TelePortHow we identify, contain, eradicate, and recover from security incidents
Last updated: July 2026
This Incident Response Plan (IRP) defines how TelePort prepares for, detects, contains, eradicates, and recovers from security incidents. Our IRP follows the NIST SP 800-61 framework and is aligned with Canadian privacy law requirements under PIPEDA, PHIPA, BC PIPA, Alberta PIPA, Quebec Law 25, and all applicable provincial health information statutes. Our goal is to minimize harm to patients, protect personal health information, and restore normal operations as quickly as possible.
| Level | Response Time | Containment | Examples |
|---|---|---|---|
| SEV-1 Critical | 15 min | 2 hours | PHI breach, ransomware, full outage |
| SEV-2 High | 1 hour | 4 hours | Suspected breach, partial outage |
| SEV-3 Medium | 4 hours | 24 hours | Account compromise, non-critical issue |
| SEV-4 Low | 1 business day | 5 business days | Minor misconfig, informational alert |
Preparation is the foundation of effective incident response. TelePort maintains readiness through:
- A dedicated Incident Response Team (IRT) with clearly defined roles
- Documented runbooks for common incident types (breach, DDoS, service outage, unauthorized access)
- Regular tabletop exercises and simulated incident drills (minimum quarterly)
- Automated monitoring and alerting on all critical systems
- 24/7 on-call rotation for security incidents
- Offline backups of critical configuration and incident response tools
- Pre-approved communication templates for stakeholder notifications
All team members receive annual training on incident response procedures and their specific responsibilities.
When an incident is detected — through automated alerts, user reports, or manual monitoring — the following steps are triggered:
1. Acknowledge the alert within 15 minutes (automated) or 1 hour (manual report)
2. Assign an incident severity level:
- Critical (SEV-1): Active breach involving PHI, complete service outage, ransomware
- High (SEV-2): Suspected breach, partial service degradation, unauthorized access attempt
- Medium (SEV-3): Suspicious activity, non-critical service issue, policy violation
- Low (SEV-4): Minor issue, informational, no risk to PHI
3. Engage the appropriate incident response team members
4. Open an incident record in the tracking system with timestamp details
5. Begin initial documentation of all findings
Immediate containment actions are taken to limit the scope of the incident and prevent further damage:
Short-Term Containment:
- Isolate affected systems from the network
- Revoke compromised credentials
- Block malicious IP addresses
- Take affected services offline if necessary
- Preserve volatile data (memory, processes, network connections)
Long-Term Containment:
- Apply temporary security patches or workarounds
- Implement additional monitoring on affected systems
- Create forensic images of affected systems for analysis
- Restore services from clean backups if needed
Containment does not mean the incident is resolved — it means the immediate threat is neutralized while investigation continues.
Once the incident is contained, we identify and eliminate the root cause:
- Conduct a thorough forensic analysis of affected systems
- Identify the vulnerability, misconfiguration, or human error that enabled the incident
- Remove malware, backdoors, or unauthorized access points
- Patch or upgrade affected software and systems
- Update firewall rules, access controls, and security policies
- Reset all credentials that may have been compromised
- Verify the eradication was successful through testing
All eradication steps are documented with timestamps and verified through peer review.
After eradication is confirmed, services are restored in a controlled manner:
1. Restore affected systems from verified clean backups
2. Apply all security patches before bringing systems online
3. Monitor restored systems closely for 48 hours for any signs of recurrence
4. Gradually increase service capacity to normal levels
5. Verify data integrity and completeness
6. Communicate restoration status to affected stakeholders
7. Document any lessons learned for future recovery efforts
Critical systems are restored before non-critical systems. Patient-facing services are prioritized.
Within 30 days of incident resolution, a post-incident review is conducted:
- Assemble a review team that includes the IRT lead, affected stakeholders, and an independent observer
- Analyze the full incident timeline from detection to resolution
- Identify what worked well and what could be improved
- Determine if any policies, procedures, or controls need updating
- Assign ownership for each improvement action with target completion dates
- Update incident response runbooks based on findings
- Update the risk register if applicable
- Generate a final incident report for management and, if required, regulators
The goal of the post-incident review is not to assign blame but to improve our security posture.
SEV-1 (Critical): Response within 15 minutes, containment within 2 hours, initial notification within 4 hours. Examples: confirmed PHI breach, ransomware, complete platform outage.
SEV-2 (High): Response within 1 hour, containment within 4 hours, notification within 24 hours if required. Examples: suspected breach, partial outage, persistent unauthorized access attempts.
SEV-3 (Medium): Response within 4 hours, containment within 24 hours. Examples: single-user account compromise, non-critical service degradation, policy violation.
SEV-4 (Low): Response within 1 business day, resolution within 5 business days. Examples: minor misconfiguration, informational alert, routine security finding.
To report a security incident affecting TelePort:
Incident Response Team: security@totus.ca
Privacy Officer: privacy@totus.ca
Emergency Contact: support@totus.ca (24/7 monitoring)
When reporting an incident, please include: the nature of the incident, when it was discovered, any systems or data involved, and your contact information for follow-up.