Managed security

Incident Response & Digital Forensics

A number to call, and a plan.

Incident response is the agreed sequence for handling a security incident, who decides, who contains, who is told and in what order, together with the forensic work that establishes what actually happened. happier IT provides it as a retainer for organizations that want the plan and the phone number in place beforehand, and as an engagement for organizations calling for the first time.

Who it's for

The point of this page is the version you read on a calm Tuesday.

Almost everything that makes an incident expensive is a decision nobody had made in advance. Those decisions are free to make now and slow to make later.

You have good controls and no plan. Endpoint protection, backups, second-factor logins. What is missing is two pages saying who declares an incident, who may disconnect what, and who phones the insurer. Every one of those is easy to decide in daylight.

An insurer or a client has asked for your incident response plan. It is now a standard question on renewals and security reviews, and the honest answer for many organizations is that one has never been written down.

You need to be able to answer “what was reached”. Under PIPEDA, the federal Personal Information Protection and Electronic Documents Act, organizations must report breaches of security safeguards that create a real risk of significant harm, notify the people affected, and keep records of every breach regardless of severity. Alberta and British Columbia have their own private-sector privacy laws with their own duties. Answering that question requires evidence.

Something has happened and you are reading this today. Then stop reading and call. Service line 1 (888) 974-2779. We will tell you plainly whether we can help, and if we are not the right people we will say who is.

The decisions worth making in daylight

Who may declare an incident. Who is authorised to take systems offline, and at what hour. Who calls the insurer, and who calls a lawyer. What staff are told, and by whom. What clients hear, and when.

Five answers, one page, agreed while nothing is happening. Keep a copy somewhere that does not depend on your own systems being available.

What's included

What a retainer covers, and what an engagement delivers.

The plan and the rehearsal are the parts you hope stay unused. They are also the parts that determine how the rest of it goes.

  • A written plan sized for your organization

    Two pages, not forty. Roles, decision authority, contact numbers, notification obligations, and the first hour in order. A plan nobody can read at 11pm on a Friday is a compliance artefact rather than a plan.

  • Named roles on both sides

    Who on your side decides, who speaks to staff, who speaks to clients, who owns the relationship with your insurer and your lawyer. And the same on ours, with the hours each person is reachable.

  • An activation route that is tested

    A number that reaches a person, an agreed way to confirm it is genuinely you, and a channel that works when your own email and chat may not be trusted. Tested during onboarding rather than discovered during an incident.

  • Containment inside a pre-agreed authority

    Isolating devices, disabling accounts, blocking senders, with the boundaries written down beforehand so the first twenty minutes are spent acting rather than seeking permission. Wider actions still require your call.

  • Forensic imaging and evidence preservation

    Copies taken properly, logs preserved before they age out, and chain-of-custody documentation recording who handled what and when. This is what allows findings to hold up in an insurance claim or a legal process later.

  • Timeline reconstruction

    What happened, in what order, how it began, which accounts and systems were reached, and whether anything left. This is the work that answers the questions a regulator, an insurer and a client will each ask in slightly different words.

  • Reporting for three different audiences

    A summary a director can act on, a technical report with the evidence behind it, and the specific factual account required for a regulatory notification or an insurance claim. Written so it does not need rewriting for each.

  • A tabletop rehearsal

    A couple of hours around a table walking through a realistic scenario with the people who would actually be involved. It reliably finds two or three assumptions that were wrong, which is exactly what it is for.

How it works

Plan, activate, learn.

The middle stage is the one people picture. The first and third are the ones that decide how the middle one goes.

  1. Write the plan and rehearse it

    Roles, authority, contacts and obligations agreed and written down, then walked through in a tabletop exercise with the people named in it. Copies kept offline, because a plan stored only in the systems it covers is not available when you need it.

  2. Activate and contain

    One call starts it. First we establish what is actually happening and how far it reaches, then contain within the agreed authority while preserving evidence. Containment and evidence pull in opposite directions, and knowing where to balance them is most of the expertise.

  3. Investigate, report and change something

    Forensic analysis, a timeline, and reports for your board, your insurer and any regulator. Then a review that changes something concrete about your environment or your process. A response that ends with a report and no change has only bought you a document.

What it costs

A retainer, or an engagement rate if you call cold.

The retainer buys the plan, the rehearsal and a route that is already open. Calling without one is possible and it is slower at the start, which is the part that matters most.

Without a retainer, we can still help. Retainer clients get someone working within the hour, whatever the hour. Without a retainer we will start the same business day, subject to what is already running.

For happier IT SOC clients, the plan, the rehearsal and containment within the agreed authority are already part of the service. The forensic work is quoted per engagement. Check your cyber-insurance policy too, many include incident response cover, and some require you to use their panel of providers.

Free things to do this week

Write down five phone numbers on paper: your IT provider, your insurer’s claims line, your lawyer, your senior decision-maker, and whoever speaks to clients. Keep the sheet somewhere that does not need a login.

Then read your cyber-insurance policy for two things: the notification deadline, and whether you must use their approved responders. Both are the kind of clause discovered at exactly the wrong moment.

Why us for this

The people who respond are the people who were watching.

Most incident response in Canada is delivered by specialist firms who arrive knowing nothing about your environment. They are often very good, and the first several hours go into learning what you have, who your people are, and what normal looked like before any of this started.

happier IT’s responders come from our own security operations centre in Canada, staffed by our employees. For clients we already monitor, they arrive with your documentation, your ticket history and your baseline already in front of them, which removes most of that first stretch. Our security team holds Certified Ethical Hacker credentials; the full list is on our awards and certifications page. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

Two honest limits. We are not your lawyer: legal privilege over an investigation is a genuine consideration and, in a serious incident, counsel should often engage the responders rather than the other way round, we will raise that early rather than after the fact. And we do not advise on paying a ransom. That decision belongs to your board, your insurer and your lawyer, with sanctions and disclosure questions in Canada that need advice on the specific facts. Our job is to make sure restoring is a real option, which is what backup and disaster recovery exists for.

Go deeper

Questions

What people ask before they sign anything.

What is incident response?

Incident response is the planned process for handling a security incident: identify what is happening, contain it, remove it, restore what was affected, and report properly. The value is almost entirely in having agreed it in advance. During an incident the technical work is usually the straightforward part, the delays come from decisions nobody had authority to make, and contacts nobody could find.

What is digital forensics, and do we need it?

Digital forensics is the disciplined analysis of systems and logs to establish what happened, in what order, and what was reached, with evidence preserved so the findings hold up later. You need it when somebody will ask a question you must answer accurately: a privacy regulator, an insurer assessing a claim, a client under a contract, or a court. If none of those apply, a proportionate investigation may be enough, and we will tell you which situation you are in.

Do we have to report a breach in Canada?

Often, yes. Under PIPEDA, the federal Personal Information Protection and Electronic Documents Act, organizations must report breaches of security safeguards that create a real risk of significant harm to the Privacy Commissioner, notify affected individuals, and keep records of every breach regardless of severity. Alberta and British Columbia have their own private-sector privacy laws with their own duties, and sector rules may add more. Get advice on the specific incident early: the reporting clock is short.

Should we call our insurer or you first?

Read your policy now, before you need to decide. Many cyber-insurance policies require notification within a set period and some require you to use responders from their approved panel, engaging someone else first can affect the claim. In practice, a short call to us to establish whether this is genuinely an incident, immediately followed by the insurer, works for most policies. But the policy governs, and the time to know what it says is today.

Can you help if we are not already a client?

Yes. Call the service line on 1 (888) 974-2779. We will establish what is happening and tell you plainly whether we are the right people, and if we are not, whether because of capacity, specialism or an insurance panel requirement, we will say so rather than taking the engagement. Response without a retainer is charged at a higher rate and starts more slowly, because nothing has been agreed in advance.

What is a tabletop exercise?

A couple of hours around a table walking through a realistic scenario with the people who would actually be involved, not a technical drill, a decision-making one. Someone reads out a situation, and the group works through who does what, who is told, and who decides. It reliably surfaces two or three assumptions that were wrong: a contact who left, an authority nobody actually holds, a system whose owner is unclear. That is what it is for.

What does incident response cost?

Check your cyber-insurance policy first: incident response cover is frequently included and already paid for.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.