Back to Blog
Cybersecurity8 min read

CCCS Baseline Control #1: A Practical Incident Response Plan for Canadian SMBs

By Anton Kuznetsov

Most Canadian SMBs spend their security budget on tools before spending time on plans. A firewall is installed, an antivirus subscription is activated, and MFA may be rolled out. What most organizations do not create is the document that determines whether any of those tools actually limit damage when something goes wrong: the incident response plan.

Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime found that only 26% of Canadian businesses had written cybersecurity policies in place — unchanged from 2021, despite two years of escalating attacks. Statistics Canada, The Daily — Impact of cybercrime on Canadian businesses, 2023 That same year, 16% of Canadian businesses experienced a cyber security incident. A significant share of those organizations had no written guidance for how to respond.

The Canadian Centre for Cyber Security addressed this gap directly: incident response planning is listed as Control #1 in its Baseline Cyber Security Controls for Small and Medium Organizations. Not MFA. Not patching. The plan. CCCS, Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089)

Why the CCCS Puts Incident Response Planning First

The CCCS applied the 80/20 rule when designing its baseline controls: find the 20% of effort that delivers 80% of security improvement. Incident response planning ranked first because its absence multiplies the cost of every other security failure.

A business without a plan that suffers a ransomware attack will improvise: employees alert each other verbally, someone calls whoever they think might help, a security firm is located through a web search hours later. Meanwhile, the attacker has had additional hours — sometimes days — to encrypt more files, establish persistence, and exfiltrate data.

IBM Security's 2025 Cost of a Data Breach Report quantified this precisely. Organizations with a tested incident response plan save an average of USD $2.66 million per breach compared to organizations without one — the single largest cost-reduction factor in the report, ahead of zero-trust architecture ($1.76M saved) and law enforcement involvement ($990K saved). IBM Security, Cost of a Data Breach Report 2025

The same report found that the average data breach against a Canadian organization cost CA$6.98 million — a 10.4% year-over-year increase. Recovery spending by Canadian businesses as a whole doubled to $1.2 billion in 2023 alone. Statistics Canada, CSCSC 2023 A documented and practiced response is the highest-leverage control available to reduce that number.

What the Verizon DBIR 2026 Shows About Response Speed

The 2026 Verizon Data Breach Investigations Report analyzed more than 31,000 security incidents and found that the average breach takes 241 days from initial compromise to full containment — 181 days to identify and 60 days to contain.

The cost difference by containment speed is significant: breaches contained within 200 days average $3.87 million; those exceeding 200 days average $5.01 million — a $1.14 million penalty for slow response. Response speed is not primarily determined by the sophistication of your security tools. It is determined by whether your team knows exactly what to do when an alert fires at 2 a.m. on a Saturday.

An incident response plan directly compresses the detection-to-containment lifecycle by eliminating the hours of confusion that occur at the start of every unplanned response.

What PIPEDA and Quebec Law 25 Require When a Breach Happens

When a breach creates a "real risk of significant harm" to individuals, Canadian privacy law creates notification obligations that begin immediately after the organization becomes aware of the incident.

Under PIPEDA, organizations must:

  • Report to the Office of the Privacy Commissioner as soon as feasible after determining that a reportable breach has occurred, with documentation of what happened, what personal information was involved, and what remediation steps have been taken. OPC, Guidance on mandatory breach reporting
  • Notify affected individuals directly, with enough information for them to understand the risk and take protective action.
  • Maintain breach records for a minimum of 24 months, including breaches that did not meet the reporting threshold.

Failure to notify the OPC of a qualifying breach can result in fines of up to $100,000 CAD per offence.

Organizations with Quebec operations face a tighter timeline under Law 25. A breach involving a Quebec resident must be reported to the Commission d'accès à l'information within 72 hours of becoming aware. Penalties under Law 25 reach $10 million CAD or 2% of worldwide turnover, whichever is greater.

In 2024-2025, the OPC received 686 breach reports under PIPEDA from private-sector organizations — a record, and a clear signal that breach notification compliance is receiving increasing regulatory attention. OPC, Annual Report to Parliament 2024-2025

Without a documented breach notification procedure embedded inside the incident response plan, meeting the PIPEDA "as soon as feasible" obligation or Quebec's 72-hour clock under active incident conditions is not reliably achievable. The plan is the mechanism that makes compliance possible under pressure.

What the CCCS Guidance Requires in the Plan

Two CCCS publications define what an effective incident response plan must contain:

  • ITSAP.40.003 (*Developing Your Incident Response Plan*): Defines the core components — preparation, detection and analysis, containment, eradication and recovery, and post-incident review. CCCS, ITSAP.40.003
  • ITSM.10.014 (*Improving Cyber Security Resilience Through Emergency Preparedness Planning*, effective January 2026): Frames emergency preparedness as the integration of three documents — an incident response plan, a business continuity plan, and a disaster recovery plan — that together define an organization's resilience posture. CCCS, ITSM.10.014

The five phases the CCCS identifies:

Preparation — Define roles and responsibilities in writing before an incident happens. Maintain an up-to-date asset inventory. Establish an out-of-band communication method for use when primary systems are compromised. Identify external contacts (IR retainer, legal counsel, cyber insurer breach hotline) and confirm those contacts can be reached on a weekend.

Detection and Analysis — Define what constitutes an incident and how severity levels are classified. A ransomware encryption event is critical; a single suspicious phishing email is minor. Each severity level should activate a different response path and notification sequence.

Containment — Isolate affected systems from the network to limit spread, while preserving forensic evidence. Short-term containment (disconnect the device) and long-term containment (rebuild from a clean image, restore from backup) require different actions. Both need step-by-step procedures.

Eradication and Recovery — Remove the threat, then restore. Confirm the backup is clean before restoring from it. Validate system integrity before reconnecting services to the network. Return to normal operations in a defined sequence with each system tested before going live.

Post-Incident Review — Document the timeline from first awareness to full containment. Identify what the plan got right and where it fell short. Schedule a plan update within 30 days. The post-incident review is how an IRP improves over time.

What Cyber Insurers Now Require

Canadian cyber insurance carriers — including Beazley, Coalition, Intact, Northbridge, and Chubb — now routinely include incident response plan documentation in their underwriting questionnaires. Organizations that cannot confirm a written and tested plan face one of three outcomes: coverage denial, premium increases, or sub-limits on breach-response costs — precisely the costs an untested plan inflates.

Evidence of a tabletop exercise conducted within the last 12 months is typically sufficient for insurer purposes. A tabletop exercise is a structured scenario walkthrough in which key team members act out their IRP roles against a simulated incident. A three-to-four hour session produces the documentation carriers accept at renewal.

Just 22% of Canadian businesses carried cyber risk insurance in 2023, up from 16% in 2021. Statistics Canada, CSCSC 2023 For those with coverage, an untested IRP is an underwriting risk at renewal. For the 78% without coverage, a documented incident response plan is a prerequisite for a successful first application.

A Minimum Viable Incident Response Plan for a 25-Person SMB

An IRP does not require a dedicated security team or a CISO. A minimum viable plan for a small Canadian business contains five sections:

Section 1 — Roles and Contacts: Name the incident commander (who declares and manages the response), the technical lead (who executes containment and recovery), and the communications lead (who manages notifications to staff, customers, and regulators). Include personal mobile numbers. Add the cyber insurer breach-response hotline and the contact for your external IR retainer or managed security provider.

Section 2 — Severity Classification: Define at least three tiers — minor (isolated device issue with no client data exposure), significant (multiple systems affected or potential client data involved), critical (confirmed ransomware, active exfiltration, or operational shutdown). Each tier triggers a different response path and a different set of external notifications.

Section 3 — Containment Checklist: For each severity tier, list the first five actions. For a critical ransomware event: (1) disconnect affected devices from the network immediately; (2) do not reboot — this preserves forensic evidence and may prevent detonation of dormant payloads; (3) contact the IR retainer and cyber insurer; (4) verify the last clean backup and confirm restorability; (5) notify the incident commander and activate your out-of-band communication channel.

Section 4 — Breach Notification Procedure: Specify the conditions that trigger a PIPEDA report to the OPC, and if applicable, a Law 25 report to the Commission d'accès à l'information. Name the privacy officer responsible for filings. Include a breach documentation template so the record-keeping obligation begins immediately.

Section 5 — Post-Incident Review Template: After any incident, document the detection-to-containment timeline, decisions made, what the plan covered and missed, and a target date for updating the IRP.

Test this plan with an annual tabletop exercise. A three-hour scenario walkthrough with key personnel satisfies the CCCS Baseline Control #1 requirement and produces the tabletop documentation cyber insurers accept. The exercise also surfaces the gaps that a document-only review never finds — the contact number that is out of date, the backup that has not been successfully restored since it was configured, the escalation path that no one actually knows how to activate.

The plan does not prevent an incident. It determines how much damage the incident does.


Sources


Cloud Forces helps Canadian SMBs build and test incident response plans aligned to CCCS baseline controls, PIPEDA breach notification obligations, and cyber insurer requirements — including facilitated tabletop exercises and IR retainer services. Explore our Cybersecurity services or contact us to schedule a complimentary incident response readiness review.

Anton Kuznetsov
Founder & Principal Engineer

Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.

Ready to bring AI to your business?

Book a free AI Readiness Consultation — no commitment required.

Book Free Consultation