Security awareness and incident response
Training fades. A written first hour doesn't.
One annual course and a folder nobody's opened since is the usual shape of security awareness at a growing business. The fix isn't a bigger program. It's a shorter, recurring nudge for staff and a plain answer to who does what in the first hour of a bad day.
Build a tenant briefWhy one training session doesn't stick
Four familiar reasons awareness fades.
- Novelty
A single course is memorable for about a month
Annual security-awareness training is common, and its effect decays quickly-the same click-through rate creeps back up within weeks of the certificate being issued.
- Attacks change
The examples get old before the course does
A phishing example from last year's training doesn't resemble this quarter's invoice-fraud attempt or a fake multi-factor prompt.
- No feedback
Nobody hears about the near miss
An employee who almost clicked, then didn't, rarely tells anyone. The near miss teaches nothing beyond the one person who noticed.
- Response assumed
Everyone assumes someone else knows the first step
Ask five people what to do the moment a suspicious sign-in alert or a ransom note appears, and expect five different answers.
What this is-and is not
Basics kept current, not a SOC.
Recurring awareness and a written first hour, not a security operations centre.
This isn't managed detection and response, a staffed monitoring desk, or a formal incident-response retainer with its own service commitments-Defender basics already draws that boundary for day-to-day protection, and it holds here too. What's missing underneath that boundary is smaller and more practical: a habit of short, current phishing nudges instead of one annual course, and a plain written answer to "what do we do in the first hour" that doesn't depend on the right person being in the office that day.
Neither piece needs a dedicated security program to be worth having. A short recurring nudge keeps one real, current example in front of staff. A first-hour outline assigns who isolates a device, who resets credentials, who decides whether customers or authorities need telling, and who's actually allowed to make that call-written down before the day it's needed, not during it.
The first hour, in order
Four steps, agreed in advance.
- Contain
Contain first
Isolate the affected device or disable the affected account before anything else. Speed matters more than certainty at this step.
- Confirm
Confirm what actually happened
Get a plain description from whoever noticed it first, before assumptions harden into the official story.
- Decide
Decide who tells whom
A named business decision-maker, not necessarily whoever's most technical, decides on customer, staff, or regulatory notification.
- Record
Record it as you go
Write down what was seen, what was done, and when. It's the same record a cyber-insurance claim or a privacy-breach assessment will ask for later.
What belongs in the recurring cadence
Five things worth keeping current.
- A current phishing example reaches staff at least once a quarter, not once a year
- The first-hour outline has a named person in each role, not just a title
- Contact details for anyone outside the building-insurer, legal counsel, a specialist responder-are current
- The outline has actually been read by the people named in it, not only written once
- A near miss or a real click gets a short debrief instead of silence
When the question is deeper than awareness
A confirmed compromise needs its own response and its own privacy assessment.
A confirmed compromise, a ransom demand, or a breach involving personal information needs a dedicated incident-response engagement and, in Canada, its own privacy-breach assessment against PIPEDA-both are separately scoped, not something a recurring awareness cadence absorbs.
Connect this to the rest of care