Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

Incident Response Requirements: A Practical Checklist

At minimum, incident response requirements mean a written plan, named responders with defined roles, a tested notification process, and a signed retainer or internal team ready to act within a set SLA, typically one hour for detection and containment to begin. Below is the checklist we use when we help Canadian companies stand up or audit their program.

Do You Have a Written Incident Response Plan

Not a slide deck. A document that names who does what, in what order, with contact information that stays current. Auditors for SOC 2, ISO 27001, and most cyber insurance underwriters will ask for this by name. If your plan lives only in someone's head, it fails the moment that person is on vacation or leaves the company.

  • Scope defined: what counts as an incident versus a routine alert.
  • Severity tiers: a P1 ransomware event is handled differently than a phished employee account.
  • Version control: reviewed and dated at least annually, more often after a real incident.

Named Responders With Defined Roles

"IT will handle it" is not an answer regulators or auditors accept. You need named individuals for incident commander, technical lead, communications lead, and legal counsel, each with a backup. Small and mid-sized companies in Toronto, Waterloo, and Ottawa often run lean security teams, which is exactly why the roles need to be explicit rather than assumed. If your technical lead is also your only sysadmin, you have a single point of failure baked into your response plan.

Service Level Agreements for Detection and Containment

An SLA turns "we'll get to it" into a measurable commitment. Common benchmarks:

  • Acknowledgment: within 15 to 30 minutes of a confirmed alert.
  • Initial triage: within one hour.
  • Containment started: within four hours for high-severity events.
  • Client or stakeholder notification: within 24 to 72 hours, depending on contractual and regulatory obligations.

These numbers matter for insurance renewals and for enterprise procurement questionnaires, which increasingly ask for documented SLA commitments rather than a general statement of intent.

An Incident Response Retainer or an In-House SOC

This is the decision point most growing companies hit. Building a 24/7 internal security operations centre means hiring, training, and retaining specialized staff around the clock, a cost that rarely makes sense until a company is well past a few hundred employees. A incident response retainer gives you named responders on call, pre-negotiated SLAs, and a lower fixed cost than carrying that headcount internally, without the coverage gaps that come from relying on whoever happens to be online when something breaks.

Detection and Logging Coverage

You cannot respond to what you cannot see. A checklist item auditors probe hard:

  • Centralized logging across cloud infrastructure, endpoints, and identity providers.
  • Alert thresholds tuned enough to catch real incidents without drowning the team in noise.
  • Log retention that meets both your compliance framework and any Canadian privacy obligation for breach investigation.

Communication and Notification Procedures

Incident response is not purely technical. Canadian organizations carry specific notification duties. Under PIPEDA, a breach involving personal information that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner and affected individuals, and records of every breach must be kept for two years even if it did not meet the reporting threshold. Quebec's Law 25 adds its own notification timeline and register requirements for any business handling Quebec residents' data. Companies pursuing CPCSC Level 1 certification for federal contracting work face additional documented notification steps. Build your communication tree, including legal counsel and, where relevant, cyber insurance carriers, before an incident forces you to figure it out live.

Tabletop Exercises and Plan Testing

A plan that has never been rehearsed is a plan you are testing for the first time during a real breach. Run a tabletop exercise at least annually, walking the response team through a realistic scenario, ransomware, a compromised admin credential, a third-party vendor breach, and time how long it actually takes to move through detection, containment, and notification. This is also where gaps in the named-responder list surface, usually the backup contact nobody updated after a role change.

Vendor and Third-Party Breach Coverage

Your incident response plan needs to cover breaches that originate outside your own environment. If a SaaS vendor, payment processor, or contractor suffers a breach that exposes your data, your plan should specify how you find out, how fast, and what your own notification obligations become as a result. This is a frequent gap in companies scaling quickly across Toronto, Vancouver, and Calgary tech hubs that add vendors faster than they update their vendor risk register.

Post-Incident Review and Documentation

Every incident, resolved or contained, should generate a written post-mortem: what happened, how it was detected, what worked, what did not, and what changes follow. This documentation is what auditors and cyber insurers want to see, and it is what actually improves your response time the next time.

Why the Checklist Matters More Than the Tooling

Companies often buy detection tools first and figure out process second. It should be the other way around. A well-documented plan with named responders and clear SLAs, backed by a retainer for after-hours coverage, closes more audit findings and prevents more damage than another dashboard. If your company is working toward SOC 2 or a broader compliance program, incident response sits alongside compliance readiness as one of the first things auditors check.

traztech works with companies across Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal to build incident response plans that hold up under audit and under real pressure, backed by named responders and a fixed-cost retainer instead of an expensive internal SOC build-out. Contact us to talk through your current plan and where the gaps are.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation