Skip to content
IT White GloveManaged IT support · Advisory · Canada
Menu

Incident response guide · Canada · EN / FR

Decide the first hour before you need it, not during it.

Ce guide est aussi tenu en français. Plan d’intervention →

Security spending gets most of the attention; what happens in the first hour after someone clicks a malicious link gets far less. An incident response plan is not a security product—it is a small set of decisions made in advance about who is called, what gets isolated, and how staff actually know what to do.

The decision to enable

Decide who is the first call, what gets isolated immediately, and what proves staff training actually works—before an incident forces improvisation.

Name the first call before the first incident

The minutes immediately after someone suspects a compromised account or a malicious attachment matter more than almost anything that happens afterward. Confirm, in writing, who staff contact first, what that person is authorized to do immediately, and how that path works outside business hours.

  • Who staff contact the moment something looks wrong
  • What that first contact is authorized to do without further approval
  • Whether the path works evenings and weekends, not just during office hours

Decide what gets isolated immediately, and who can authorize it

Disconnecting a device from the network, disabling an account, or blocking a sender can stop a small problem from spreading—but someone needs the authority to do it immediately, not after a meeting is scheduled. Name that authority in advance, separate from who investigates afterward.

Define what “trained” actually proves

Security awareness training that staff click through once a year proves attendance, not readiness. Decide what evidence would actually show staff can recognize a real attempt—a simulated phishing test, a reporting rate, or a recent real example reviewed as a team—rather than a completion certificate alone.

  • What specific behaviour the training is meant to produce
  • How that behaviour is actually tested, not just taught
  • What happens when someone reports a false alarm—confirming they are encouraged, not discouraged, to report

Rehearse the plan before an incident, not during one

A plan that has only ever existed as a document is an assumption, not a capability. Walk through a plausible scenario—a compromised email account, a suspicious attachment already opened—and confirm each named person actually knows their part before it is tested for real.

Decision frame

What leadership should be able to verify.

These criteria do not produce a score. They expose the questions that need resolution before a responsible decision.

CriterionUseful signalLeadership question
First callStaff know exactly who to contact first, at any hour.If this happened at 6 p.m. on a Friday, who would actually get the call?
Isolation authoritySomeone is authorized to disconnect or disable immediately, without a meeting.Who can disable an account or isolate a device right now, without waiting for approval?
Training evidenceAwareness training is measured by behaviour, not completion alone.What evidence shows staff would actually recognize a real attempt?
RehearsalThe plan has been walked through, not only written down.When was this plan last tested against a realistic scenario?

Practical scenarios

The same discipline applied to different decisions.

An employee clicks a convincing phishing link on a Friday afternoon

Situation: An employee realizes, after the fact, that a link they clicked asked for their credentials and they entered them.

Useful response: Follow the pre-agreed first call and immediate isolation steps—password reset, session revocation, and a check for further access—rather than waiting until Monday because the moment felt too small to escalate.

Boundary: This guide does not perform incident response or forensic investigation; it frames the decisions to have ready before one is needed.

Annual security awareness training has a 100% completion rate but incidents keep happening

Situation: Every employee completed the required annual training, yet staff continue to fall for realistic phishing attempts.

Useful response: Treat completion rate as the wrong metric, and test actual recognition behaviour instead—a simulated attempt, a reporting rate, or a short review of a real recent example—to see what the training is actually producing.

Boundary: This guide does not select or evaluate a specific training platform or vendor.