Cluster Brief // NA-CLOCK-2026-09
Dual-clock incident runbook
Desmond Otieno Odhiambo · Verified 7 September 2026
The next serious incident in a Canada–US operating company will not fail because nobody detected it. It will fail because counsel, the SOC, and the privacy lead are building three timelines from three tools.
Bill C-8 enacted the Critical Cyber Systems Protection Act. PIPEDA breach notice already runs in parallel when personal information is involved. CIRCIA, once the final rule is in effect, adds a US clock: substantial incidents to CISA within 72 hours and ransomware payments within 24 hours.
One ledger, many reports
Capture at first reliable knowledge, not at first press statement:
- Detection time and first-confirmed time
- Systems, identities, agents, and regions touched
- Data classes: personal information, specified contract information, CUI-equivalent, model prompts and outputs
- Processors and subprocessors, including US parents and support paths
- Containment actions and residual uncertainty
- Who was notified, when, and under which statute
Two drills a year
- Northbound spill: compromise starts in Canada and data lands with a US processor or model endpoint.
- Southbound spill: compromise starts in the US and touches Canadian personal or specified contract data.
Score time-to-single-timeline, not time-to-statement.
Disclosure gates
CCSPA-style directions can restrict disclosure of the direction itself. CIRCIA and sector regulators have their own sharing rules. Privacy notice to individuals can still be required when there is a real risk of significant harm. The runbook must say who may speak, to whom, and which facts remain unverified.
Parent brief · CPCSC vs CMMC · Assessment