Totus Life ServicesTelePort

Incident Response Plan

How we identify, contain, eradicate, and recover from security incidents

Last updated: July 2026

This Incident Response Plan (IRP) defines how TelePort prepares for, detects, contains, eradicates, and recovers from security incidents. Our IRP follows the NIST SP 800-61 framework and is aligned with Canadian privacy law requirements under PIPEDA, PHIPA, BC PIPA, Alberta PIPA, Quebec Law 25, and all applicable provincial health information statutes. Our goal is to minimize harm to patients, protect personal health information, and restore normal operations as quickly as possible.

Incident Severity Levels

LevelResponse TimeContainmentExamples
SEV-1 Critical15 min2 hoursPHI breach, ransomware, full outage
SEV-2 High1 hour4 hoursSuspected breach, partial outage
SEV-3 Medium4 hours24 hoursAccount compromise, non-critical issue
SEV-4 Low1 business day5 business daysMinor misconfig, informational alert

Phase 1: Preparation

Preparation is the foundation of effective incident response. TelePort maintains readiness through:

- A dedicated Incident Response Team (IRT) with clearly defined roles

- Documented runbooks for common incident types (breach, DDoS, service outage, unauthorized access)

- Regular tabletop exercises and simulated incident drills (minimum quarterly)

- Automated monitoring and alerting on all critical systems

- 24/7 on-call rotation for security incidents

- Offline backups of critical configuration and incident response tools

- Pre-approved communication templates for stakeholder notifications

All team members receive annual training on incident response procedures and their specific responsibilities.

Phase 2: Identification & Triage

When an incident is detected — through automated alerts, user reports, or manual monitoring — the following steps are triggered:

1. Acknowledge the alert within 15 minutes (automated) or 1 hour (manual report)

2. Assign an incident severity level:

- Critical (SEV-1): Active breach involving PHI, complete service outage, ransomware

- High (SEV-2): Suspected breach, partial service degradation, unauthorized access attempt

- Medium (SEV-3): Suspicious activity, non-critical service issue, policy violation

- Low (SEV-4): Minor issue, informational, no risk to PHI

3. Engage the appropriate incident response team members

4. Open an incident record in the tracking system with timestamp details

5. Begin initial documentation of all findings

Phase 3: Containment

Immediate containment actions are taken to limit the scope of the incident and prevent further damage:

Short-Term Containment:

- Isolate affected systems from the network

- Revoke compromised credentials

- Block malicious IP addresses

- Take affected services offline if necessary

- Preserve volatile data (memory, processes, network connections)

Long-Term Containment:

- Apply temporary security patches or workarounds

- Implement additional monitoring on affected systems

- Create forensic images of affected systems for analysis

- Restore services from clean backups if needed

Containment does not mean the incident is resolved — it means the immediate threat is neutralized while investigation continues.

Phase 4: Eradication

Once the incident is contained, we identify and eliminate the root cause:

- Conduct a thorough forensic analysis of affected systems

- Identify the vulnerability, misconfiguration, or human error that enabled the incident

- Remove malware, backdoors, or unauthorized access points

- Patch or upgrade affected software and systems

- Update firewall rules, access controls, and security policies

- Reset all credentials that may have been compromised

- Verify the eradication was successful through testing

All eradication steps are documented with timestamps and verified through peer review.

Phase 5: Recovery

After eradication is confirmed, services are restored in a controlled manner:

1. Restore affected systems from verified clean backups

2. Apply all security patches before bringing systems online

3. Monitor restored systems closely for 48 hours for any signs of recurrence

4. Gradually increase service capacity to normal levels

5. Verify data integrity and completeness

6. Communicate restoration status to affected stakeholders

7. Document any lessons learned for future recovery efforts

Critical systems are restored before non-critical systems. Patient-facing services are prioritized.

Phase 6: Post-Incident Review

Within 30 days of incident resolution, a post-incident review is conducted:

- Assemble a review team that includes the IRT lead, affected stakeholders, and an independent observer

- Analyze the full incident timeline from detection to resolution

- Identify what worked well and what could be improved

- Determine if any policies, procedures, or controls need updating

- Assign ownership for each improvement action with target completion dates

- Update incident response runbooks based on findings

- Update the risk register if applicable

- Generate a final incident report for management and, if required, regulators

The goal of the post-incident review is not to assign blame but to improve our security posture.

Incident Classification & Response Timeframes

SEV-1 (Critical): Response within 15 minutes, containment within 2 hours, initial notification within 4 hours. Examples: confirmed PHI breach, ransomware, complete platform outage.

SEV-2 (High): Response within 1 hour, containment within 4 hours, notification within 24 hours if required. Examples: suspected breach, partial outage, persistent unauthorized access attempts.

SEV-3 (Medium): Response within 4 hours, containment within 24 hours. Examples: single-user account compromise, non-critical service degradation, policy violation.

SEV-4 (Low): Response within 1 business day, resolution within 5 business days. Examples: minor misconfiguration, informational alert, routine security finding.

Contact Information

To report a security incident affecting TelePort:

Incident Response Team: security@totus.ca

Privacy Officer: privacy@totus.ca

Emergency Contact: support@totus.ca (24/7 monitoring)

When reporting an incident, please include: the nature of the incident, when it was discovered, any systems or data involved, and your contact information for follow-up.