Cybersecurity · Response
Incident Response Planning and Support
The first hour of an incident determines much of what follows. Organizations with a written plan contain the damage and preserve evidence. Organizations without one lose time deciding who to call, and often destroy the evidence their insurer will later ask for.
We prepare the plan, rehearse the decisions and provide the technical response when something happens.
The problem
What goes wrong in the first hour
The instinctive reactions are usually the harmful ones: wiping and rebuilding the affected machine, resetting one password and returning to work, or leaving systems running for days while people debate. Each of those destroys evidence or extends the intrusion.
There is also a practical obstacle. Cyber-insurance policies typically require notification within a defined window and the use of the insurer's approved responders. Engaging outside help before notifying can affect coverage — and the policy document is often stored on the file server that has just been encrypted.
A plan solves ordinary problems: who has authority to disconnect systems, whose phone number is called at 11pm, where the offline copy of the credentials and contacts lives, and what is said to clients.
What we do
Preparation and live response
- 01
Write the plan for your organization
A concise document naming the incident lead, the technical lead, the communications owner and the person authorised to take systems offline, together with severity definitions and the first actions for each type of event.
- 02
Record the obligations
Insurer notification requirements and contacts, legal counsel, privacy-breach considerations under Canadian requirements, and any contractual notification duties owed to clients.
- 03
Keep it reachable
Printed and offline copies of the plan, contact tree and critical credentials, because a plan stored only on an encrypted file server is not a plan.
- 04
Contain correctly
During an incident: isolate rather than wipe, revoke sessions and reset credentials in the right order, preserve logs and disk images, and identify the entry point before rebuilding.
- 05
Recover in a known order
Restore from verified clean backups following the agreed priority sequence, validating integrity as systems return rather than restoring everything at once.
- 06
Review honestly afterwards
A written timeline, root cause, and specific changes — configuration, process or training — with dates and owners, so the same route is not available next time.
Rehearsal
Tabletop exercises find the gaps cheaply
We walk leadership through a realistic scenario — an encrypted file server on a Sunday, or a finance mailbox compromise discovered after a payment left — and work through the decisions in sequence. These sessions reliably expose the things a document alone will not: nobody knows the insurance policy number, the only person who can authorise a shutdown is on holiday, or the plan assumes an internet connection that will not be available.
An hour of rehearsal usually changes the plan more than a week of drafting it.
- Ransomware scenario
- Mailbox compromise and payment fraud
- Lost or stolen device
- Cloud account takeover
- Extended outage at a single site
- Third-party or supplier breach
Where this fits
Assurance work like this sits alongside the day-to-day controls described on our St. Catharines cybersecurity page.
Questions
Frequently asked questions
- Who should we call first during an incident?
- For managed clients, us — and in parallel your insurer's breach line if you carry cyber coverage, because policies usually require prompt notification and may direct which responders are used. The plan we prepare records both numbers and the order.
- Should we pay a ransom?
- That decision belongs to leadership with legal and insurer input, and it is not a technical recommendation we make. Our role is to establish whether recovery is possible from clean backups, which is usually the strongest position to negotiate from — or to avoid negotiating at all.
- We are not a managed client. Can you still help?
- Yes. We take incident engagements for organizations we do not otherwise support, and we will work alongside your insurer's appointed responders. Call (289) 667-4000 and say it is an active incident.
Keep reading
Related cybersecurity services
- Identity & Access ManagementMFA, Conditional Access, privileged accounts and joiner-mover-leaver control.
- Email SecurityStopping invoice fraud, impersonation and credential-harvesting mail.
- Ransomware ProtectionBlocking the intrusion path and keeping a recovery option that survives it.
- Endpoint Detection & ResponseBehavioural detection and isolation on laptops, desktops and servers.
- Managed Detection & ResponseAnalysts watching the alerts overnight so a detection becomes an action.
- Vulnerability ManagementContinuous discovery, risk ranking and verified remediation.
Next step
Talk to Griffin IT Group about your St. Catharines IT environment
Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.
