No business wants to think about it, but breaches happen — even to careful, well-run companies. What separates a bad day from a disaster is often how you respond in the first hours. Panic makes things worse; a calm, clear plan limits the damage. Here's a practical, step-by-step guide for how an Alberta small business should respond to a data breach.
This is general guidance, not legal advice. For a real incident, involve your IT provider and, where appropriate, legal counsel.
First: don't panic, and don't hide it
The instinct to quietly deal with it and hope no one notices is understandable — and dangerous. Covering up a breach makes the legal, financial, and reputational fallout worse. A measured, honest response is always the better path.
The immediate steps
1. Contain it
Stop the bleeding first. Disconnect affected devices from the network (but don't necessarily power them off — that can destroy evidence), disable compromised accounts, and change passwords. The goal is to prevent the attacker from doing more damage or spreading further.
2. Bring in help
Contact your IT provider or a security professional immediately. Early expert help makes a huge difference in limiting damage and understanding what happened. This is exactly the moment a managed IT partner earns their keep.
3. Assess what happened
Work out the scope: What was accessed or taken? Whose personal information was involved? How did they get in? You need this to respond properly and to meet your obligations.
4. Preserve evidence
Keep logs and affected systems intact where possible. They're essential for understanding the breach and may be needed for legal or insurance purposes.
Your reporting obligations
Under Alberta's Personal Information Protection Act (PIPA), organizations must notify the Office of the Information and Privacy Commissioner of Alberta of a breach involving personal information where there's a real risk of significant harm to affected individuals — and affected individuals may need to be notified too. Don't guess at this; confirm your specific obligations with the OIPC or legal counsel. If you have cyber insurance, notify your insurer promptly as well.
Recover and communicate
- Restore from clean backups — this is where tested backups prove their worth, letting you recover without paying a ransom or losing data. (See cloud vs on-site backup.)
- Communicate honestly with affected customers or clients where required — clear, timely communication protects trust better than silence.
- Rebuild securely — don't just restore; close the hole that let the breach happen.
Then: learn from it
Once the immediate crisis passes, review what happened and strengthen your defences so it doesn't recur — better MFA, EDR, staff training, whatever the incident exposed. A breach is a painful but powerful lesson.
The best response is preparation
The businesses that handle breaches best are the ones that prepared: they have tested backups, know who to call, and have thought through the steps in advance. A simple incident-response plan — even a one-page document — turns a chaotic scramble into an orderly response.
The bottom line
If you're breached: contain it, get expert help, assess the scope, preserve evidence, meet your PIPA reporting obligations, recover from clean backups, and communicate honestly — then learn from it. And the best time to prepare is before it ever happens.
We help Alberta businesses prepare for, prevent, and respond to security incidents. Learn more about our cybersecurity services, or book a free evaluation to review your readiness.
