Incident response · Public sector & education
Incident Response Planning for Public Agencies & Crown Corporations
Privacy Horizon writes incident response plans that tell a public body exactly who does what when a breach hits: how materiality gets decided, which regulator hears first, when the minister's office and the board are briefed, and how to work an incident whose entry point sits with a central provider. Most engagements start after a tabletop question nobody could answer, or after watching a peer agency improvise its way through headlines.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
Decisions your agency's plan must settle in advance
An agency incident is a governance event as much as a technical one, and the plan's job is to remove every decision that can be made calmly beforehand.
The materiality and harm call
The plan names who assesses whether a breach is material or meets the real-risk-of-significant-harm threshold, on what evidence, and how the assessment is recorded, because statutory clocks hang on that determination.
The notification sequence
Federal bodies report to TBS and the OPC; Ontario agencies notify individuals and the IPC; BC Crowns go to the OIPC; Alberta bodies notify the Commissioner, individuals and the Minister. The plan hard-codes your map so nobody researches it mid-crisis.
Governance escalation
When the CEO briefs the board chair, when the audit and risk committee convenes, and what the responsible ministry hears under the MOU are set out as triggers, not judgment calls made at midnight.
Service continuity choices
A utility, insurer or transit operator must decide in advance which systems can be isolated without halting public services, and who holds authority to disconnect a revenue-generating platform.
Evidence and records handling
Response records may later face an ATIP request, a commissioner's investigation or an auditor; the plan sets how logs, decisions and legal advice are captured and protected from day one.
Regulatory map
Breach duties the plan is engineered around
Every jurisdiction that owns agencies rewrote its breach rules recently, and a plan drafted even three years ago likely points at the wrong recipients and clocks.
The federal 7-day material-breach report
Under the TBS Policy on Privacy Protection, a material breach must be reported to TBS and the OPC no later than 7 days after materiality is determined, with Appendix B of the Directive on Privacy Practices carrying the working procedures.
Ontario FIPPA breach notification
Since July 1, 2025, agencies must notify affected individuals and report to the IPC when a breach creates a real risk of significant harm, and every incident feeds the annual statistics due each March 31.
BC FOIPPA s. 36.3 notification
Schedule 2 Crown corporations notify affected individuals and the OIPC where harm thresholds are met, backed by the province's breach-process guidance for public bodies.
Alberta's three-recipient rule
POPA requires RROSH breach notice to the Commissioner, to affected individuals and to the Minister, a wider distribution than any other Canadian public-sector regime and easy to get wrong without a documented map.
OPC breach reporting channel
Federal institutions file breach reports with the Office of the Privacy Commissioner through its established process, and the plan includes the current forms and contact paths so filing takes minutes.
What goes wrong
Incident shapes agencies should rehearse for
The plan is built around scenarios drawn from what has actually happened to Canadian public bodies, because those are the ones your board will ask about.
The central-provider incident
Global Affairs Canada's compromise arrived through a VPN operated by Shared Services Canada, meaning detection, containment and forensics all depended on another organization's cooperation; the plan pre-wires those interfaces.
Mass exfiltration via a vendor product
MOVEit-style events surface as a vendor advisory rather than an internal alarm, so the plan includes a path that starts from external notification and moves straight to exposure assessment.
Long-dwell ransomware
Toronto Public Library's attacker operated unseen for two months; the plan addresses what to do when the compromise window is unknown and decades of HR and program records may be in play.
An incident with an operational dimension
For critical-infrastructure Crowns, the plan covers the moment a cyber event threatens service delivery, including engagement with the Cyber Centre and sector partners.
Our incident response for public agencies & crown corporations
What we deliver in an agency response plan
The engagement produces documents your people will actually reach for, tailored to your statute, governance and systems rather than a template with the logo swapped.

The core response plan
Roles, escalation triggers, severity definitions, decision authorities and communication trees, written around your org chart, delegation instruments and MOU obligations.
A notification decision matrix
One page per scenario mapping harm assessment to recipients and deadlines across TBS, OPC, IPC, OIPC, ministerial and board notifications, with draft report skeletons attached.
Central-provider and vendor annexes
Contact paths, contractual notification commitments and coordination steps for SSC, provincial data centres, MFT vendors and other parties whose systems could be the entry point.
Public communications guidance
Holding-statement frameworks and approval chains for a body whose incident will draw media, requester and legislative attention, aligned with counsel and the ministry's communications shop.
Maintenance and update cycle
A review rhythm that keeps recipients, statutes and contacts current as directives change, staff turn over and new systems come online.
How the engagement runs
Building the plan with your people
Step 1
Discovery
We interview the executives, IT leads, ATIP or FOI coordinator and counsel who would live the incident, and gather your statutes, delegation instruments, MOU and existing runbooks.
Step 2
Draft the choreography
The plan, matrix and annexes are drafted around your actual reporting lines and provider relationships, then pressure-tested against the scenarios most likely to hit your body.
Step 3
Walk it through
A structured walkthrough with the response team surfaces gaps, wrong assumptions and missing authorities before sign-off, and doubles as the team's first orientation to the plan.
Step 4
Finalize and embed
The approved plan is issued with a maintenance schedule, and we can support periodic refreshes so it never drifts back into shelf-ware.
What it costs
What incident response planning costs for a public body
Effort scales with your notification complexity and structure: a single-statute tribunal with one office needs a leaner plan than a federal Crown corporation with subsidiaries, OT operations, a central-provider dependency and a communications function. The number of annexes, the depth of walkthrough sessions and integration with existing corporate emergency plans are the other main drivers, and we quote a fixed fee once those are known.
Agencies already running our Virtual Privacy Office have an incident management protocol included in the retainer, which starts from $2,200 CAD per month, so a standalone plan engagement is often the entry point for bodies not yet ready for ongoing support.
Public Agencies & Crown Corporations: Incident response questions, answered
Sequence follows statute and governance, not instinct. Regulatory recipients come from your regime: TBS and the OPC together for federal material breaches, the IPC plus affected individuals in Ontario, the OIPC in BC, and the Commissioner, individuals and the Minister in Alberta. Internally, the CEO and board chair should never learn of a serious incident after a regulator does, and ministry no-surprises expectations under the MOU usually mean an early heads-up. The plan fixes this order per scenario so it is executed, not debated.
Your statutory duties do not transfer just because the compromised system belongs to Shared Services Canada or a provincial data centre; the personal information is still yours. The plan therefore establishes provider liaison contacts, information you will demand (indicators, timelines, affected assets), how joint containment decisions get made, and how you document a response you do not fully control. The Global Affairs incident is the template: institutions had to assess their own exposure through infrastructure someone else operated.
Enough to be honest, nothing you may have to retract. Early statements confirm an incident, what services are affected, and what customers or citizens should do, while avoiding attacker attribution, scope estimates and system detail that forensics may overturn. A commercial Crown also has counterparties and possibly markets watching, and its ministry will expect aligned lines. We draft holding-statement frameworks and an approval chain in advance so communications keep pace with a fast story.
The runbook restores systems; the plan discharges obligations. Nothing in a typical IT runbook decides materiality, files with TBS and the OPC inside 7 days, notifies individuals under a RROSH test, briefs a board chair or manages a minister's office. Agencies that conflate the two tend to run a competent technical recovery while missing statutory duties, which is precisely the pattern commissioners criticize in public findings. The two documents reference each other and hand off cleanly.
In a ten-person tribunal, the team may be the executive director, the coordinator holding delegated privacy duties, an IT contractor and external counsel, with our plan giving each a double role card. A large utility or insurer adds a security lead, operations, communications, HR, procurement for emergency vendor spend, and a board liaison. Either way the plan names alternates, because incidents reliably start when the primary is on leave.
Tie maintenance to events, not good intentions: a refresh when a directive or statute changes, when a major system or provider is added, after every real incident or exercise, and at least annually alongside the business-plan cycle. Contact lists and regulator filing paths decay fastest. We include a maintenance schedule in the deliverable and offer periodic reviews so the version on the shelf is always the version you would actually run.
More for public agencies & crown corporations
Other services for this niche
About this service
Answers & guides
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.