner
  • Member
  • Data protection lead
  • IT lead
  • Notified user 
  • Attachment reviewer
  • Screening reviewer
  • Approver

Warning:

When creating a new incident, the logged-in user will automatically be assigned the role of Owner, and this field cannot be changed.

 

There can only be a single owner, data protection lead, and IT lead of an incident but there are no limits to the number of members or notified users. Each attachment can also have one reviewer.  Owners can edit and delete their assigned items, while all other roles have edit rights but cannot delete. When more than two members or notified users are added, the additional user details are combined into a single pill, which can be clicked to view further details. These pills are alphabetically ordered.

 
 

Adding and removing notified users

Adding removing notified users forms

To add a notified user, use the mention function in the “Additional Notes” featur

To add a notified user, use the mention function in the Additional Notes feature.

  • To begin, click the @ symbol on your keyboard and type the first name of the user you wish to mention. 
  • A user can be mentioned at the start, in the middle, or at the end of the entered text. 
  • To remove a user as a notified user, simply delete their name from the relevant note. 
  • Mentioning a user sends an in-Platform notification and an email unless the user has disabled email notifications. 
  • The email notification sends a complete copy of the text entered by the user in the 9ine Platform, to the user’s registered email address.

 

 
 

Understanding how to create an incident

Begin by clicking New Incident, to get started. You will then be presented with the Assess New Incident popup, which displays four fields:

  • Incident title
  • Person reporting the incident
  • Email address of the reportee
  • Telephone number of the reportee

Two of the four fields are mandatory when creating a new incident area including: incident title and person reporting the incident. On entering the required fields, you have two options:

  • Save & Close: Saves the information, creates the incidents, and returns you to the incident log.
  • Save & Add Details: Saves the information and navigates you to the Background step of the incident form.

 
 

Creating a new incident or editing an existing one

When creating a new incident or editing an existing one, you will be navigated to the form and presented with four headers, including:

  • Background
  • Investigation
  • Risk & Impact
  • Outcome & Closure

The title of the incident is consistently displayed at the top of the form, and to the right, a unique reference number is provided. This number is prefixed with INC and followed by a unique identifier (calendar year, month, date, and a unique reference number) that cannot be edited. 

For new incidents, only the Background step will be enabled by default. Users must first answer the question, Will an incident assessment be completed? in the Screening Outcome section before they can proceed. This question allows organisations to conduct a preliminary assessment before deciding whether a full incident evaluation is required. 

  • On selecting Yes, you must enter a date in the Completion required by field. Once this is done, the Save & Exit button will change to Save & Next, allowing you to navigate to the Investigation step of the incident form.

  • On selecting No, additional fields will appear, including an explanation text box, a Screening review required by field, a Review status dropdown (with options: Incident not required, Incident required, Awaiting review), and a Next Review Date field. The remaining steps in the form will stay greyed out, preventing further progression

  • On selecting Don’t Know, you must enter the Screening review required by, Review status, and Next review date fields. The remaining steps in the form will stay greyed out, preventing further progression.

In step 2, Investigation, when selecting Security & Systems or Both for the question Incident Classification, an additional step, 2a S&S Investigation, will be added to the incident form.

It is possible to link an incident to a record of processing activity through the Add Details option provided for the question Does the organisation’s record of processing include a processing activity related to this incident?

Third parties, such as data processors, will be identified during the investigation phase of the incident assessment. These third parties are often software vendors or suppliers involved in the transfer of personal data from the organisation to the third party. You have the ability to document processing responsibilities within the investigation step.

Tip:

  • Tooltips are available throughout the incident form to provide guidance and support, offering helpful insights and additional context for a more informed and accurate assessment.
  • The S&S Investigation step should be completed by the IT lead identified in step 1, Background.
 

In step 3, Risk & Impact, when selecting Yes, No, or Possible, sub-questions and an additional comments field will appear. Upon selecting one of these options, the type of Risk Consideration is added to the question: When there is a risk of damage, what is the likelihood of distress being experienced by the data subject? This allows you to select both Impact and Likelihood, which are multiplied to provide a risk score.

A visual representation of the risk consideration is available by clicking the Overview button.

Similar logic is applied in the Communication section of step 3, Risk Consideration.

The final step in Risk & Impact is to determine the assessment outcome by selecting a decision for Assessment Decision and Proposed Action and indicating Yes or No for the Regulatory Authority Informed option.

On navigating to step 4 Outcome & Closure you will be presented with a Summary of Activities table which is used to capture any risks, issues, lessons, and tasks created through the incident assessment process. 

At the bottom of this step, you can log the closure information, which includes the Closure Date, Approved By, and Reason for Closure. Similar to the Owner field in step 1, Background, the Closure By field is automatically pre-filled with the logged-in user and is un-editable.

 
 

Selecting data subjects and the associated personal and special category data

Selecting data subjects and the associated personal and special category data

Within each form in the 9ine Platform (Records of Processing Activity, DPIA, Proc...

Within each form in the 9ine Platform (Records of Processing Activity, DPIA, Processing Operation Assessment, and Incident Management), you can select data subjects along with their associated personal and special category data. On selecting a data subject, their details appear in a pill below the question for easy reference.

Tip:

If a data subject type is not available in the Platform’s default list, you can add it using the +Other function. Any data subjects added this way will be accessible to all users in your organisation for future use.

 

Each data subject appears in the popup when you click Select Personal Data or Select Special Category Data.

When a user adds any Personal Data or Special Category Data in the corresponding pop-up, a Copy To All button becomes visible. This button allows the user to copy the selected data option to all applicable entries, ensuring consistency and efficiency across the forms.

The secondary number displayed in the Answered pill represents the total number of selected data subjects. For example, if one data subject was initially selected and an additional two were chosen, the count would change from 1 to 3.

 

 
 

Creating an associated risk, issue, lesson, or task (Summary of Activities)

Create associated risk

In the top right-hand corner there is a +New button which provides four options: 

In the top right corner there is a +New button which provides four options: New Risk, New Issue, New Lesson, and New Task.  

For more detailed information on the specific logs, please refer to their individual user guides:

When creating a risk, issue, lesson, or task the details are automatically added to the Summary of Activities table.

 
 

Utilising the additional notes and attachments features

Utilising the additional notes and attachments features

The “Additional Notes” feature allows you to maintain a single repository of info

The Additional Notes feature allows you to maintain a single repository of information related to a moduleName. You can add multiple notes at once using the Save Note function. These notes are saved without the need to click the primary Save at the bottom of the page.

When adding a new note, a record of the user's details, date, and time of entry are added, and the most recent notes will automatically appear at the top of the list. If an individual note is edited, the time and date of the note are updated.

Tip:

Individual notes can only be edited or deleted by the user who originally created the note. However, users have the option to add comments to notes created by others.

 

Additional formatting functionality is provided in the additional notes feature. If entering large volumes of data, click the Full Screen or Expand Popup options.

Warning:

  • For security purposes, the 9ine Platform will log users out of their active sessions after 45 minutes of inactivity, with a reminder triggered at 30 minutes of inactivity. 
  • If you are in full screen mode, the reminder may not appear unless you have browser-based notifications enabled. 
  • Typing in the field is not considered activity; activity is only registered when clicking Cancel or Save.
 

The Attachments feature allows you to upload files or images using your native file explorer. You can upload up to five attachments at once. 

  • Maximum file size: 10MB
  • A maximum of five files can be uploaded at a time
  • Supported file types: jpg, jpeg, tif, tiff, png, odg, otg, txt, rtf, doc, docx, pages, odt, ott, odm, pdf, xml, xmlx, numbers, ods, ots, ppt, pptx, key, keynote, odp, otp, xls, xlsx, tsv, csv, pst, eml, emlx, ost, oft, msg
  • The file name cannot contain special characters :/?<>|"\ #+&'~

Each attachment uploaded can be assigned a reviewer, allocated a review date, and further information can be included. This process ensures that attachments added remain current and do not become obsolete.

 
 

Understanding how to use the incident log

When creating a new incident, or editing an existing one, the details entered are added to the log. Each incident is automatically assigned a unique reference number (starting with INC) that cannot be edited.

To view only the areas you are responsible for, use the My Incidents toggle located in the top right-hand corner of the log. This will filter and display items where you are the owner, member, notified user, data protection (DP) lead, and IT lead.

Understanding how to use the log (forms)

Default sorting is applied to the “Ref No.”, which can be altered by clicking on 

Default sorting is applied to the Ref No., which can be altered by clicking on the title of any other column. Clicking a column header once sorts the log by the selected column, and clicking it a second time reverses the order. 

To remove individual columns, click View and deselect the columns you do not want to display, whilst retaining a minimum of one column. After selecting your preferred columns, click Apply. You also have the option to Save View.

You can also change the sequence order of the columns by dragging and dropping them into your preferred order. Any changes are automatically saved and retained on the next login. 

Tip:

  • The changes applied to the sequence order of the log and in the View popup are user and log specific and only applied to your profile.
  • The sequence order in the View popup does not update to reflect the order created through your dragging and dropping actions.
 

To focus on a specific moudueName, you can use the Filter or Search functions. When a filter is active, an orange icon appears next to the filter icon for easy recognition. 

  • To quickly clear any filters, click the Clear Filters button in the popup. 
  • You can also apply a temporary filter without clicking Save Filter.
  • To revert back to your saved filter, click Reset.
  • Similarly, you can select data points and click Apply
  • Without saving your filter options.
 
 

Downloading incidents

Downloading Forms

To download a moduleName(s) and its activities click the ...

To download a moduleName(s) and its activities click the Download button located in the top right-hand corner of the moduleName log. You can customise the download report to include or exclude data by using the search bar, filter, view options, or My moduleName functions.  Upon clicking Download, the export is processed in the background. Once complete, you will receive both an in-platform notification and an email notification. The exported file is provided in XLS format.

On the moduleName log, You have three download options available:

  • Log - Downloads in XLS format.
  • Advanced - Downloads in XLS format.
  • Form (available in the quick actions menu) - Downloads in DOCX format.
 
 

Understanding the quick actions for an incident

The incident log provides a range of quick-access functions within the menu options, including:

  • Add Member(s)
    Opens a members popup to quickly grant users access to the incident.
  • Duplicate
    Duplicates the incident and all associated risks, issues, lessons, and tasks labelling them with the prefix Copy of. The duplicated items do not include notes, attachments, linked processing area, logged time and logged cost data.
  • Revisions
    Opens the incident closure revisions popup. 
  • Close
    Marks the incident and all its associated risks, issues, lessons, and tasks as closed, removing all items from their respective logs.
  • Reopen
    Marks a closed incident as Open and restores all associated items. Related tasks are returned to Not Started, while associated risks, issues, and lessons are returned to Open status.
  • Delete
    Marks the incident and all its associated risks, issues, lessons, and tasks as deleted, effectively removing them from the 9ine Platform.
  • Download
    Downloads the incident form in a DOCX format.
 
 

Configuring incident notification settings

Global Due Date Notifications Alerts

To ensure you're always informed of key moduleName milestones, users can configure their personal notification preferences within the Notification Settings area of the 9ine Platform. This enables both email and in-Platform alerts for important events in the moduleName lifecycle such as end dates, due dates, renewal reminders, termination deadlines, and next review dates.

To activate alerts:

  1. Navigate to your Notifications (available in the header)
  2. Click the Notification Settings icon

Toggle Global Lifecycle Alerts on for both In Platform and Email to receive notifications through both channels.

Under Reminder, you can select how far in advance you would like to be notified of an upcoming milestone (e.g. 7, 14, or 30 days before the due date). This ensures you receive early warnings before deadlines approach. You can choose any period from 1 to 31 days in advance.

These reminders are designed to give moduleName owners and stakeholders enough lead time to review, act, or make decisions before renewal or termination windows close.

To receive multiple reminders, you can enable Repeat notifications.

  • Repeats are available in weekly intervals and are only triggered if your chosen reminder period is 7 days or more.
  • The number of notifications is based on your reminder window:

For example:

  • If your reminder is set to 10 days, you’ll receive 1 notification.
  • If it’s set to 16 days, you’ll receive 2 notifications.

This flexible notification system helps ensure key events never go unnoticed, especially in busy school environments where planning ahead is essential.