Security awareness and incident response
Training fades. A written first hour doesn't.
One annual course and a folder nobody's opened since is the usual shape of security awareness at a growing business. The fix isn't a bigger program. It's a shorter, recurring nudge for staff and a plain answer to who does what in the first hour of a bad day.
Book a scoping callWhy one training session doesn't stick
Four familiar reasons awareness fades.
- Novelty
A single course is memorable for about a month
Annual security-awareness training is common, and its effect decays quickly—the same click-through rate creeps back up within weeks of the certificate being issued.
- Attacks change
The examples get old before the course does
A phishing example from last year's training doesn't resemble this quarter's invoice-fraud attempt or a fake multi-factor prompt.
- No feedback
Nobody hears about the near miss
An employee who almost clicked, then didn't, rarely tells anyone. The near miss teaches nothing beyond the one person who noticed.
- Response assumed
Everyone assumes someone else knows the first step
Ask five people what to do the moment a suspicious sign-in alert or a ransom note appears, and expect five different answers.
What this is—and is not
Basics kept current, not a SOC.
Recurring awareness and a written first hour, not a security operations centre.
This isn't managed detection and response, a staffed monitoring desk, or a formal incident-response retainer with its own service commitments—Defender basics already draws that boundary for day-to-day protection, and it holds here too. What's missing underneath that boundary is smaller and more practical: a habit of short, current phishing nudges instead of one annual course, and a plain written answer to "what do we do in the first hour" that doesn't depend on the right person being in the office that day.
Neither piece needs a dedicated security program to be worth having. A short recurring nudge keeps one real, current example in front of staff. A first-hour outline assigns who isolates a device, who resets credentials, who decides whether customers or authorities need telling, and who's actually allowed to make that call—written down before the day it's needed, not during it.
The first hour, in order
Four steps, agreed in advance.
- Contain
Contain first
Isolate the affected device or disable the affected account before anything else. Speed matters more than certainty at this step.
- Confirm
Confirm what actually happened
Get a plain description from whoever noticed it first, before assumptions harden into the official story.
- Decide
Decide who tells whom
A named business decision-maker, not necessarily whoever's most technical, decides on customer, staff, or regulatory notification.
- Record
Record it as you go
Write down what was seen, what was done, and when. It's the same record a cyber-insurance claim or a privacy-breach assessment will ask for later.
What belongs in the recurring cadence
Five things worth keeping current.
- A current phishing example reaches staff at least once a quarter, not once a year
- The first-hour outline has a named person in each role, not just a title
- Contact details for anyone outside the building—insurer, legal counsel, a specialist responder—are current
- The outline has actually been read by the people named in it, not only written once
- A near miss or a real click gets a short debrief instead of silence
When the question is deeper than awareness
A confirmed compromise needs its own response and its own privacy assessment.
A confirmed compromise, a ransom demand, or a breach involving personal information needs a dedicated incident-response engagement and, in Canada, its own privacy-breach assessment against PIPEDA—both are separately scoped, not something a recurring awareness cadence absorbs.
Connect this to the rest of care