PIPEDA and a mailbox breach
If personal information left the building, you have a clock. Know who calls whom before it starts.
ITSIGN Administrator · November 12, 2025 · 2 min read
You will need: what left, whose data, when you knew, and what you did. Counsel leads the notification decision. IT supplies the facts.
Do not wait until the incident to meet your privacy officer. Write the one-pager now.
Incident response retainers include that call tree. GRC writes the policy.
Related reading
A board briefing that fits in ten minutes
Residual risk, open highs, last restore test, last simulation. Then stop talking.
2 min read
Vendor questionnaires that waste a week
Keep a living packet: MFA, backup, pentest date, policies. Answer from the packet, not from memory.
2 min read
SOC 2 readiness for a 40-person firm
You do not need a 20-person GRC team. You need owners, evidence locations, and a scope that matches the customer who asked.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
