You are on CAQA Technologies
CAQA Technologies - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
Home / Incident Response Terms

Incident Response Terms

How CAQA Technologies manages incident reporting, authorisation, evidence handling, response priorities and third-party dependencies.

1. About these terms

These Incident Response Terms explain how CAQA Technologies, part of CAQA Groups and a Career Calling International initiative, receives reports of suspected cyber security incidents, how a response is authorised and prioritised, how evidence is handled and how third-party dependencies can affect timeframes. They apply to incident response assistance requested through this website and to incident response delivered under a managed services agreement with education and business clients.

2. Reporting obligations

Fast reporting is the single most important factor in limiting damage. Clients should report a suspected incident as soon as it is noticed, even if the details are incomplete. Urgent reports should be made by phone on 1800 266 160 or 03 8103 8000; non-urgent reports can be made by email to info@caqa.com.au or through our contact page. A useful report describes what was observed, when it was first noticed, which systems, accounts or data appear to be affected and any actions already taken. Managed services clients agree to report suspected incidents affecting supported systems promptly, because delay narrows the response options available.

3. Authorisation

Incident response actions are taken only with authorisation from the client’s nominated authorised contact. Authorisation covers the actions reasonably needed to investigate and contain the incident, which may include isolating systems from the network, disabling or resetting accounts and credentials, blocking traffic, restoring from backup and engaging relevant vendors on the client’s behalf. In an emergency, verbal authorisation may be accepted and will be confirmed in writing as soon as practicable. Work beyond the initial containment scope, such as extended forensic analysis or rebuild projects, is quoted and authorised separately.

4. Evidence handling

During a response we aim to preserve evidence while restoring service. Wherever practicable we retain relevant logs, capture system images or snapshots before rebuilding, record the timeline of actions taken and avoid destructive steps until the client has decided whether forensic investigation, an insurance claim or a report to authorities is likely. Where formal forensic standards or chain-of-custody handling are required, this is identified early, because it changes how systems must be treated. Clients should tell us immediately if an insurer, lawyer, regulator or law enforcement agency is, or is likely to become, involved.

5. Response priorities

Incidents are triaged on severity and business impact. An active, spreading compromise, ransomware event or whole-of-organisation outage is treated with the highest priority; a contained incident on a single device, or a suspicious event with no confirmed impact, is prioritised accordingly. Within an engagement, agreed response targets are set out in the relevant service agreement and in our Support and Service Levels page. For organisations that are not existing clients, assistance depends on the availability of our team and acceptance of a written engagement, and we will say quickly and honestly what we can and cannot take on.

6. Third-party dependencies

Incident response frequently depends on third parties, including cloud platforms, internet service providers, software vendors, hosting companies, insurers and law enforcement. Their investigation queues, support processes and decision timeframes are outside our control, and some recovery steps, such as account reinstatement by a platform provider, cannot be completed until a third party acts. We coordinate these dependencies actively, but we cannot guarantee third-party response times or outcomes.

7. Client responsibilities during an incident

8. Fees and payments

No payments are taken through this website. Incident response for managed clients is delivered under the relevant agreement, which states what is included and what is charged separately. Work for other organisations is quoted and invoiced under a written engagement. Because no products or services are sold through this website, no website refund terms apply; the cancellation position for any engagement is stated in its agreement, and nothing here limits the Australian Consumer Law.

9. Limits of the service

Incident response reduces harm; it cannot promise a perfect outcome. We cannot guarantee that all data will be recovered, that an attacker’s identity will be established, that a regulator, insurer or platform will decide in the client’s favour or that an incident will not recur. Our assistance is technical and operational: it is not legal advice, and decisions about obligations under the Notifiable Data Breaches scheme or other laws remain with the client and its advisers, as explained in our Cybersecurity Disclaimer.

10. Contact

To report an incident or ask about these terms, call 1800 266 160, email info@caqa.com.au or use our contact page.

Newsletter Subscription

To Receive Updates And Offers