HireACISO

Incident response plan: a Canadian guide

A useful incident response plan is two to six pages, names people rather than roles, and is readable by someone woken at three in the morning. The fifty page version exists to pass a questionnaire. Both can be true at once, but only one of them will be open during an incident.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

For a Canadian company the notification section is the hardest part of an incident response plan. At least four clocks can run at once: PIPEDA's real risk of significant harm assessment, Quebec's Law 25 where you touch Quebec data, contractual windows you agreed to in large deals, and provincial health privacy law if you hold health information. Writing those clocks into one table is the single highest-value hour of work in the whole plan.

A vCISO writing a real plan and running the tabletop that tests it is $6,000 to $18,000 CAD as a standalone piece of work, or four to eight hours a month inside a retainer. Standalone deliverable pricing is on fractional CISO services.

Why the short plan wins

Long plans are written for an auditor, filed, and never read again. By the time an incident happens the named people have left, the phone numbers are stale and the tooling described no longer exists. The plan that works is short enough to review in fifteen minutes every quarter.

What each version of the plan is for
The short planThe long document
Length2 to 6 pages30 to 60 pages
AudienceWhoever is awakeAn auditor or a customer's diligence team
ContainsNames, numbers, severity, clocks, first four actionsPolicy language, roles, scope, references, appendices
ReviewedQuarterly, in fifteen minutesAnnually, by one person, under duress
Open during an incidentYesNo

Write the short one first and let the long one be its policy wrapper. Doing it the other way round produces a fifty page document with a two page summary nobody trusts. The summary and the body disagree by month six.

What goes in the short plan

The decision log is the deliverable nobody plans for

Every retrospective assessment of an incident, by a regulator, an insurer, an auditor or a customer, turns on what you knew and when you decided. A timestamped log kept during the incident by someone whose only job is writing it down is worth more afterwards than most of the technical work. Assign that person in the plan. Assign them during the incident and it will be whoever is least useful.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Severity levels that mean something

Severity levels in business terms, with the response each triggers
LevelLooks likeTriggers
SEV1 Customer data confirmed exposed, production down for customers, or an active intruder with access now Executive team convened within one hour, counsel engaged, board chair told same day, insurer notified
SEV2 Credible exposure not yet confirmed, one customer affected, or a significant internal compromise Incident commander appointed, counsel on standby, executive update within four hours
SEV3 Contained internal issue, no customer impact, no data movement found Normal working hours, logged, reviewed weekly

Three levels is enough for almost every company under 500 people. Five levels means the first twenty minutes of every incident is an argument about which level applies. All three definitions are about customers and data rather than servers, because the decisions the plan drives are business decisions.

The Canadian notification clock table

Copy this into your plan and fill the last column with your own contractual windows. Getting this wrong is more likely to cost you money than any technical failure during the response.

Notification obligations that can run simultaneously for a Canadian company
ObligationTriggerTiming
PIPEDA, to the Privacy Commissioner and individuals Breach of security safeguards creating a real risk of significant harm As soon as feasible after the determination. Write the assessment down either way
PIPEDA breach record Any breach of security safeguards, reportable or not Kept 24 months, produced to the Commissioner on request
Quebec Law 25 Confidentiality incident presenting a risk of serious injury Prompt notification to the Commission d'acces a l'information and affected individuals, plus a register of incidents
Provincial health privacy, such as PHIPA Unauthorised access to personal health information At the first reasonable opportunity, with additional duties for custodians
Customer contracts Discovery, usually, not materiality Commonly 24 to 72 hours. Frequently your shortest clock
Cyber insurance policy Notice of circumstances Immediately, and before engaging firms outside the panel
Securities disclosure, if you file in the US Determination of materiality Four business days on Form 8-K. See SEC cyber disclosure
OSFI, if federally regulated Reportable technology or cyber incident Prompt notification to your lead supervisor. See OSFI regulated institutions

Availability, and what a monthly retainer does not buy

A vCISO retainer at $5,000 CAD a month does not buy round the clock incident availability, and a provider claiming it does is either not going to honour it or has priced it somewhere you have not found. Know which of the three arrangements you have.

Business hours advisory
The normal retainer. Your vCISO is a phone call during the day and a judgement layer over the response. Fine for most companies, and it should be written in the contract rather than assumed.
A separate incident response retainer
Pre-paid hours with a specialist firm, typically $10,000 to $40,000 CAD a year, buying a guaranteed response time and, more usefully, a firm that has already onboarded to your environment. The onboarding is most of the value.
Insurer panel only
Free until you use it, slower to start, and constrained to the panel. It is a real option for a small company and should be a deliberate choice rather than a discovery made at two in the morning.

Contract terms around availability are covered on the vCISO contract checklist, and the aftermath, which is where the real cost lives, is on bringing in a vCISO after a breach.

The tabletop is the part that works

A plan that has never been exercised is a hypothesis. Two hours, once a year at minimum, with the actual executive team in the room rather than the security team playing all the parts. Cost is $8,000 to $20,000 CAD facilitated externally, and less inside a retainer.

  1. Pick a scenario with an ugly decision in it, not a clean one. Ransomware where the backups are good is a bad exercise, because it has no argument in it.
  2. Include the notification decision, not just containment. Most companies discover here that counsel and the security lead disagree about what "material" or "real risk of significant harm" means.
  3. Put the CEO in the room. Without them the exercise never surfaces who is in charge.
  4. Time-box it and stop when it breaks. An exercise that reaches the end of the script cleanly has taught you nothing.
  5. Write the findings into the plan the same week, and into your risk register if they need funding.

If you are reading this because something has already happened rather than to prepare, stop here and go to the first two weeks after an incident, the day by day version for a founder with no security team.

Get an incident plan written and tested

A plan and a tabletop is a fixed-scope piece of work. Tell us your size and your obligations and we will get Canadian providers to quote it.

Get matched

Common questions

What should a Canadian incident response plan contain?

Named people with phone numbers, who can declare an incident, three severity levels defined by customer and data impact, the first four actions for whoever finds it, a communication channel that works when your network does not, when counsel and the insurer are engaged, a table of every notification clock that can apply to you, and where the decision log lives. Two to six pages. Anything longer is a policy document, which is a different thing with a different purpose.

How often should we test the incident response plan?

A two hour tabletop annually is the floor, and twice a year is better if you handle sensitive data or have large customers with audit rights. Also test it whenever the incident commander changes, because the plan depends more on that person than on anything written in it. Reviewing the names and numbers quarterly takes fifteen minutes and prevents the most common failure.

Does PIPEDA require an incident response plan?

Not by name. PIPEDA requires safeguards appropriate to the sensitivity of the information, reporting of breaches creating a real risk of significant harm, and a record of every breach of security safeguards kept for 24 months. Meeting the record-keeping duty reliably without a plan is difficult, which is why the plan is effectively expected even though the statute does not name it.

Should the incident plan be a public document?

No, but a one paragraph description of it usually should be, on your trust page or in your security overview. Enterprise buyers ask whether you have one, when it was last tested and what your notification commitment is. Answering those three in public removes them from a large share of questionnaires, which is worth real money at scale.

Who should be the incident commander?

Someone with authority to spend money and stop shipping, which usually rules out the most technical person in the room. The common and effective split is a business incident commander who runs the decisions and communication, and a technical lead who runs the response. If your vCISO is the commander, be clear that they are business-hours unless you have bought something more, and name an internal deputy who is not.