SECURITY INCIDENT LOG Incident ID: SEC-2026-0042 Classification: MEDIUM Status: OPEN Date Reported: 22 February 2026 Reported By: Marcus Bell, Engineering Director Affected User: David Mitchell (EMP-2847), david.mitchell@acmecorp.co.uk INCIDENT DESCRIPTION: Employee used personal Gmail account (david.mitchell.personal@gmail.com) to transmit work documents due to corporate VPN instability. Documents transmitted included: - Henderson Group API specification (CONFIDENTIAL) - Internal network topology diagram (INTERNAL) - Project Neptune database schema (CONFIDENTIAL - GBP 340K project) RISK ASSESSMENT: - Personal email does not meet ACME Corp Data Handling Policy (DHP-003) - Henderson contract Section 14.2 requires all project data to remain within approved ACME systems - Potential breach of client confidentiality obligations - No customer PII confirmed in transmitted files REMEDIATION ACTIONS: 1. [PENDING] David Mitchell to permanently delete all work files from personal Gmail by 25 February 2026 2. [COMPLETE] VPN issue escalated to infrastructure team (Tomasz Kowalski, ext 4421) 3. [PENDING] Data handling refresher training for David Mitchell 4. [PENDING] VPN reliability root cause analysis by 1 March RELATED PARTIES: - Tomasz Kowalski (EMP-4400) — Infrastructure lead, investigating VPN issue - Richard Henderson — Client sponsor, Henderson Group. Not yet notified. - Geoff Harrison — VPN provider account manager, geoff.harrison@securenet.co.uk APPROVALS: - Investigating Officer: IT Security Team (itsec@acmecorp.co.uk) - Incident Owner: Marcus Bell - HR Notified: Linda Thompson (22 Feb 2026) No disciplinary action recommended at this stage. To be reviewed at next quarterly security meeting (18 May 2026).