Identity-verification incident response
Identity incidents need both security containment and fair treatment of people whose onboarding, account or credential may be affected. Prepare evidence, decision rights, provider contacts and user communications before a bypass or outage occurs.
Applicable notification duties depend on the incident, organisation and sector. This operational checklist does not determine whether a specific event is reportable.
For: incident response, fraud, DPO, identity operations, legal and communications teams. This is independent information, not legal, compliance or security advice.
Scenarios
- New document, biometric or injection bypass.
- False-accept or false-reject spike after a model/threshold change.
- Provider or trust-service outage.
- Credential issuer, key, wallet or status-service compromise.
- Exposure of documents, images, templates or logs.
- Malicious or erroneous manual-review activity.
First actions
- Preserve relevant evidence and establish scope.
- Stop or constrain the affected flow without destroying safe access alternatives.
- Contact the provider through the contractual incident route.
- Identify affected decisions, accounts, credentials and people.
- Assess legal, regulatory, contractual and user-notification duties.
- Plan correction, re-verification and redress.
Do not punish legitimate users
A response may invalidate sessions or require re-proofing. Design it to avoid unnecessary document recollection, inaccessible deadlines or unexplained account closure, and provide staffed escalation for disputed outcomes.
Learn and re-open safely
Document root cause, control failure, vendor evidence, decision timeline and corrective action. Re-test the exact production path, update the threat model/DPIA and monitor for recurrence before returning to normal operation.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- ENISA Remote Identity Proofing: Attacks and Countermeasures
- NIST SP 800-63A-4 identity proofing
- General Data Protection Regulation
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing