Incident Management
Capture, triage and resolve incidents with root cause and lessons learned
Record incidents as they happen, triage them by severity and impact, drive them through response and resolution, and capture root cause and lessons learned — with every incident linked to the risks and controls it exposes, so recurring weaknesses are addressed rather than repeated. An incident is a control speaking: a breach, an outage, a data loss, a process failure. OnyxOne treats each one as a structured record from first report to closure, so the firm responds consistently, meets its notification obligations, and turns the painful ones into the improvements that stop them happening again.
How it works, visually
Alert, triage, investigate, decide, report — with clear ownership and a defensible trail at every stage.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Incidents are reported everywhere and nowhere
A breach surfaces in an email, an outage in a chat channel, a process failure in a hallway conversation. With no single intake, incidents are logged inconsistently or not at all, and the firm has no reliable view of what has actually gone wrong.
Severity is judged in the moment, inconsistently
Without defined triage criteria, one team treats an event as critical and another shrugs off something worse. Inconsistent severity assessment means the wrong incidents get the urgent response, and the firm cannot show it prioritises by real impact.
Notification deadlines are missed
Many incidents carry regulatory or contractual notification clocks that start the moment the incident is known. When response is ad hoc, those deadlines are tracked in someone's head, and a missed notification turns an operational problem into a compliance breach.
Root cause is never really established
Under pressure to restore service, teams fix the symptom and move on. The underlying cause is never documented, so nothing is learned, and the same failure recurs — each time treated as a surprise.
Incidents don't connect to risk and controls
An incident is evidence that a control failed or a risk crystallised, but if incidents live in their own silo, that evidence never reaches the risk register. The firm's view of its risk stays theoretical while reality keeps proving it wrong.
How OnyxOne addresses it
One intake for every incident
Incidents are captured through a single, consistent intake — reported by staff, raised from monitoring, or escalated from another module — so there is one reliable record of what has gone wrong across the organisation.
Consistent, criteria-based triage
Each incident is triaged against defined severity and impact criteria, so prioritisation reflects real consequence rather than the reporter's mood. The most serious incidents get the urgent response, consistently and demonstrably.
Notification clocks tracked from the start
When an incident type carries a regulatory or contractual notification obligation, the deadline is tracked on the record from the moment it opens, with reminders and escalation, so the firm meets its obligations rather than discovering them too late.
Structured response and root-cause analysis
Incidents move through defined response stages to resolution, and closure requires a documented root cause and lessons learned. The discipline of establishing why turns firefighting into improvement.
Linked to risks, controls and actions
Every incident links to the risks it crystallised and the controls it exposed, and can raise remediation actions against them. The incident record feeds the firm's real risk picture and drives the fixes that prevent recurrence.
What's in the module
Turn on what you need and add more as your programme scales.
Unified incident intake
Capture incidents from staff reports, monitoring signals and escalations through one consistent entry point.
Severity & impact triage
Assess each incident against defined criteria so prioritisation reflects real consequence.
Response workflow
Drive incidents through defined stages — contain, investigate, resolve — with clear ownership at each.
Notification tracking
Track regulatory and contractual notification deadlines on the record, with reminders and escalation.
Root-cause analysis
Capture the underlying cause of an incident, not just the symptom that was fixed.
Lessons learned
Record what the incident taught and what should change, so the firm improves rather than repeats.
Risk & control linkage
Link each incident to the risks it crystallised and the controls it exposed.
Remediation actions
Raise and track corrective actions against the risks and controls an incident revealed.
Incident register
Maintain a single, searchable register of all incidents, their severity, status and outcome.
Immutable incident trail
Every report, triage decision, action and closure is written to an append-only record.
The views your team works from
Purpose-built dashboards and views, each answering a question a specific role needs to act on.
A representative layout of the KPI tiles and charts these dashboards present. Figures shown are illustrative examples, not real data.
Incident queue
Open incidents by severity and status, with owner, age and next action against each.
Severity heatmap
The distribution of incidents by severity and impact area, highlighting where things are going wrong most.
Notification tracker
Incidents with active notification deadlines, showing time remaining and escalation status.
Root-cause trends
Recurring root causes across incidents, surfacing the systemic weaknesses worth fixing once.
Remediation monitor
Corrective actions raised from incidents, tracked to completion against the risks and controls they address.
What the platform automates
Rules, workflows, alerts and scheduling that run the routine so your team works the exceptions.
Detection-driven intake
Alerts from monitoring and security systems raise incidents automatically, pre-populated with the signal that triggered them.
Severity-based routing
Triaged incidents are routed and escalated automatically according to their assessed severity and impact.
Notification deadline alerts
Approaching notification deadlines are escalated automatically so obligations are not missed.
Risk & control linkage
Incidents are linked to related risks and controls automatically where the mapping is known, and remediation actions raised against them.
Recurrence detection
Incidents matching prior root-cause patterns are flagged automatically so systemic issues are recognised early.
Where AI helps the analyst
Assistive, decision-support features that speed up the work on the record. Suggestions are always reviewable, and a person stays in control of every decision.
Incident summarisation
Drafts a concise summary of an incident from its reports and response notes for responders and reviewers to verify.
Root-cause assistance
Suggests candidate root causes from the incident detail and similar prior incidents, which the team investigates and confirms.
Severity suggestion
Proposes an initial severity from the reported impact against your criteria, which the responder reviews and sets.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Capture
An incident is logged through one intake — reported, detected or escalated — with its type, description and initial impact.
Triage
The incident is assessed against defined severity and impact criteria, prioritised, and assigned to an owner.
Contain & respond
Response moves through defined stages, with any notification deadlines tracked on the record from the outset.
Resolve
The immediate issue is resolved and the resolution documented, closing the operational impact.
Root cause & lessons
The underlying cause is established and lessons learned recorded, with remediation actions raised against exposed risks and controls.
Close & feed back
The incident closes with its full record preserved, its risk and control links updated, and its remediation tracked to completion.
What your team gains
A reliable view of what went wrong
A single intake and register replace scattered emails and chat threads, so the firm actually knows its incident history.
Prioritised by real impact
Criteria-based triage means the most serious incidents get the urgent response, consistently and demonstrably.
Notification deadlines met
Notification clocks tracked from the moment an incident opens keep an operational problem from becoming a compliance breach.
Weaknesses fixed, not repeated
Documented root cause, lessons learned and remediation actions turn painful incidents into improvements that stop recurrence.
Reality feeds the risk register
Linking incidents to risks and controls updates the firm's risk picture with what actually happened, not just what was assumed.
Defensible incident response
Because triage, response, notification and root cause are all on the record, showing you handled an incident properly is retrieval.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Raises incidents automatically from your existing monitoring, security and operational alerting systems
- Links incidents to the risks and controls held in your enterprise-risk and internal-controls modules
- Connects to your existing service-management and ticketing tools so operational response stays aligned
- Aligns incident ownership and response roles with your existing identity provider and directory
- Routes incident alerts, escalations and status updates through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Incident records, evidence and response detail are encrypted in transit and at rest.
- Role-based access controls who can view, respond to and close an incident, with need-to-know restrictions on sensitive incidents.
- Incidents involving personal-data breaches can be handled under tighter access with the sensitivity flagged on the record.
- Every report, triage decision, action and closure is written to an append-only audit trail.
- Notification deadlines and the actions taken against them are preserved as evidence of timely response.
- Data residency and retention for incident records are configurable to your regulatory obligations.
Compliance support
- Supports operational-incident capture and response expectations under operational-resilience regimes
- Underpins regulatory and contractual breach-notification obligations with deadline tracking
- Supports data-breach incident handling and the associated notification duties
- Feeds operational-risk loss-event and root-cause requirements
- Provides documented, timestamped evidence of incident response for audit and examination
Reports & exports
- Incident register with severity, status and outcome
- Incident volume, severity and trend reports
- Notification-deadline adherence reports
- Root-cause and lessons-learned summaries
- Remediation-action status against exposed risks and controls
- Incident management information for risk committees and the board
How to get the most from it
One front door for incidents
Insist that every incident, however minor, enters through the single intake. A reliable incident picture depends on nothing being logged off to the side.
Triage against criteria, not instinct
Assess severity against defined impact criteria so prioritisation is consistent and defensible, rather than a function of who happened to assess it.
Start the notification clock immediately
Record notification obligations the moment an incident is known. Deadlines tracked from the start are met; deadlines remembered later are missed.
Close on root cause, not symptom
Require a documented root cause and remediation before closure. An incident fixed but not understood is an incident you will see again.
Questions, answered
What counts as an incident here?
Any event that disrupts operations, breaches a control or obligation, or exposes a risk — an outage, a data breach, a process failure, a security event. The intake and triage are designed to handle the full range consistently, with severity determining the response.
How are notification deadlines handled?
When an incident type carries a regulatory or contractual notification obligation, the deadline is tracked on the record from the moment the incident opens, with reminders and escalation, so the firm meets the deadline rather than discovering it after the fact. The firm remains responsible for the notification itself.
How do incidents connect to our risk register?
Each incident links to the risks it crystallised and the controls it exposed, and can raise remediation actions against them. That feeds the enterprise-risk and internal-controls modules, so your risk picture reflects what has actually happened.
Does closing an incident require root cause?
By configuration, yes — closure can require a documented root cause and lessons learned, so the discipline of understanding why is enforced rather than optional. That is what turns incident response into genuine improvement.
Is OnyxOne deciding how to respond to an incident?
No. The platform structures the response, tracks obligations and surfaces links to risks and controls, but the response team makes the decisions and owns them. OnyxOne is decision-support and record-keeping software, not an automated responder.
Related modules
See Incident Management in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.