← Back

EC Ransomware Malware Destructive Event Response Policy

03_policy_library/ec_ransomware_malware_destructive_event_response_policy.md

Employee Center Ransomware, Malware, and Destructive Event Response Policy

No Raw Database Data Claim

For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.

This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.

Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policies Hub: /legal/policies

Policy URL: /legal/policies/policies/ransomware-malware-destructive-event-response-policy


1. Purpose

This policy explains how EC may respond to ransomware, malware, sabotage, destructive deletion, credential compromise, unauthorized encryption, or similar destructive events.

2. Covered Events

Covered events include ransomware, malware, malicious deletion, unauthorized encryption, backup destruction, repository tampering, database corruption, credential theft, malicious scripts, destructive automations, suspicious exports, device compromise, and insider sabotage.

3. Immediate Response

Quintin N. Mahan may immediately isolate systems, disable accounts, revoke sessions, rotate credentials, disable APIs, disable integrations, stop jobs, preserve evidence, take snapshots, restore backups, change hosting, or disconnect affected systems.

4. Evidence Preservation

Logs, backups, files, memory of events, timestamps, user activity, network activity, and related records may be preserved for investigation, legal defense, law enforcement, insurance, or owner/admin purposes.

5. Restoration

Restoration order, timing, source, and scope are controlled by Quintin N. Mahan.

Restoration is not guaranteed to be immediate, complete, or loss-free.

6. User Duties

Users must report suspicious files, messages, popups, account activity, device compromise, lost devices, malware warnings, or suspected credential exposure promptly.

7. No Interference

Users and companies may not delete evidence, wipe devices, rotate owner/admin credentials, destroy backups, or interfere with incident response.


Changes to This Policy

Quintin N. Mahan may update this policy by publishing a new active version in EC.

The current active version will be displayed through the Legal hub or Policies hub.

Older versions may remain stored in Postgres for audit, evidence, legal history, and historical review.


Contact / Owner

Employee Center is owned by Quintin N. Mahan.

Legal and policy documents are available from:

/legal

Policy documents may be organized at:

/legal/policies

The current Terms and Conditions are available from:

/legal/terms-and-conditions

End of Employee Center Ransomware, Malware, and Destructive Event Response Policy.