Incident Response
1. Contain
Stop the affected signer/connector/node from producing new authoritative events where possible without destroying evidence.
2. Preserve evidence
Capture logs, hashes, manifests, state roots, affected Entity/key IDs, release version and time window. Avoid altering the only copy of suspect state.
3. Classify
Determine whether the incident affects key custody, authority delegation, evidence/provenance, rights/settlement, provider availability, release integrity or BTDU state.
4. Recover/rotate
Use trusted recovery/rotation procedures. Verify the same Entity identity and continuity proof; do not simply create a replacement identity.
5. Reverify
Reverify state, evidence, rights/passports, recovery roots and restored signing. For BTDU, verify/reconstruct sampled objects and compare roots/manifests.
6. Report
Use private security reporting for exploitable findings and document lessons/controls without exposing keys or production data.