KehitysSuper-admin console
Mock mode

K11 · Incidents + breach

Incident workbench.

Open incidents and drills in one console. Each incident carries a state machine, impact summary, scoped tenant list, and — when PII is in scope — a 72-hour Art. 33 notification clock.

Open

01

Newly triaged or unresolved.

Monitoring

01

Mitigated, watch window active.

PII in scope

00

Triggers Art. 33 clock.

Breach contacts

03

Verified per tenant.


Open incidents

What's running.

Incident · INC-2026-014

Resend bounce spike — Publicis save-the-date batch

SEV2
Monitoring

Opened 23 May 2026, 17:10 by deliverability-alert

Scope

Publicis Sweden — Centenary 100

PII in scope
No
Impact summary

4/320 hard bounces during STD initial burst. No data exposure; isolated to invalid mailbox addresses. Suppression list updated.

Timeline

23 May 2026, 17:42 · ops@kehitys.se

Suppressed 4 addresses; flagged tenant CS for follow-up.

23 May 2026, 17:14 · ops@kehitys.se

Replayed Resend webhook retries after one 5xx flake.

23 May 2026, 17:10 · deliverability-alert

Bounce rate breach threshold (>1%) for publicis sending domain.


Privileged actions

Postmortem closure and breach-notification dispatch both route through step-up + reason.


Breach contacts

Per-tenant DPO + escalation.

Verified out-of-band. Re-verification is required if a tenant DPO changes; the re-verify action routes through step-up.

TenantDPOEmailEscalationVerified

Publicis Sweden — Centenary 100

Anna Sjölund

dpo@publicis.se

+46 8 411 00 00 · GC during business hours

19 May 2026, 16:30

Ericsson — 150 Years

Per Hansson

dpo@ericsson.com

+46 10 719 00 00 · global DPO desk

12 May 2026, 13:30

Nordic Gala 2027

Karin Lind

dpo@nordicgala.se

+46 8 555 12 00 · CEO out-of-hours

20 May 2026, 11:00


Drill history

Quarterly tabletop cadence.

18 Jan 2026, 11:00

Tabletop — leaked invite token batch / cross-tenant read.

Participants: founder@kehitys.se, ops@kehitys.se, review@kehitys.se

Identified gap: tenant DPO escalation phone was stale. Resolved within 48h.

Completed
12 Jul 2026, 12:00

Tabletop — Resend account compromise.

Participants: founder@kehitys.se, ops@kehitys.se

Quarter scheduling per architecture §15 (quarterly cadence).

Scheduled