Answer
Organizations must rapidly detect, contain, investigate, recover, and appropriately notify stakeholders following documented incident response procedures that distinguish mature organizations from unprepared ones.
Security incidents and data breaches are unfortunate realities of modern cybersecurity—no organization can guarantee perfect prevention regardless of security investments. What distinguishes mature organizations from unprepared ones is how they respond when incidents occur.
CPCSC requires organizations to have incident response capabilities that enable rapid detection, effective containment, thorough investigation, complete recovery, and appropriate notification. Understanding incident response requirements helps executives prepare their organizations to handle security incidents professionally and minimize damage.
What Constitutes a Security Incident
Security incidents are adverse events that compromise confidentiality, integrity, or availability of systems or information.
Confirmed incidents include the following:
- Malware infections by ransomware, viruses, trojans, or spyware
- Unauthorized access to systems by external attackers or unauthorized insiders
- Data breaches involving theft or unauthorized disclosure of specified information
- Denial of service attacks that disrupt system availability
- System compromises where attackers gain persistent access
- Insider threats involving malicious employee actions
- Physical security breaches like theft of devices containing specified information
- Loss of mobile devices, laptops, or storage media containing specified information
Suspected incidents include the following:
- Unusual network traffic or system behavior suggesting possible compromise
- Security tool alerts indicating potential attacks
- Reports from personnel about suspicious activities
- Intelligence from external sources about threats targeting your organization
- Discovery of unauthorized changes to systems or data
Both confirmed and suspected incidents require investigation and response—waiting for absolute proof before responding allows attackers time to expand access and cause greater damage. Organizations should err toward investigating suspicious activity rather than dismissing potential incidents.
ITSP.10.171 Incident Response Requirements
The Incident Response family in ITSP.10.171 includes comprehensive requirements:
- Implement incident-handling capability that is consistent with incident response plan and includes preparation, detection and analysis, containment, eradication, and recovery
- Track and document system security incidents
- Report suspected incidents to organizational incident response capability within defined time period
- Report incident information to defined authorities (including government customers if specified information is affected)
- Provide incident response support resource that offers advice and assistance to system users for handling and reporting incidents
- Test effectiveness of incident response capability at defined frequency
- Provide incident response training to system users consistent with assigned roles and responsibilities before assuming incident response role, when required by system changes, and at defined frequency thereafter
- Develop incident response plan that provides roadmap for implementing incident response capability, describes structure and organization, addresses information sharing, designates responsibilities, and protects plan from unauthorized disclosure
- Update incident response plan to address system and organizational changes or problems encountered
- Distribute copies of plan to designated incident response personnel
These requirements establish expectation that incident response is planned, resourced, tested, and capable rather than improvised during crisis.
Incident Response Phases
Effective incident response follows structured phases:
- Preparation before incidents occur through incident response plan development, incident response team formation and training, security tool deployment for detection and analysis, documented procedures and playbooks, established communication channels, and relationships with external parties (law enforcement, external investigators, legal counsel)
- Detection and analysis using security monitoring to identify potential incidents, initial triage to confirm incidents vs. false positives, scope determination to understand what systems and data are affected, and severity rating to prioritize response
- Containment using short-term containment to stop incident expansion (disconnecting affected systems, blocking attacker IP addresses, disabling compromised accounts), and long-term containment establishing control while maintaining business operations (patching vulnerabilities, implementing additional security controls)
- Eradication removing adversary presence through malware removal, closing attack vectors, eliminating attacker access, and addressing root causes that enabled the incident
- Recovery through system restoration from clean backups, system rebuild when compromise is extensive, security verification before returning systems to production, and enhanced monitoring during recovery period
- Post-incident activity including lessons learned review, security improvement implementation, incident documentation, and updating incident response procedures based on experience
Organizations should document these phases in incident response plans and train teams on procedures for each phase.
Incident Response Team Structure
Effective response requires coordinated teams with clear roles:
- Incident commander provides overall leadership, makes key decisions, coordinates between teams, and communicates with executive management
- Technical response team conducts technical investigation, performs containment and eradication, manages recovery, and provides forensic analysis—typically IT security personnel
- IT operations team provides system administration support, assists with containment and recovery, provides technical knowledge of affected systems, and implements technical changes
- Communications team manages internal communications to employees and external communications to customers, media, or public while coordinating with legal counsel on messaging
- Legal counsel advises on legal obligations, manages law enforcement coordination, handles regulatory notification, and addresses liability issues
- Human resources addresses insider threat incidents, manages personnel implications, and coordinates with legal on employment actions
- Executive management provides authority for major decisions, allocates resources, and approves external communications
- Business unit representatives provide business context, prioritize recovery activities, and communicate with affected business operations
For smaller organizations, single individuals might fill multiple roles, but responsibilities should be explicitly assigned.
External parties may support incident response depending on severity:
- Forensic investigators
- Legal counsel specializing in data breach
- Public relations firms
- Cyber insurance carriers
- Law enforcement
Containment Strategies
Rapid containment limits incident damage. Organizations should have pre-planned containment procedures for common incident types rather than inventing responses during crisis.
Containment strategies include the following:
- Network isolation disconnects affected systems from networks to prevent adversary lateral movement—balance containment against business impact
- Account disablement deactivates compromised user accounts to prevent further unauthorized access
- System shutdown powers off systems if severe compromise threatens critical data or other systems—save volatile memory for forensic analysis before shutdown
- Firewall rules block adversary IP addresses, command-and-control domains, or malicious traffic patterns
- Email blocking addresses incoming phishing emails, filters malicious content, or quarantines suspicious messages
- Password resets force credential changes system-wide if widespread compromise is suspected
- Access restrictions limit who can access systems during incident to prevent further compromise
The containment strategy depends on incident nature—ransomware might require network isolation; data exfiltration might require egress filtering; credential compromise might require password resets.
Containment decisions balance security (stopping attackers) against business continuity (maintaining operations)—senior management often must make these judgment calls.
Evidence Preservation and Forensics
Proper evidence handling enables investigation and potential prosecution.
Evidence preservation protects digital evidence from alteration or destruction through the following:
- Forensically sound imaging of affected systems
- Preservation of log files before they're overwritten
- Documentation of volatile system state (memory contents, active network connections)
- Chain of custody documentation tracking evidence handling
Forensic analysis examines evidence to determine what happened, how attackers gained access, what they did during compromise, what information was accessed or stolen, whether attackers maintain persistent access, and how to prevent recurrence.
Forensic investigation requires specialized skills and tools—many organizations engage external digital forensic firms for complex incidents.
Evidence may be needed for law enforcement prosecution, civil litigation, insurance claims, regulatory proceedings, or internal disciplinary actions—proper preservation maintains legal admissibility.
Organizations should document evidence handling procedures and ensure incident responders understand basics of evidence preservation even if detailed forensic analysis is outsourced.
Notification and Reporting Requirements
Security incidents often trigger notification obligations. Organizations should document notification obligations in incident response plans, including who must be notified, what information must be provided, and what timelines apply.
Notification requirements include the following:
- Internal notification to incident response team, senior management, legal counsel, and affected business units should occur promptly per incident response plan
- Government customer notification is typically required for contracts involving specified information when incidents affect that information—contracts specify notification timelines (often 24-72 hours)
- Privacy breach notification is mandatory under Canadian privacy law when incidents involve personal information—affected individuals, Privacy Commissioner of Canada, and potentially provincial regulators must be notified when harm is reasonably foreseeable
- Law enforcement notification is advisable for criminal incidents, though mandatory only in limited circumstances—coordinate through legal counsel
- Cyber insurance carrier notification per insurance policy terms to preserve coverage—delayed notification might void coverage
- Regulatory notification to sector-specific regulators depending on industry
- Public disclosure may be required or advisable depending on incident severity, stakeholder impact, and reputational considerations—coordinate with legal counsel and public relations
Failure to notify properly can result in contractual breaches, regulatory penalties, insurance coverage loss, or reputational damage beyond the incident itself.
Recovery and Restoration
Returning to normal operations safely requires careful recovery. Organizations should test recovery procedures regularly through tabletop exercises or simulations to ensure procedures work and teams are prepared.
Recovery activities include the following:
- System restoration from clean backups taken before compromise ensures attacker presence is removed—verify backup integrity before restoration
- System rebuild when extensive compromise makes restoration untrustworthy involves reinstalling operating systems and applications from known-good sources and applying all security patches
- Configuration hardening addresses vulnerabilities that enabled initial compromise before returning systems to production
- Security verification through vulnerability scanning, configuration review, and testing confirms systems are secure before production use
- Enhanced monitoring during recovery period detects if attackers return or if eradication was incomplete
- Incremental restoration prioritizes critical systems for recovery while thoroughly cleaning less critical systems
- User credential resets if compromise involved credential theft forces users to establish new passwords
Recovery time objectives balance speed with thoroughness—hasty recovery that leaves attacker access enables re-compromise, while excessively slow recovery impacts business.
Privacy Breaches
Incidents involving personal information require special handling under Canadian privacy law. A privacy breach occurs when personal information is subject to loss of control, unauthorized access or disclosure, unauthorized copying or use, or unauthorized modification.
Breach assessment determines the following:
- What personal information was affected
- How many individuals are impacted
- Whether harm is likely (identity theft, fraud, damage to reputation, etc.)
- What caused breach
- Whether notification is required
Notification thresholds under Breach of Security Safeguards Regulations require notifying Privacy Commissioner of Canada and affected individuals if breach creates real risk of significant harm—organizations must assess this for each incident.
Notification content must include the following:
- Circumstances of breach
- Date or time period
- Description of personal information involved
- Steps taken to reduce risk
- Steps individuals can take to reduce harm
- Contact information for inquiries
Notification timing should be as soon as feasible after organization determines real risk of significant harm exists—unnecessary delays violate legal obligations.
Record keeping requires documenting all breaches regardless of whether notification was required, including details of breach, assessment of harm risk, notification decisions, and remedial actions.
Privacy breaches can result in regulatory investigation, fines, civil litigation by affected individuals, and reputational damage. Organizations should engage privacy counsel for significant breaches involving personal information.
Lessons Learned and Improvement
Post-incident review drives security improvement. Organizations should treat incidents as learning opportunities that drive security maturity rather than just problems to be solved and forgotten.
Post-incident activities include the following:
- Lessons learned session brings together incident response participants to discuss what happened, what worked well, what didn't work, what should change, and what lessons apply
- Root cause analysis identifies underlying causes that enabled incident rather than just proximate causes—address systemic issues, not just symptoms
- Security control improvements implement lessons learned through enhanced security controls, policy changes, training improvements, or technology additions
- Incident response procedure updates refine procedures based on what worked or didn't during response
- Documentation captures incident details, response timeline, decisions made, and outcomes for future reference and compliance demonstration
- Sharing lessons within organization prevents recurrence across other systems or business units
- Potential industry sharing (anonymized) contributes to collective defense—information sharing organizations exchange anonymized threat intelligence
Regular review of incident trends helps executives understand whether security investments are effective and what additional investments are warranted.
Learn More
Additional resources are available for further guidance: