HireACISO

First two weeks after a security incident

Do not delete anything, do not promise customers a cause in the first 48 hours, and start the record now. At a company with no security team the first two weeks are mostly about evidence, counsel and honest communication.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

You have had a security incident, you have no security team, and you are the person deciding what happens next. Three things matter in the first 48 hours: preserve evidence before you clean up, engage a lawyer on day one, and tell customers what you know without naming a cause you cannot yet support.

This is not an incident response plan. If nothing has happened yet, write one instead: the incident response plan page covers what goes in it, and it is four pages of work, not a project.

The single most common mistake

Reimaging the affected machine to get the employee working again. It destroys the evidence and makes the next four questions unanswerable: what was accessed, when, for how long, and whether it is still happening. Without that you cannot tell a customer or a regulator anything true. Snapshot first, then rebuild.

Days one and two: contain and preserve

  1. Stop the deletion. Tell everyone in writing to preserve logs, emails, machines and messages. Turn on any cloud logging that is not retained by default. Snapshot before you touch anything.
  2. Call a lawyer. Canadian privacy counsel or a firm with a cyber practice, on day one, before you hire an investigator. Retaining the investigator through counsel is how the investigation stays privileged, and it cannot be done retroactively.
  3. Notify your insurer. Cyber policies have notification windows measured in days and most require you to use their panel of responders. Calling your own firm first can cost you coverage. If you do not have a policy, note that now for the follow-up plan.
  4. Rotate credentials and revoke sessions. Administrative accounts, cloud keys, service tokens, single sign-on sessions. Write down every action with a timestamp as you go, because you will be asked to reconstruct this later and memory will not do it.
  5. Assign one person to the log. Not the person doing the technical work. A single running document with times, decisions and who made them is the artifact that everything afterward depends on.
  6. Say something internally. Staff who hear nothing will speculate, and the speculation reaches customers. Tell them what is known, what is not, and who is allowed to speak externally.

Days three to seven: scope and reporting duties

By the end of the first week you need a defensible answer to what data was involved, and a decision on what you are legally required to report. In Canada that is not one question.

Canadian notification duties a small company assesses in week one
TriggerWho you notifyTiming
PIPEDA breach of security safeguards creating a real risk of significant harm The Privacy Commissioner of Canada and the affected individuals As soon as feasible
Any PIPEDA breach of security safeguards, harmful or not Nobody, but you must keep a record of it Record retained 24 months
Personal information of Quebec residents, under Law 25 The Commission d'acces a l'information and affected individuals Promptly, with its own register
Ontario health information, under PHIPA The Information and Privacy Commissioner of Ontario and individuals At the first reasonable opportunity
Contractual notification clauses with business customers Each customer, per their contract Often 24 to 72 hours, and often missed
Cyber insurance policy conditions Your insurer or broker Days, per policy

The row founders overlook is the fifth. Enterprise contracts routinely contain a 24 or 72 hour notification clause, and those clocks run from discovery, not from the end of your investigation. Have someone read the security addendum of your five largest contracts on day two. The federal duties are set out on PIPEDA breach reporting, and the practical steps on privacy breach response in Canada.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What do you tell customers?

Say what you know, say what you do not know, and say when you will speak again. A short update with a next date beats a detailed one that turns out to be wrong, and it is the wrong one that gets quoted back at you.

Three things not to write in the first week. Do not name a root cause before the investigation supports it. Do not say no customer data was affected unless someone can demonstrate it from logs. The retraction is worse than the original disclosure. And do not promise a remediation date you have not costed, because you will be held to it at renewal.

Days eight to fourteen: the record and the plan

By day fourteen you should have two documents. You will be asked for both over the next two years: by customers, by insurers, by an auditor, by an acquirer during diligence.

What does the first two weeks cost?

Canadian dollars, at a company of 15 to 80 people, and heavily dependent on whether personal information was involved.

Typical first fortnight costs for a small Canadian company, CAD
ItemCost, CADNotes
Privacy or cyber counsel$5,000 to $25,000Higher if notification is required and multi-jurisdiction
Digital forensics and incident response$15,000 to $75,000Often covered by insurance if you use the panel
Interim security leadership for a small team, embedded$12,000 to $25,000 per monthTwo to three days a week, usually for one quarter
Customer notification and support loadInternal timeThe largest hidden cost, absorbed by founders and support
Remediation engineeringHighly variableBudget it in the plan rather than discovering it
First fortnight, common range$20,000 to $100,000Before remediation

Embedded leadership is the one line here worth its price at a small company, and only for a quarter. Someone senior in the room daily while you are containing, notifying and rebuilding is a different purchase from an advisory retainer, and it should step down by month four. Bringing in a vCISO after a breach covers how that engagement is scoped and where it goes wrong.

Get someone senior in the room this week

Tell us what happened and what you have contained so far. We will point you at Canadian providers who do incident leadership rather than forensics, and tell you which of the two you actually need.

Get matched

Common questions

Do we have to tell the Privacy Commissioner?

Under PIPEDA you must report a breach of security safeguards to the Office of the Privacy Commissioner of Canada and notify affected individuals where the breach creates a real risk of significant harm. That assessment considers the sensitivity of the information and the probability of misuse. Separately, you must keep a record of every breach of security safeguards for 24 months whether or not it was reportable, and the Commissioner can ask for those records. Make the assessment with counsel and write down the reasoning either way.

Should we pay a ransom?

That is a decision for counsel, your insurer and the executive team together, and it is not primarily a technical question. What matters operationally is that paying does not discharge any notification duty, does not guarantee the data is destroyed, and carries sanctions screening obligations. Do not let anyone open that conversation without counsel involved.

Can we handle this without hiring anyone?

A small incident with no personal information, contained quickly, with good logs, sometimes yes. Anything involving personal information, ransomware, or a period of unauthorised access you cannot bound should have counsel and an outside responder. The reason is not technical capability. It is that your own people cannot credibly investigate an incident they may have contributed to, and customers will ask who did the work.

Our customers are asking for a report. What do we give them?

A written summary of what happened, what data was involved, what you have done, and what you are changing with dates. Not the forensic report itself, which is usually privileged and which your counsel will tell you not to distribute. Prepare one version and send the same one to everyone, because different accounts of the same incident circulating between customers is a problem that compounds.

What should change after the fourteen days?

Name an accountable owner and give them protected time, write the incident response plan you did not have, and fix the two or three things the incident exposed rather than launching a program. Companies that respond to an incident by starting a certification usually stall, because the certification does not address the thing that happened. Assigning the owner is the step that makes the rest stick.