Module 14 / 15
🚨

Responding Effectively to a Security IncidentUpdated: 2026

From a phishing email to active ransomware: learn to recognize, contain, and report any cyber incident with the right habits.

⏱️ ~20 min
πŸ“š 8 lessons
🎯 Beginner
🎯 Module objective

By the end of this module, you'll be able to…

  • Recognize and qualify a security incident
  • Apply the steps of an incident response plan
  • Report an incident to the relevant authorities (RCMP, Canadian Centre for Cyber Security)
  • Recover your systems from backups safely
  • Document and learn from an incident to prevent recurrence
1

What is a security incident?

A security incident is any event that compromises the confidentiality, integrity, or availability of your information or systems. It doesn't have to be an active attack: it can be a detected attempt, an accidental data leak, or a confirmed compromise.

Common incident types

  • Ransomware: your files are encrypted and a ransom is demanded
  • Successful phishing: an employee clicked a link and entered their credentials
  • Unauthorized access: a suspicious login detected on an account or server
  • Data leak: customer or internal information has been exposed
  • Active malware: malicious software detected on a device
Key takeawayBetter to report an incident that turns out to be minor than to ignore a real compromise. The cost of not reacting is always higher.
2

The first 60 minutes β€” the habits that matter

The first hour after detecting an incident is critical. Your actions in this window determine the extent of the damage, the preservation of evidence, and the speed of recovery.

βœ“ The 4 golden rules of the first 60 minutes

  • Isolate immediately β€” disconnect the infected device from the network (Wi-Fi and Ethernet cable). Prevent lateral spread.
  • Don't power off the device β€” unless it's your only option. RAM holds valuable, volatile forensic evidence.
  • Don't panic β€” hasty mistakes make things worse. Breathe, follow your plan.
  • Document right now β€” note the exact time of detection, what you saw, what you did. Take photos of the screen.

βœ— Common mistakes to avoid

  • Restarting the computer "to see if it clears up" β€” erases traces in memory
  • Telling everyone at once by email β€” the attacker may be monitoring your inbox
  • Trying to remove the malware yourself without expertise β€” risks erasing evidence
  • Continuing to work normally, hoping it resolves itself
3

Contain without destroying β€” preserving evidence

Containment aims to limit the spread without destroying the evidence needed to identify the attacker, understand what happened, and β€” in the case of litigation or an insurance claim β€” document the harm.

βœ“ Containment procedure

  • Disconnect the device from the network without turning it off (unplug the cable, disable Wi-Fi)
  • Photograph every screen before any intervention β€” ransom messages, alerts, visible logs
  • Save system logs if accessible (Windows event logs, Linux syslog)
  • Identify other devices on the same network that might be compromised
  • Change the passwords of exposed accounts β€” from a clean device, not the infected one
  • Write everything down: times, actions, people involved β€” this timeline will be invaluable
Key takeawayA compromised device is a crime scene. Preserve evidence like an investigator would. Don't clean anything without an expert's approval.
4

Who to call β€” the escalation chain

Depending on the severity and nature of the incident, several parties need to be contacted, in the right order.

βœ“ Recommended escalation chain

  • 1. Internal IT team or provider: first move β€” they have access to your infrastructure
  • 2. Canadian Centre for Cyber Security: cyber.gc.ca β€” reporting and free technical support for Canadian organizations
  • 3. RCMP: for any cybercrime β€” data theft, ransomware, fraud. Portal: rcmp-grc.gc.ca
  • 4. Your bank: immediately if financial data or banking access is compromised
  • 5. Privacy officer / legal counsel: to assess your legal reporting obligations
  • 6. Cyber insurer: if you have a cyber policy β€” document everything before any intervention

For SMBs without an IT team: the Canadian Centre for Cyber Security offers a helpline for Canadian organizations: 1-833-CYBER-88.

5

Legal reporting in Canada β€” your obligations

In Canada, breach notification is governed by several laws. Not knowing them can worsen your legal exposure.

βœ“ Canadian legal framework

  • PIPEDA (Personal Information Protection and Electronic Documents Act): requires federally regulated businesses to report any breach presenting a real risk of significant harm to the Office of the Privacy Commissioner of Canada (OPC) and to affected individuals β€” as soon as feasible.
  • Law 25 (Quebec): requires reporting to the CAI (Commission d'accΓ¨s Γ  l'information) within 72 hours for any incident involving personal information that presents a risk of serious harm.
  • Other provinces: Alberta (PIPA) and British Columbia have similar obligations. Check the law that applies to your province.
  • Financial and health sectors: additional obligations under FINTRAC, provincial health laws, etc.

βœ— Common legal mistakes

  • Waiting to be 100% certain before reporting β€” the clock starts at the moment of detection
  • Downplaying the scope of the breach in the report β€” worsens penalties
  • Failing to notify affected individuals β€” a separate legal obligation from reporting to authorities
  • Destroying evidence before an investigation β€” obstruction of justice
6

Recovering from backups β€” the 3-2-1 rule

Recovery only begins once the incident is contained and the threat eliminated. Recovering onto a still-compromised system is like mopping a floor in the rain.

βœ“ The 3-2-1 rule

  • 3 copies of your data (the original + 2 backups)
  • 2 different media (e.g., external drive + cloud)
  • 1 offsite copy (cloud or a different physical location)
  • Test your backups regularly β€” an untested backup isn't a reliable backup

βœ— Ransomware: DO NOT pay

  • Paying doesn't guarantee data recovery β€” 40% of victims who pay recover nothing
  • Paying funds criminal groups and encourages new attacks
  • Your organization becomes a known "payer" target β€” expect a repeat attack
  • The decryption key provided may itself contain malware
Key takeawayYour best defense against ransomware is a recent, tested, offline backup. Prepare it today β€” not after the incident.
7

Internal and external communication β€” stay factual

Managing communication during and after an incident is just as critical as the technical response. Poor communication can worsen the crisis, cause unnecessary panic, or expose your organization to additional legal risk.

βœ“ Crisis communication principles

  • Centralize: designate a single spokesperson. Avoid spontaneous communications from multiple employees.
  • Be factual: communicate what you know with certainty. Avoid speculation.
  • Communicate early: better to say "we're investigating an incident" than to let rumors spread.
  • Protect your channels: if email is compromised, use an alternate channel for internal communications.

βœ— Template for notifying affected individuals

  • "Subject: Important notice regarding the security of your information"
  • Describe what happened, when, and what information was affected
  • Explain what you're doing to resolve the issue
  • List the steps affected individuals can take to protect themselves
  • Provide a contact for questions β€” and keep it current
8

After the incident β€” lessons learned and improvement

The post-incident phase is often neglected, but it's what turns a crisis into organizational learning. A well-run post-mortem (or after-action review) significantly reduces the risk of recurrence.

βœ“ Running the post-mortem

  • Full timeline: reconstruct events from detection to resolution
  • Root cause: identify the initial vulnerability β€” not to assign blame, but to fix it
  • Real impact: data affected, downtime, estimated cost
  • Corrective actions: list the changes to make, with an owner and a date
  • Update the response plan: fold the lessons into your documentation
Key takeawayThe post-mortem isn't a blame session. Its goal is to understand systemically what failed and turn it into a more robust process.
Scenario β€” SMB hit by ransomware

Situation: Monday morning, 8:30 AM, Marie, director of a 12-employee SMB, turns on her computer. All her files have a .locked extension. A message demands $15,000 in Bitcoin within 48 hours.

Decision 1 β€” Isolate immediately: Marie unplugs her computer from the network without turning it off. She asks employees not to turn on their computers until the scope is known. Result: 3 additional computers would have been encrypted had the network stayed active.

Decision 2 β€” Photograph and document: Marie takes photos of the ransom message with her phone, notes the exact time (8:31 AM). This evidence will be essential for insurance and the RCMP.

Decision 3 β€” Call the Canadian Centre for Cyber Security: cyber.gc.ca provides immediate guidance, confirms the identified ransomware group, and recommends an incident response provider. Don't pay β€” this group has a publicly available decryption key.

Decision 4 β€” Check the backups: The backup on the local NAS is encrypted (it was connected to the network). The previous week's cloud backup is intact. Data loss: 5 days of work. Recovery cost: 2 days of expert time + restoration. Ransom paid: $0.

Lesson: A disconnected (offline) backup would have cut the loss to nearly zero. The 3-2-1 rule is non-negotiable.

Module quiz

Test what you've learned with 4 questions.

See also