Auctor purus, aliquet risus tincidunt erat nulla sed quam blandit mattis id gravida elementum, amet id libero nibh urna nisi sit sed. Velit enim at purus arcu sed ac. Viverra maecenas id netus euismod phasellus et tempus rutrum tellus nisi, amet porttitor facilisis aenean faucibus eu nec pellentesque id. Volutpat, pellentesque cursus sit at ut a imperdiet duis turpis duis ultrices gravida at aenean amet mattis sed aliquam augue nisl cras suscipit.
At elit elementum consectetur interdum venenatis et id vestibulum id imperdiet elit urna sed vulputate bibendum aliquam. Tristique lectus tellus amet, mauris lorem venenatis vulputate morbi condimentum felis et lobortis urna amet odio leo tincidunt semper sed bibendum metus, malesuada scelerisque laoreet risus duis.
Ullamcorper pellentesque a ultrices maecenas fermentum neque eget. Habitant cum esat ornare sed. Tristique semper est diam mattis elit. Viverra adipiscing vulputate nibh neque at. Adipiscing tempus id sed arcu accumsan ullamcorper dignissim pulvinar ullamcorper urna, habitasse. Lectus scelerisque euismod risus tristique nullam elementum diam libero sit sed diam rhoncus, accumsan proin amet eu nunc vel turpis eu orci sit fames.
“Sit enim porttitor vehicula consequat urna, eleifend tincidunt vulputate turpis, dignissim pulvinar ullamcorper”
Nisi in sem ipsum fermentum massa quisque cursus risus sociis sit massa suspendisse. Neque vulputate sed purus, dui sit diam praesent ullamcorper at in non dignissim iaculis velit nibh eu vitae. Bibendum euismod ipsum euismod urna vestibulum ut ligula. In faucibus egestas dui integer tempor feugiat lorem venenatis sollicitudin quis ultrices cras feugiat iaculis eget.
Id ac imperdiet est eget justo viverra nunc faucibus tempus tempus porttitor commodo sodales sed tellus eu donec enim. Lectus eu viverra ullamcorper ultricies et lacinia nisl ut at aliquet lacus blandit dui arcu at in id amet orci egestas commodo sagittis in. Vel risus magna nibh elementum pellentesque feugiat netus sit donec tellus nunc gravida feugiat nullam dignissim rutrum lacus felis morbi nisi interdum tincidunt. Vestibulum pellentesque cursus magna pulvinar est at quis nisi nam et sed in hac quis vulputate vitae in et sit. Interdum etiam nulla lorem lorem feugiat cursus etiam massa facilisi ut.
If an incident occurs, will you know what to do? How can you avoid panicking and making the wrong decisions that could impact your data recovery, insurance claims, a police investigation at risk, or put you at risk of regulatory fines?
Have you identified all the necessary contacts to enable effective crisis management? Do you know when you are required to notify authorities such as the Commission for Information Access and the Canadian Anti-Fraud Centre? Should you also contact your cyber insurer?
An IT or security incident is a violation or imminent threat of violation of IT security policies, IT acceptable use policies or standard security practices. More specifically, a confidentiality incident (Act 25) relates to a potential data breach or violation caused by:
If you witness or are aware of a potential incident, notify your IT support team immediately.
An IT and cybersecurity incident response plan establishes the organizational structure, operational authority, action plan and procedures necessary to:
The incident response plan is designed to provide an initial response to any confirmed major IT or security incident, such as a distributed denial of service (DDOS) attack, phishing email, ransomware or exfiltration of sensitive data.
In the event of a cyber attack, a company may incur a number of costs. A cyber insurance policy can help offset such costs as loss of profit due to a cyber attack, crisis management, legal investigations, system restoration, ransom payments, compensation claims and fines. The company could also be held responsible for the protection of the data it holds and be held liable.
Raise awareness and train employees in cybersecurity risks and data protection to prevent cyberattacks (e.g.: recognize phishing emails and social engineering attacks, apply good password management practices). You will then have a 2-fold strategy: prevention to reduce the risk of cyber-attacks and data leakage, and incident response preparedness to ensure a clear protocol in the event of an incident to ensure the availability, integrity and confidentiality of your data.
To ensure that your incident response plan is linked to your business needs, ensure integration with a business continuity plan and a disaster recovery plan that will be tested annually.
Secur01 has the compliance expertise, cybersecurity competence and experience of multiple cyber risk mandates for clients of all sizes and industries.