Glossary term
Incident Response
Incident response is the structured process of detecting, containing, eradicating, and recovering from a cybersecurity incident, frequently paired with forensic investigation to produce a defensible record of what happened.
The standard reference framework is NIST SP 800-61 Rev. 2, the Computer Security Incident Handling Guide. The framework's core phases are Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity.
Most Canadian businesses do not staff a full incident-response team. They rely on a managed detection and response (MDR) provider, a cyber insurer's panel firm, or a CISO with a small in-house team. The IR process for a serious incident typically involves all three.
Forensic investigation is the part of IR that produces the defensible record after the fact. While the MDR provider focuses on detection and containment, the forensic team focuses on scope of compromise, exfiltration analysis, regulator-ready reporting, and any litigation support that follows.
For Canadian businesses, IR engagements often involve PIPEDA breach notification analysis. The forensic determination is what supports counsel's "real risk of significant harm" assessment.
