Skip to content

The 30 incident.io security checks Black Cat runs

Black Cat SSPM evaluates 30 security policies against your incident.io configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect incident.io — what access Black Cat needs, and why.

Access control & privilege (5)

Data sharing & exposure (3)

Logging & audit (11)

Governance & compliance (7)

Other checks (4)

severity: medium IP Allowlist Disabled fix difficulty: medium #

Enable the IP allowlist in Incident.io security settings to restrict access to trusted IP ranges

  1. Sign in to Incident.io and navigate to Settings > Security
  2. Locate the IP allowlist section and click to configure
  3. Add all trusted IP ranges (CIDR notation) that should have access
  4. Toggle the allowlist to enabled
  5. Verify that legitimate users on approved networks can still sign in

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: high IP Allowlist Enabled With No Rules fix difficulty: medium #

Add at least one IP allowlist rule or disable the allowlist to restore access to Incident.io

  1. Sign in to Incident.io from a network that still has access (e.g., via direct DB or support channel)
  2. Navigate to Settings > Security and open the IP allowlist section
  3. Add the CIDR ranges for all trusted office networks and VPN exit nodes
  4. Verify each entry is correctly formatted before saving
  5. Save the rules and confirm that users on approved networks can authenticate
  6. If no rules can be determined immediately, disable the allowlist temporarily until rules are defined

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: medium Workflow Has No Steps fix difficulty: easy #

Add at least one action step to workflows that currently have none or remove the workflow if it is unused

  1. Sign in to Incident.io and navigate to Workflows
  2. Open the workflow flagged by this policy
  3. Click "Edit" and navigate to the steps section
  4. Add the appropriate action steps (e.g., send Slack message, create ticket, page on-call)
  5. If the workflow serves no current purpose, delete it to reduce noise in the workflow list
  6. Save and enable the workflow, then test with a triggering event

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium User No Slack Linked fix difficulty: easy #

Link a Slack account to each Incident.io user so they receive real-time incident notifications and can interact with incidents from Slack

  1. Sign in to Incident.io and navigate to Settings > Users
  2. Find the user flagged by this policy
  3. Ask the user to connect their Slack account through their Incident.io profile settings
  4. If the Slack integration is not configured, navigate to Settings > Integrations and set up the Slack integration first
  5. Verify the user's Slack user ID appears in their profile after linking

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial