Detection, containment, customer notification, and improvement
This procedure defines how Virtus Group identifies, assesses, contains, communicates, and learns from security incidents and privacy breaches, including how customer notification is managed when customer data or services may be impacted.
Virtus Group notifies the impacted customer when there is reasonable suspicion or confirmation that:
Separation: If an incident affects multiple customers, notifications and evidence are managed per customer to prevent cross‑customer information disclosure.
Subject: Security incident notification — [Customer] — [Date/Time]
© Virtus Group Ltd.
Informational procedure summary. Engagement-specific notification contacts and timeframes are defined in the relevant contract/SOW and customer policies.