Incident response runbooks · Free, in full
The first hour
What to do in the sixty minutes after you realise something has gone wrong — and which Canadian clocks start running the moment you do.
Complete, free, and yours to share inside your organisation. Print it and keep it somewhere reachable without a working computer. Aussi disponible en français.
Three rules before you touch anything
- One person coordinates. Name them out loud. Everything else goes wrong when four people are independently phoning the same supplier.
- Do not destroy evidence. Isolate machines, do not wipe them. Do not delete the phishing email. Logs you overwrite today are the logs your insurer and the regulator will ask for.
- Promise nothing yet. Not to customers, not to staff, not on social media. You do not know the scope in the first hour, and a correction later costs more trust than an hour of silence.
The first sixty minutes
0–15 minutes · Stop the bleeding
- Name the coordinator and open a written log. Time-stamp every entry from now on.
- Isolate affected systems from the network. Disconnect, do not power off — memory holds evidence.
- Disable or reset the credentials you believe were used, including any session tokens.
- Check whether backups are reachable and, critically, whether they are also affected.
- Tell your cyber insurer’s hotline if you hold a policy. Many policies require notice before you engage anyone.
15–30 minutes · Work out what you are dealing with
- What exactly happened, in one sentence you would be comfortable reading back in six months.
- Which systems, which accounts, which data. Write down what you know and what you are guessing.
- Was personal information involved, or might it have been? This is the question that starts the legal clocks.
- Is it still happening? An incident that is contained and one that is live need different next moves.
- Does a supplier or customer need to know because their systems are exposed through yours?
30–60 minutes · Decide and notify
- Work through the notification decision tree below. Decide, and record why you decided it.
- Start the record the law requires whether or not you end up notifying anyone.
- Brief one person to handle all external questions. Everyone else refers to them.
- Tell the board or owner. A short factual note now is worth more than a polished one tomorrow.
- Book the post-incident review before you finish the call. It will not happen otherwise.
The notification decision tree
Two regimes can apply at once. Federal law and Quebec law ask different questions, use different thresholds and keep records for different lengths of time. Work through both — not one or the other.

This tree covers private-sector organisations. Federally regulated sectors, public bodies and health information custodians carry additional obligations. It is a starting point for your own legal advice, not a substitute for it.
What not to do
- Do not pay a ransom before taking advice. It may be a sanctions offence, and it rarely restores everything.
- Do not email about the incident using the system you think is compromised.
- Do not tell anyone the incident is closed until you know how the attacker got in.
- Do not let “we are still investigating” become the reason you miss a notification deadline. The clock does not pause.
- Do not skip the record because you decided not to notify. The record is required either way.
What to write down
When you became aware
Both retention clocks run from a date you must be able to state.
What happened
In plain words. Regulators read these; so do customers, eventually.
Personal information involved
Categories and approximate number of people. Say “unknown” if it is unknown.
Harm assessment
Your reasoning, not just your conclusion. The reasoning is what gets tested.
Who was notified, and when
Regulator, individuals, other organisations, insurer, customers.
What you changed
The control you fixed. This is what turns an incident into an improvement.
Why this one is free
If it is useful at two in the morning, it has done its job.
This is a complete extract from our incident response runbooks, not a teaser. You can print it, share it inside your organisation, and use it without buying anything. We publish work in full because it is the only honest way to let you judge whether the rest is worth paying for.
And the rule we hold ourselves to, in writing: we will not carry out an independent assessment of a management system built on documents we sold you. A runbook is a procedure, not a management system, so buying one does not prevent us from assessing you — the full licence terms set out exactly where that line falls.
Practical tip
Marc Tremblay
The moment an incident starts, write down the time you became aware of it. Every clock a regulator later asks about runs from that moment, and nobody can ever remember it afterwards.
Quebec cyber and privacy governance · the people who do the work
The rest of the incident response runbooks
The full module covers ransomware, business email compromise, a lost or stolen device, data exposed by mistake, and a supplier’s breach becoming yours — each on a single page, with the evidence to keep and the mistakes people make. Available in English and French.