Karo
Safe. Simple. Sorted.
Karo Digital Classics Ltd
Version 1.0 · Last updated 15 August 2026
Date: 15 August 2026. Format: tabletop exercise, run by Classic Talent Optimization, an affiliated party, against the incident response outline published in the Karo Data Protection Impact Assessment.
Participants: the Karo platform owner and data protection contact, the engineering owner for the platform, and the reviewer from Classic Talent Optimization acting as facilitator and scribe.
A staff account at a subscribing school is compromised on a shared device. The account holds a role with access to sick bay records and guardian contact details. The compromise is noticed the following morning after unexpected messages appear in the delivery log.
The exercise ran the full sequence: contain, assess, notify the school as controller, support the school's notification to the supervisory authority where the threshold is met, and record the preventive change.
Containment worked as designed. Revoking the account terminated the live session immediately rather than at next page load, and the five-minute inactivity termination limited the plausible window of unattended access.
Assessment was possible from the records the platform already keeps: the append-only audit log attributed each health record read to an account and time, and the delivery centre showed exactly which guardians received which message.
Two improvements were identified and actioned: the notification narrative to the school now leads with the specific records touched rather than a general statement, and the audit review step is written as a named checklist rather than relying on the responder knowing where to look.
The incident response outline is rehearsed, workable and supported by the evidence the platform captures. This record is the evidence behind the rehearsed incident response control in the DPIA.
The exercise is repeated at least annually, and after any material change to access control, logging or the messaging pipeline. Each run is recorded here with its date, participants, scenario and findings.
Read alongside the platform security assessment.