Cybersecurity · Response

Incident Response Planning and Support

The first hour of an incident determines much of what follows. Organizations with a written plan contain the damage and preserve evidence. Organizations without one lose time deciding who to call, and often destroy the evidence their insurer will later ask for.

We prepare the plan, rehearse the decisions and provide the technical response when something happens.

The problem

What goes wrong in the first hour

The instinctive reactions are usually the harmful ones: wiping and rebuilding the affected machine, resetting one password and returning to work, or leaving systems running for days while people debate. Each of those destroys evidence or extends the intrusion.

There is also a practical obstacle. Cyber-insurance policies typically require notification within a defined window and the use of the insurer's approved responders. Engaging outside help before notifying can affect coverage — and the policy document is often stored on the file server that has just been encrypted.

A plan solves ordinary problems: who has authority to disconnect systems, whose phone number is called at 11pm, where the offline copy of the credentials and contacts lives, and what is said to clients.

What we do

Preparation and live response

  1. 01

    Write the plan for your organization

    A concise document naming the incident lead, the technical lead, the communications owner and the person authorised to take systems offline, together with severity definitions and the first actions for each type of event.

  2. 02

    Record the obligations

    Insurer notification requirements and contacts, legal counsel, privacy-breach considerations under Canadian requirements, and any contractual notification duties owed to clients.

  3. 03

    Keep it reachable

    Printed and offline copies of the plan, contact tree and critical credentials, because a plan stored only on an encrypted file server is not a plan.

  4. 04

    Contain correctly

    During an incident: isolate rather than wipe, revoke sessions and reset credentials in the right order, preserve logs and disk images, and identify the entry point before rebuilding.

  5. 05

    Recover in a known order

    Restore from verified clean backups following the agreed priority sequence, validating integrity as systems return rather than restoring everything at once.

  6. 06

    Review honestly afterwards

    A written timeline, root cause, and specific changes — configuration, process or training — with dates and owners, so the same route is not available next time.

Rehearsal

Tabletop exercises find the gaps cheaply

We walk leadership through a realistic scenario — an encrypted file server on a Sunday, or a finance mailbox compromise discovered after a payment left — and work through the decisions in sequence. These sessions reliably expose the things a document alone will not: nobody knows the insurance policy number, the only person who can authorise a shutdown is on holiday, or the plan assumes an internet connection that will not be available.

An hour of rehearsal usually changes the plan more than a week of drafting it.

  • Ransomware scenario
  • Mailbox compromise and payment fraud
  • Lost or stolen device
  • Cloud account takeover
  • Extended outage at a single site
  • Third-party or supplier breach

Where this fits

Assurance work like this sits alongside the day-to-day controls described on our St. Catharines cybersecurity page.

Questions

Frequently asked questions

Who should we call first during an incident?
For managed clients, us — and in parallel your insurer's breach line if you carry cyber coverage, because policies usually require prompt notification and may direct which responders are used. The plan we prepare records both numbers and the order.
Should we pay a ransom?
That decision belongs to leadership with legal and insurer input, and it is not a technical recommendation we make. Our role is to establish whether recovery is possible from clean backups, which is usually the strongest position to negotiate from — or to avoid negotiating at all.
We are not a managed client. Can you still help?
Yes. We take incident engagements for organizations we do not otherwise support, and we will work alongside your insurer's appointed responders. Call (289) 667-4000 and say it is an active incident.

Next step

Talk to Griffin IT Group about your St. Catharines IT environment

Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.