Cluster Brief // NA-CLOCK-2026-09

Dual-clock incident runbook

Desmond Otieno Odhiambo · Verified 7 September 2026

The next serious incident in a Canada–US operating company will not fail because nobody detected it. It will fail because counsel, the SOC, and the privacy lead are building three timelines from three tools.

Bill C-8 enacted the Critical Cyber Systems Protection Act. PIPEDA breach notice already runs in parallel when personal information is involved. CIRCIA, once the final rule is in effect, adds a US clock: substantial incidents to CISA within 72 hours and ransomware payments within 24 hours.

One ledger, many reports

Capture at first reliable knowledge, not at first press statement:

Two drills a year

  1. Northbound spill: compromise starts in Canada and data lands with a US processor or model endpoint.
  2. Southbound spill: compromise starts in the US and touches Canadian personal or specified contract data.

Score time-to-single-timeline, not time-to-statement.

Disclosure gates

CCSPA-style directions can restrict disclosure of the direction itself. CIRCIA and sector regulators have their own sharing rules. Privacy notice to individuals can still be required when there is a real risk of significant harm. The runbook must say who may speak, to whom, and which facts remain unverified.

Parent brief · CPCSC vs CMMC · Assessment

CIRCIA mandatory reporting starts after the final rule. CCSPA duties follow designation and in-force dates. Re-check before relying on a clock.