How you respond in the first hours after discovering a breach significantly affects both the damage caused and your legal obligations.
1. Contain It
Isolate affected systems, change compromised credentials, and stop the ongoing exposure before anything else.
2. Assess the Scope
Determine what data was actually accessed or exposed, and for how long, before deciding on next steps.
3. Understand Your Legal Obligations
Under PIPEDA, breaches posing a real risk of significant harm must be reported to the Office of the Privacy Commissioner and affected individuals — know this requirement before an incident happens, not during one.
4. Communicate Transparently
Clear, honest communication with affected customers, even when the news is bad, protects trust far better than silence or delay.
5. Learn and Harden
Once contained, a thorough post-incident review identifies exactly how the breach happened, so the same gap doesn't get exploited again.
Español
Deutsch