Cyber Incidents

Logs information-security and cyber incidents (mfi.cyber.incident) - breaches, fraud attempts, outages and data exposures - with severity, impact and response timeline. It gives the board oversight of operational-technology risk and supports mandatory breach notifications. Each incident tracks containment, root cause and lessons learned.

Cyber Incidents
Cyber Incidents — live screen from the BridgeERP MFI Suite.

Workflow

  1. Open Cyber Incidents under Governance.
  2. Raise an incident with its category, severity and detection time.
  3. Record affected systems, data and customer impact.
  4. Track containment, investigation and root-cause findings.
  5. Close with lessons learned and any regulator notification logged.

Fields reference

Every field on this screen, drawn from the live data model.

FieldTypeRequiredDescription
Cbk Notify Required
cbk_notify_required
Yes/No—Computed: True when severity is high or critical.
Cbk Notify Due At
cbk_notify_due_at
Date & time—Computed: detected_at + 24h.
Cbk Notified Via
cbk_notified_via
Text—How the notification was delivered (email + ref).
Notification narrative
cbk_notify_text
Long text—Free-text narrative sent to CBK.
Affected Records
affected_records
Number—Estimated number of customer records affected.
Affected members
affected_members_ids
Tags—Members whose data was potentially exposed.
Title
title
TextYesTitle
Kind
kind
Choice: Phishing, Malware / Ransomware, Credential Compromise, DDoS / Availability Attack, Data Breach, Insider Threat, Third-Party / Vendor Compromise, Misconfiguration / DriftYesKind
Severity
severity
Choice: Low — informational, Medium — material impact, High — significant impact, Critical — adverse impact (CBK 24h notify)YesSeverity
State
state
Choice: Detected, Assessing impact, Reported to Regulator, Contained, Resolved, Post-mortem complete, Cancelled / False positiveYesState
Detected At
detected_at
Date & timeYesDetected At
Has Message
has_message
Yes/No—Has Message
Reference
reference
Text—Reference
Detected By
detected_by
Link → res.users—Detected By
Detection Source
detection_source
Choice: SIEM alert, User report, Routine audit, Vendor notification, Vulnerability scan, Other—Detection Source
Cbk Notified At
cbk_notified_at
Date & time—Cbk Notified At
Monetary Loss
monetary_loss
Money—Monetary Loss
Currency
currency_id
Link → res.currency—Currency
Containment Actions
containment_actions
Long text—Containment Actions
Eradication Actions
eradication_actions
Long text—Eradication Actions
Recovery Actions
recovery_actions
Long text—Recovery Actions
Root Cause
root_cause
Long text—Root Cause
Lessons Learned
lessons_learned
Long text—Lessons Learned
Contained At
contained_at
Date & time—Contained At
Resolved At
resolved_at
Date & time—Resolved At
Resolved By
resolved_by
Link → res.users—Resolved By
Post Mortem Url
post_mortem_url
Text—Post Mortem Url
Company
company_id
Link → res.company—Company

Actions & buttons

Buttons available on this screen and what they do:

  • Start Assessment
  • Notify CBK Now
  • Mark Contained
  • Mark Resolved
  • Post-mortem Done

Status lifecycle

Records on this screen move through these statuses:

Detected → Assessing impact → Reported to Regulator → Contained → Resolved → Post-mortem complete → Cancelled / False positive

Notes & rules

  • Captures breaches, fraud, outages and data exposures.
  • Severity and impact drive escalation to the board.
  • Supports mandatory breach-notification timelines.
  • Root-cause and lessons-learned feed risk management.

Technical model: mfi.cyber.incident · Record: MFI Cyber / Security Incident

Was this page helpful?