incident.io data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On incident.io, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.
Checks (3)
severity: high Workflow Accesses Private Data fix difficulty: medium #
Disable private incident and escalation access in Incident.io workflow settings unless strictly required
- Sign in to Incident.io and navigate to Workflows
- Open the workflow flagged by this policy
- Click "Edit" on the workflow configuration
- Locate the privacy settings and uncheck options for private incident or escalation access
- Save the workflow and confirm it no longer references private data unless justified
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.12
severity: low Public Status Page fix difficulty: easy #
Review whether public status page exposure is intended and restrict access if not required
- Sign in to Incident.io and navigate to Status pages
- Open the status page flagged by this policy
- Click "Settings" or "Edit" on the status page
- If public exposure is not required, change the visibility to private or internal
- Save the change and verify the status page is no longer publicly accessible
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-5.1f.iii HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium Workflow Unconstrained on All Incidents fix difficulty: medium #
Add conditions to workflows that run on all incidents without filters to limit unintended data exposure
- Sign in to Incident.io and navigate to Workflows
- Open the workflow flagged by this policy
- Click "Edit" and navigate to the conditions section
- Add at least one condition group to restrict which incidents trigger this workflow
- Consider filtering by severity, type, or team to limit scope
- Save the workflow and test with a sample incident to confirm conditions apply
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11