Triage the alert and set an appropriate severity
Start a time-stamped incident record and appoint an incident lead, a KSeF business owner and a technical owner. Recommended practice is to treat confirmed copying or public exposure of a production private key as high severity; credible access by an unauthorised person, malware on its host, an unexplained export or loss of a device holding it also warrants urgent containment. A false-positive scanner alert, an inaccessible backup or a certificate nearing expiry may justify investigation without immediately declaring misuse. Record what was observed, by whom, when, and whether the key could sign offline invoices or authenticate to KSeF. In the first 15 minutes, stop further distribution and preserve volatile evidence; within the first hour, identify the serial number, type and deployments, choose a clean authorised revocation route, and assess invoicing continuity. These are incident-response targets, not statutory KSeF deadlines. Do not delay a justified revocation merely to finish attribution, but do not revoke a look-alike certificate based only on a filename. Severity should reflect exposure confidence, privilege path, production use, duration, deployment breadth and signs of suspicious invoice activity.