Bringing in a vCISO after a breach
After an incident, buy two different things from two different parties: incident response, which is forensics and containment billed by the hour, and security leadership, which is the person who answers to your board, your customers and the Privacy Commissioner for the next two quarters. Companies that buy one and assume it covers the other are the ones still explaining themselves a year later.
An embedded vCISO for a quarter after an incident costs $12,000 to $25,000 CAD a month, and a lighter arrangement running the aftermath rather than the response costs $6,000 to $12,000 CAD a month. That is separate from digital forensics and incident response, which is billed hourly at $400 to $700 CAD an hour or bought as a pre-paid retainer, and separate again from breach counsel. Keep the three apart because they answer to different people. Forensics answers a technical question, counsel protects privilege, and the vCISO owns what the company does next.
If it is happening right now
This page is about the weeks after, not the first six hours. If you are in an active incident, the order is: contain, engage breach counsel so the investigation runs under privilege, engage forensics through counsel, and notify your insurer before you spend money you want covered. Most cyber policies require the insurer's approved panel, and paying your own firm first is a common and expensive mistake.
What a vCISO does in the eight weeks after
The response ends and the consequences start. Almost everything that determines how much the incident costs you happens after the technical work is finished, and it is executive work.
| Week | What has to happen | Owner |
|---|---|---|
| 1 to 2 | Containment verified independently, scope of affected records established, notification decisions made and documented | Forensics and counsel, with the vCISO translating for the executive team |
| 2 to 4 | PIPEDA real risk of significant harm assessment written down, notifications to the Privacy Commissioner and affected individuals if the threshold is met, breach record opened | Counsel decides, the vCISO produces the evidence and keeps the record |
| 2 to 6 | Customer communication, contractual notification clauses honoured, and the wave of questionnaires and audit requests that follows | vCISO, and this is where the hours actually go |
| 3 to 8 | Root cause understood as a management failure rather than a technical one, and a remediation plan with dates and owners | vCISO |
| 4 to 10 | Board and insurer reporting, including what changed so it does not happen again | vCISO, using the board report template |
| 8 to 26 | The remediation actually landing, and the program that should have existed before | vCISO on a normal retainer, or an internal hire |
The row that surprises executives is the customer communication one. Companies budget for forensics and forget that a breach at a B2B company generates a security review from every large customer at once, each with its own questionnaire, each with a deadline, and several with a contractual right to audit. That work alone can consume a full retainer for two months.
The Canadian obligations a vCISO owns
These are the duties most American post-incident material does not cover, and they are the ones a Canadian regulator will ask about.
- PIPEDA breach reporting
- Where a breach of security safeguards creates a real risk of significant harm, you must report to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible. The assessment of whether that threshold is met has to be written down at the time, because "we decided it was not reportable" is only defensible if you can show the reasoning.
- The 24 month breach record
- PIPEDA requires you to keep a record of every breach of security safeguards for 24 months, reportable or not, and to give it to the Commissioner on request. Knowingly failing to report or to keep records carries fines of up to $10,000 CAD on summary conviction and up to $100,000 CAD on indictment. This is the duty companies forget, and it is the easiest thing in the world for a regulator to check.
- Quebec Law 25
- A confidentiality incident presenting a risk of serious injury must be reported to the Commission d'acces a l'information and to affected individuals, and a register of confidentiality incidents must be kept. Law 25 penalties are materially higher than PIPEDA's. If you have Quebec customers or staff, this applies regardless of where you are headquartered.
- Provincial health privacy
- Ontario's PHIPA and the equivalent statutes elsewhere add their own notification duties, and in Ontario a duty to report certain breaches to the regulating college of the custodian. Health data changes the whole timetable.
- Contractual notification
- Frequently stricter than the law. Enterprise agreements commonly require notification within 24 to 72 hours of discovery, and missing that is a contract problem regardless of whether the incident was reportable.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Why the responder should not write the report
The firm that ran your containment has an interest in the conclusion. Not a dishonest one, usually, but a real one: their report describes work they did and decisions they made under pressure. Having the same party assess root cause, grade the response and recommend the remediation spend is the same conflict as a managed provider recommending its own tooling, and boards and insurers have started noticing.
The workable split is that forensics establishes what happened, and an independent vCISO decides what it means and what changes. It also solves a practical problem: the forensics firm leaves when the invoice is paid, and the remediation takes six months. Someone has to still be there. The engagement shapes are compared on vCISO engagement models.
What the aftermath costs
| Item | Typical range | Notes |
|---|---|---|
| Digital forensics and incident response | $25,000 to $150,000 | Hourly at $400 to $700. Insurer panel firms are often covered |
| Breach counsel | $15,000 to $80,000 | Engage first so the investigation runs under privilege |
| Embedded vCISO, one quarter | $36,000 to $75,000 | Two to three days a week while the aftermath is live |
| Ongoing vCISO retainer after that | $6,000 to $12,000 per month | Program leadership through remediation |
| Notification and credit monitoring | $3 to $12 per individual | Only where individuals are notified. Scales badly |
| Remediation tooling and work | $50,000 to $400,000 | The largest and least predictable line |
| Independent post-incident review | $15,000 to $45,000 | Increasingly asked for by insurers and large customers |
Check your policy before assuming any of this is covered. Cyber policies commonly cover forensics, counsel and notification, and commonly do not cover security leadership or remediation, on the grounds that those are improvements rather than losses. The retainer is usually an operating expense you carry.
What not to do in the first month
- Do not fire someone in week one. It looks like accountability and it is usually the fastest way to lose the person who understands the environment, and it teaches everyone else not to report the next thing early.
- Do not buy tooling before root cause is established. Post-incident is when security budgets are approved without argument, which is why the spending is worst then.
- Do not commit publicly to a cause before forensics has finished. Retracted statements do more damage than late ones.
- Do not skip the written assessment of whether the harm threshold was met. A defensible decision not to notify is worth a great deal, and an undocumented one is worth nothing.
- Do not let the remediation plan live only in the incident report. Move it into a risk register with owners and dates, or it stops being tracked by the second quarter.
Then what
The quarter of embedded work should end with a decision, not a renewal by default. Either the company has enough continuous security work to justify a permanent leader, in which case the path is on moving from a vCISO to a full-time CISO, or it does not, and the arrangement should step down to a normal advisory retainer at a quarter of the cost. A provider who does not raise that conversation at the end of the quarter is managing their revenue rather than your program.
What to do on day one, day three and day fourteen, including preserving evidence before cleanup and the PIPEDA record you must keep for 24 months, is on the first two weeks after a security incident.
Find a vCISO for the aftermath
Tell us what happened, what your customers are asking for, and what your insurer expects. We will put it in front of Canadian providers who have done the post-incident quarter before.
Get matchedCommon questions
Do we need a vCISO after a breach, or just an incident response firm?
Both, and they do different jobs. The incident response firm establishes what happened and helps contain it, then leaves. The vCISO owns everything that follows: notification decisions and their documentation, customer and board communication, the remediation plan, and the program that should have existed. The response is measured in days and the aftermath in quarters.
How quickly must a Canadian company report a breach?
Under PIPEDA, as soon as feasible after determining that a breach creates a real risk of significant harm, both to the Privacy Commissioner and to the affected individuals. There is no fixed hour count, but "as soon as feasible" has been read strictly, and delay while you decide is hard to defend. Quebec's Law 25 has an equivalent prompt duty. Contractual clauses with large customers are often stricter than either, commonly 24 to 72 hours from discovery.
How long should the post-incident engagement run?
A quarter of embedded work, then a deliberate step down. The heavy load is weeks two to ten, and by month four the work looks like a normal program with an unusually attentive board. Committing to twelve months of embedded pricing during the panic of week one is how companies end up paying $200,000 CAD a year for advisory work.
Will insurance pay for the vCISO?
Usually not. Cyber policies typically cover forensics, breach counsel, notification and sometimes public relations, and treat security leadership and remediation as improvements rather than covered losses. Ask your broker before you sign anything, and get any approval in writing, because paying a firm outside the insurer's panel can affect coverage of the parts that would otherwise be paid.
Should the same person who ran the response write the post-incident review?
No. The responder is assessing their own decisions, and boards and insurers increasingly ask who wrote the review. Have forensics establish the facts and an independent security leader assess what those facts mean for the program. It also solves the practical problem that the forensics firm leaves and the remediation takes six months.