The 12 checks in this quiz
Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.
Plan & roles
-
Do you have a written incident response plan that staff can actually find and follow?
Write a short, practical IR plan and store it where it is reachable even if systems are down (printed or off-network).
-
Is it clear who does what during an incident: who leads, who decides, who calls whom?
Assign incident roles in advance: an incident lead, a decision-maker, and who contacts IT, legal and your insurer.
-
Do you know who to call first (internal IT or MSP, insurer, legal) with the numbers on hand?
Keep a one-page contact list (MSP, cyber-insurer hotline, legal, key vendors) with the plan, stored off-network.
Detection
-
Do you collect logs and alerts that would actually tell you an incident is happening?
Turn on and centralize logging and alerting for email, endpoints and key systems so an incident is noticed, not missed.
-
Do staff know how to recognize and report a suspected incident quickly?
Give staff one obvious way to report anything suspicious, and make clear that fast reporting is rewarded, not punished.
Containment & recovery
-
Could you isolate an affected device or account fast to stop the spread?
Practice the basics of containment (disable an account, isolate a device, reset credentials) so it is fast under pressure.
-
Do you have tested, offline or immutable backups you could restore from after ransomware?
Keep backups ransomware cannot reach (offline or immutable) and test a restore, so recovery is real, not theoretical. See the cyber insurance quiz.
-
Do you know how you would keep the business running while you recover (manual workarounds)?
Document basic workarounds for critical functions so the business can keep going during recovery.
Communication
-
Do you know your breach-notification obligations to customers and regulators (PIPEDA / Law 25)?
Know when a breach must be reported and to whom; PIPEDA and Quebec Law 25 set notification rules. See the privacy readiness quiz.
-
Do you have a plan for what to tell staff, customers and partners during an incident?
Prepare holding statements and name a comms owner so messaging stays calm, accurate and consistent, not improvised.
Test & improve
-
Have you ever run a tabletop exercise or walkthrough of your plan?
Run a one-hour tabletop: talk through a ransomware or business-email-compromise scenario and find the gaps before an attacker does.
-
After issues or near-misses, do you review what happened and update the plan?
Hold a short post-incident review after any issue and fold the lessons back into the plan.
The time to plan is before the incident
A calm, practiced response is the difference between a bad day and a business-ending event. We help Canadian businesses build an incident response plan that fits how they actually work, wire up the detection and backups behind it, and run the tabletop so everyone knows their part before a real attacker arrives.