Trust Center

Incident Response

Effective date: July 22, 2026

This page outlines how suspected security and technology incidents are reported, triaged, contained, and moved toward recovery.

Purpose

This Incident Response page explains how Clover Technologies approaches suspected technology and cybersecurity events for covered managed IT environments.

Examples of Reportable Events

Suspected account compromise, unexpected MFA prompts, or suspicious login activity.

Phishing emails, malicious attachments, fraudulent payment requests, or business email compromise concerns.

Lost or stolen devices that may contain business data or access to company systems.

Malware alerts, ransomware indicators, unusual system behavior, or unexplained outages.

Unauthorized access, data exposure concerns, or suspicious administrative changes.

Response Approach

Triage the report and gather available facts from users, systems, logs, alerts, and impacted services.

Prioritize containment steps such as password resets, session revocation, endpoint isolation, access restriction, or blocking malicious indicators when appropriate.

Escalate to customer contacts, vendors, carriers, cloud providers, cyber insurance, legal counsel, or specialized incident response partners when needed.

Support recovery activities such as restoring access, validating systems, reviewing backups, and confirming business-critical services.

Document known facts, actions taken, open risks, and recommended follow-up improvements.

Customer Responsibilities

Report suspected incidents as soon as possible through an approved support or emergency contact path.

Provide accurate information about affected users, devices, systems, timelines, and business impact.

Preserve evidence where practical and avoid unnecessary changes before triage if doing so is safe.

Make business decisions about notification, legal obligations, cyber insurance, and third-party incident response when required.

Communication

Clover Technologies communicates incident updates to authorized contacts based on severity, available information, service scope, and business impact. Fast reporting and clear authorization help speed containment and recovery.

Post-Incident Improvement

After an incident, Clover Technologies may recommend improvements such as MFA changes, email security adjustments, endpoint protection updates, backup changes, user training, access reviews, or additional monitoring.