The 30 incident.io security checks Black Cat runs
Black Cat SSPM evaluates 30 security policies against your incident.io configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.
How to connect incident.io — what access Black Cat needs, and why.
Access control & privilege
5 checks · highest severity: high
Data sharing & exposure
3 checks · highest severity: high
Logging & audit
11 checks · highest severity: high
Governance & compliance
7 checks · highest severity: medium
Access control & privilege (5)
- Excessive Admins severity: high
- Single Account Owner severity: medium
- User Without Base Role severity: medium
- User Has Custom Roles But No Base Role severity: medium
- User With Excessive Custom Roles severity: low
Data sharing & exposure (3)
- Workflow Accesses Private Data severity: high
- Public Status Page severity: low
- Workflow Unconstrained on All Incidents severity: medium
Logging & audit (11)
- Single Responder Escalation severity: high
- Single Rotation Schedule severity: medium
- Schedule Without Active Shift severity: high
- Workflow Disabled or Error severity: medium
- Workflow Ignores Step Errors severity: low
- Alert Source No Auto-Resolve severity: low
- Alert Route No Escalation Path severity: high
- Alert Route No Grouping severity: low
- Escalation Path No Current Responders severity: high
- Alert Source Auto-Resolve Timeout Too Long severity: medium
- Escalation Path Shallow severity: medium
Governance & compliance (7)
- Alert Source Unowned severity: medium
- Alert Route No Conditions severity: medium
- Escalation Path No Team Assignment severity: medium
- Schedule No Team Assignment severity: medium
- Active Workflow Never Updated severity: low
- Schedule Missing Timezone severity: low
- Schedule No Holiday Configuration severity: low
Other checks (4)
severity: medium IP Allowlist Disabled fix difficulty: medium #
Enable the IP allowlist in Incident.io security settings to restrict access to trusted IP ranges
- Sign in to Incident.io and navigate to Settings > Security
- Locate the IP allowlist section and click to configure
- Add all trusted IP ranges (CIDR notation) that should have access
- Toggle the allowlist to enabled
- Verify that legitimate users on approved networks can still sign in
Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 CIS Controls v8 CIS-12.1 NIST CSF 2.0 PR.IR GDPR (SaaS Security) GDPR-5.1f.i HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9
severity: high IP Allowlist Enabled With No Rules fix difficulty: medium #
Add at least one IP allowlist rule or disable the allowlist to restore access to Incident.io
- Sign in to Incident.io from a network that still has access (e.g., via direct DB or support channel)
- Navigate to Settings > Security and open the IP allowlist section
- Add the CIDR ranges for all trusted office networks and VPN exit nodes
- Verify each entry is correctly formatted before saving
- Save the rules and confirm that users on approved networks can authenticate
- If no rules can be determined immediately, disable the allowlist temporarily until rules are defined
Satisfies: ISO 27001:2022 A.8.20 SOC 2 Type II CC6.6 NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9
severity: medium Workflow Has No Steps fix difficulty: easy #
Add at least one action step to workflows that currently have none or remove the workflow if it is unused
- Sign in to Incident.io and navigate to Workflows
- Open the workflow flagged by this policy
- Click "Edit" and navigate to the steps section
- Add the appropriate action steps (e.g., send Slack message, create ticket, page on-call)
- If the workflow serves no current purpose, delete it to reduce noise in the workflow list
- Save and enable the workflow, then test with a triggering event
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC7.2 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium User No Slack Linked fix difficulty: easy #
Link a Slack account to each Incident.io user so they receive real-time incident notifications and can interact with incidents from Slack
- Sign in to Incident.io and navigate to Settings > Users
- Find the user flagged by this policy
- Ask the user to connect their Slack account through their Incident.io profile settings
- If the Slack integration is not configured, navigate to Settings > Integrations and set up the Slack integration first
- Verify the user's Slack user ID appears in their profile after linking
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10