Cyber Incident Response Planning for Canadian Nonprofits
A cyberattack does not wait for a convenient time—or for a larger IT budget. A clear, tested incident response plan helps your nonprofit protect donor information, continue essential services, make sound decisions, and communicate with confidence when something goes wrong.
Prepared teams make faster, calmer decisions during a cyber incident.
Canadian nonprofits often hold more sensitive information than they realize: donor records, payment details, employee files, volunteer information, client case notes, health-related information, grant documents, and credentials for cloud services. At the same time, many operate with small teams, shared responsibilities, and limited internal IT resources.
This combination makes preparation especially important. An incident response plan is not simply an IT document. It is an organization-wide playbook that defines who makes decisions, how systems are contained, how evidence is preserved, when outside help is called, and how stakeholders are informed.
What counts as a cyber incident?
A cyber incident may include a compromised Microsoft 365 account, ransomware, stolen credentials, accidental disclosure of personal information, a malicious email rule, an infected website, lost equipment, unauthorized access to cloud storage, payment fraud, or a service outage caused by an attack.
Why nonprofits need a written response plan
During an incident, uncertainty creates delay. Staff may not know whether to disconnect a device, reset a password, contact the bank, call the cyber insurer, notify leadership, or preserve logs. Well-intentioned actions can also destroy evidence or alert an attacker before the organization understands the scope of the compromise.
A practical plan gives your team a common process. It helps reduce downtime, limits data loss, supports regulatory and contractual decisions, and protects the trust your organization has built with donors, employees, volunteers, partners, and the people you serve.
The six stages of nonprofit incident response
Prepare
Identify critical systems and information, assign roles, document contacts, confirm backups, and arrange technical, legal, insurance, and communications support before an emergency.
Detect and verify
Collect the first facts: what happened, when it began, which accounts or devices are involved, what alerts were generated, and whether essential services are affected.
Contain
Limit further damage by isolating affected devices, blocking malicious access, revoking active sessions, protecting privileged accounts, and applying temporary controls.
Remove the threat
Eliminate malicious files, accounts, persistence mechanisms, unsafe configurations, and exposed credentials. Determine the likely entry point before restoring normal access.
Recover safely
Restore clean systems and data in a controlled order, monitor closely for recurring activity, validate business functions, and keep leadership informed of risk and progress.
Learn and improve
Document the timeline, cause, impact, response actions, and lessons learned. Assign corrective actions with owners and deadlines, then update and retest the plan.
Who should be on the incident response team?
The team does not need to be large, but every essential responsibility needs an owner and a backup. Record names, personal contact methods, authority levels, and after-hours escalation instructions. Store a protected offline copy in case email or cloud files are unavailable.
| Role | Primary responsibility |
|---|---|
| Incident lead | Coordinates the response, maintains priorities, approves major actions, and keeps an incident log. |
| Executive decision-maker | Authorizes business disruption, emergency spending, external support, and stakeholder communications. |
| IT/security provider | Investigates, contains, preserves technical evidence, restores services, and monitors for further activity. |
| Privacy or legal adviser | Assesses privacy, contractual, employment, regulatory, notification, and evidence-handling obligations. |
| Communications lead | Prepares accurate, consistent messages for staff, donors, partners, clients, the board, and the public. |
| Cyber insurance contact | Opens the claim and confirms insurer requirements before the organization hires outside specialists or incurs major costs. |
Your first-hour cyber incident checklist
The exact response depends on the event. The following checklist provides a safe starting structure for your plan:
- Contact the designated incident lead and IT/security provider using a trusted channel.
- Record who discovered the incident, the time, visible symptoms, affected accounts or devices, and actions already taken.
- Preserve suspicious emails, alerts, screenshots, logs, and device details. Do not delete evidence.
- Isolate affected devices or accounts as directed, but do not broadly shut down or wipe systems without technical guidance.
- Protect administrative accounts, revoke suspicious sessions, and verify that attackers have not changed recovery methods or mailbox rules.
- Use a clean device to secure financial, domain, backup, cloud, and identity-management accounts if compromise is suspected.
- Notify executive leadership, legal/privacy advisers, and the cyber insurer according to the escalation matrix.
- Begin a chronological incident log and route external communications through one authorized spokesperson.
Privacy breach assessment in Canada
A cybersecurity event and a privacy breach are related, but they are not always the same. If personal information may have been lost, accessed, or disclosed without authorization, your organization should promptly involve qualified privacy or legal counsel to determine which laws and contractual requirements apply.
Organizations subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) must keep records of breaches of security safeguards involving personal information under their control. A breach that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada, and affected individuals must be notified. Provincial laws, funder agreements, sector requirements, or other obligations may also apply.
Your incident file should document what information was involved, how sensitive it was, who may be affected, the likelihood of misuse, containment steps, the reasoning behind notification decisions, and the actions taken to reduce harm. This article is general information, not legal advice.
Build the plan before you need it
A useful incident response plan does not need to be a hundred-page binder. Begin with the information your team will actually need under pressure:
- A one-page escalation chart with primary and backup contacts
- An inventory of critical systems, data, vendors, administrators, and system owners
- Secure emergency access procedures for Microsoft 365, cloud platforms, domains, backups, banking, and the website
- Technical playbooks for account compromise, ransomware, lost devices, payment fraud, website compromise, and data exposure
- Cyber insurance policy details and instructions for opening a claim
- Pre-approved internal, donor, partner, and public communication templates
- Backup restoration priorities and realistic recovery time objectives
- An incident log template and a decision record for privacy breach assessment
Test the plan with a tabletop exercise
A plan that has never been tested is still an assumption. At least annually—and after major technology or staffing changes—run a short tabletop exercise with leadership, operations, communications, and your IT/security provider.
Use a realistic scenario, such as an executive’s Microsoft 365 account being compromised shortly before a major fundraising campaign. Walk through how the incident would be detected, who would be contacted, whether access could be contained, how donations would continue, which evidence would be preserved, and who would approve external communications.
The goal is not to catch people making mistakes. It is to find missing contacts, unclear authority, inaccessible documentation, backup gaps, and technical dependencies while there is still time to fix them.
Technology that supports a faster response
Documentation matters, but the right safeguards make the plan executable. For many nonprofits, the highest-value improvements include multifactor authentication, separate administrative accounts, endpoint detection and response, centralized security monitoring, secure email controls, conditional access, tested backups, DNS and web protection, rapid session revocation, and reliable logging.
These controls help your organization detect suspicious activity earlier, contain compromised users and devices faster, and determine what actually happened. They also reduce the risk that a single stolen password becomes an organization-wide crisis.
Is your nonprofit ready to respond?
TEKYHOST helps Canadian nonprofits assess cybersecurity risk, strengthen Microsoft 365 and cloud security, prepare practical incident response plans, and respond when suspicious activity occurs. We can help you turn uncertainty into a clear, tested process.
Request a Nonprofit Cybersecurity Consultation