An Employee Clicked a Malicious Link: What to Do Now

Reviewed by IT Cares certified technicians · Updated July 2026

A stressed Canadian office employee alerting their IT manager after clicking a suspicious link on a work computer
The moment right after the click is the one that matters most — what you do in the next few minutes has more impact on the outcome than anything that happens afterward.
🚨
This happening right now? Stop reading in a minute and disconnect the device from the network first — then come back. Need a technician immediately? IT Cares handles emergency incident response for Canadian businesses.
Get SOS Help →

An employee just told you they clicked a link they shouldn't have. Your first move is to disconnect that device from the network — unplug the ethernet cable or turn off Wi-Fi — without shutting it down or restarting it, because powering off can erase evidence and, with some ransomware strains, can actually trigger the damage rather than stop it. From there, the response follows a specific order: gather what actually happened, isolate the machine at the network level if you have IT support, escalate to your provider, and reset passwords starting with email, from a different device entirely. None of this is complicated once you know the sequence — the danger is improvising it under pressure.

This guide is built for the moment right after it happens, whether you're the employee who clicked, the manager they told, or the IT person who just got the call. It walks through the first 15 minutes in detail, then the fuller response over the following hours and days: what to check for signs of deeper compromise, what changes if this turns into ransomware, when a click becomes a reportable privacy breach under Canadian law, and how to close the loop afterward without turning your workplace into a place people are afraid to report the next one. If you're trying to determine whether your systems show broader signs of compromise beyond this single click, our is my computer hacked warning signs guide covers the detection side in more depth; if you want the background on how these links get sent in the first place, see our what is phishing guide.

Who wrote this guide

This article was written and reviewed by IT Cares certified technicians based on the emergency calls we field from Canadian businesses in exactly this situation — usually within minutes of the click, sometimes mid-panic. The sequence below is the same one our technicians walk clients through on the phone before we've even remoted in, because the first few minutes matter more than anything a technician can do after the fact.

The First 60 Seconds: What to Do Immediately

Everything that happens in the first minute sets the tone for everything after it, so it's worth being precise about exactly what to do, and just as importantly, what not to do.

Stop clicking

The instinct when something looks wrong is to try to fix it — close the pop-up, click "cancel," try the link again to "see what it actually does." Resist all of that. Every additional click is a fresh opportunity for a malicious page to trigger another action, and closing a fake warning by clicking anywhere on it, including an apparent "X," can itself be the action that starts a download. Stop touching the mouse and keyboard beyond what's needed to disconnect the machine from the network.

Disconnect from the network — physically, if possible

Unplug the ethernet cable if the device is wired in, or turn off Wi-Fi from the network settings if it's wireless. If you're not confident finding the Wi-Fi toggle quickly under pressure, physically switching off the machine's Wi-Fi hardware switch (many laptops have one) or simply putting the device in airplane mode works just as well. The goal is singular: cut off the device's ability to talk to anything else on your network or the internet, immediately, before whatever was triggered has a chance to communicate out, download something further, or spread.

Do NOT shut down or restart the computer — and here's why that matters

This is the step people get wrong most often, because shutting the computer off feels like the obviously safe move. It isn't, for two specific reasons. First, a device's memory (RAM) holds information that vanishes the instant power is cut — running processes, active network connections, and evidence of exactly what a piece of malware was doing at that moment. If a forensic investigation is needed later, that volatile memory is often the single most useful source of truth about what actually happened, and it's gone forever the second the machine powers down. Second, and more urgently, some ransomware strains are specifically engineered to complete or accelerate their file encryption routine when the machine shuts down or during the next startup, precisely because security teams have historically reached for the power button as a first reaction. Disconnecting from the network stops an attacker's ability to communicate with the device; shutting it down does not achieve that, and can make things measurably worse. Leave the machine powered on and disconnected, full stop.

Don't panic-click anything else on the screen

If a warning, a countdown, a "your files have been encrypted" message, or any other prompt is on screen, leave it exactly as it is. Don't try to close it, don't screenshot it by clicking through menus you're unfamiliar with, and don't try to open Task Manager to "kill the process" unless you already know precisely what you're doing — untrained attempts to intervene can trigger exactly the outcome you're trying to prevent. A photo taken with a phone camera of what's on the screen is a safe, useful way to capture what's showing without touching the keyboard further.

📊 IT Cares field note: On nearly every emergency call we take for this exact scenario, the caller's first question is "should I turn it off?" The answer is almost always no, and explaining why — memory evidence, shutdown-triggered encryption routines — is usually the single most useful thing we say in the first thirty seconds of the call, because it's also the thing callers are most likely to do wrong on instinct alone.

Need a technician on this right now?

IT Cares offers emergency remote response for exactly this situation — a certified technician can assess the device and guide your next step within minutes.

If You're IT: Isolating the Machine at the Network Level

Physically disconnecting the device is step one, but if you have any IT support — internal or an MSP — a second layer of isolation at the network level matters too, especially if there's any chance the device reconnects automatically or someone else in the office plugs it back in without knowing why it was unplugged.

Disable the switch port

If the device connects through a managed switch, disable the specific port it's plugged into from your switch's administration interface. This stops the device from rejoining the network even if someone plugs the ethernet cable back in without realizing what happened, which is a more common failure mode than people expect in a busy office.

Remove it from Wi-Fi at the access point or controller

For wireless devices, don't rely solely on the device's own Wi-Fi toggle — block the device's MAC address at your router or wireless controller level, or temporarily change the Wi-Fi password if your environment doesn't support per-device blocking. This closes the gap where a device silently reconnects to Wi-Fi in the background the moment its own radio is turned back on.

Move it into a quarantine VLAN if you have one

Businesses running a segmented network with a quarantine or guest VLAN can drop the affected device into that segment, which isolates it from internal file shares, servers, and other workstations while still allowing controlled remote access for your IT team or MSP to investigate. This is the cleanest option when available, because it lets an investigation proceed without leaving the device completely dark.

Check what else that device could reach

While isolating the device, take stock of what it had access to — shared network drives, cloud storage sync folders, VPN connections, admin credentials saved in a browser or password manager. This isn't about panicking over every possibility; it's about building an accurate list of what needs checking next, so the investigation that follows is targeted rather than a blind guess.

What Information to Gather Immediately

While the device sits safely disconnected, the next priority is capturing what actually happened while it's still fresh in the employee's memory — this becomes the single most useful piece of information for whoever handles the technical response next, whether that's your internal IT person or an outside provider on the phone.

None of this requires technical expertise to gather — it's simply a matter of asking the employee calmly, in plain language, without making them feel like they're being interrogated. The quality of the response that follows depends heavily on how complete and honest this initial account is, which is exactly why the tone of this conversation matters as much as the content.

When to Escalate to Your MSP or IT Provider vs. Handling It Internally

Some clicks genuinely resolve themselves with nothing more than a disconnected device and a quick look-over; others need a professional response immediately. Knowing which is which saves precious time.

Escalate immediately, without trying to resolve it yourself first, if: any credentials were entered on the fake page; a file was downloaded and opened, or a program installation was triggered; you see any indication of ransomware — a ransom note, files that suddenly won't open, or file extensions that have changed; the device has access to shared drives, client data, financial systems, or admin-level accounts; or you simply aren't confident assessing what happened on your own. None of these are situations where "let's just keep an eye on it" is an acceptable response — the cost of escalating and finding out it was minor is trivial compared to the cost of not escalating and finding out it wasn't.

It's reasonable to do a first-pass check internally, with escalation available as a backup, if: the employee is confident a page loaded but they closed it without entering anything or downloading anything; the device has limited access (no shared drives, no saved admin credentials, a standard user account rather than an administrator); and someone with at least basic IT competence can properly check for signs of compromise using the guidance later in this article. Even in this lower-risk case, having your MSP's number ready and being willing to call at the first sign of anything unusual is the right posture — "start cautious, escalate fast" beats "wait and see" every time in this specific situation.

When you do call your MSP or IT provider, come prepared with the information gathered in the previous section — what was clicked, what the employee saw, whether credentials were entered, and roughly when it happened. A provider who receives "someone clicked something, not sure what" spends the first ten minutes of the call just getting to the starting line that a prepared caller reaches instantly.

Password Reset Priorities — From a Different Device, In This Order

If there's any chance credentials were entered, or if you can't be fully sure they weren't, password resets need to happen — but the order and the device you use both matter more than people usually assume.

Always reset from a different, clean device

Never reset a password on the same device that may be compromised. If something was installed that logs keystrokes or captures screen activity, typing a brand-new password on that same device hands the attacker the new password just as easily as the old one. Use a phone, a different computer, or any device you're confident wasn't involved.

1

Email first

Email is almost always the recovery path for everything else — banking, business applications, cloud storage, other logins — so it's the single highest-priority reset. If an attacker has access to email, they can typically reset nearly every other password themselves using "forgot password" links, which is exactly why email goes first, not last.

2

Financial and banking systems

Business banking portals, payroll platforms, and accounting software logins come next, given the direct financial exposure if these were compromised. Where possible, also contact your bank directly to flag the account for extra monitoring rather than relying solely on a password change.

3

Other business systems

CRM, shared drives, cloud storage, VPN access, and any other application the employee's account touches, roughly in order of how sensitive the data behind each one is. Enable multi-factor authentication anywhere it isn't already active as part of this pass, not as a separate later task.

4

Notify anyone with shared or delegated access

If the compromised account had delegated access to shared mailboxes, calendars, or files, or if other staff use a shared login tied to the same credentials, make sure they know a reset happened and why, so no one is locked out unexpectedly or confused about what changed.

Checking for Signs of Compromise

Whether you're handling this internally or your IT provider is, these are the specific things worth checking on and around the affected device once it's safely isolated, to understand whether the click actually led anywhere or simply loaded a page that did nothing.

Unusual outbound network traffic

Before fully isolating the device, or from firewall and router logs afterward, unusual outbound connections — especially to unfamiliar IP addresses or countries your business has no reason to be communicating with — are one of the clearest signs that something on the device tried to phone home to an attacker's infrastructure.

New scheduled tasks or startup entries

Malware frequently establishes persistence by creating a scheduled task or a startup entry so it survives a restart. Checking Task Scheduler on Windows, or the equivalent startup items and launch agents on a Mac, for anything unfamiliar that wasn't there before is a quick, meaningful check.

New administrator accounts

A new local or domain administrator account that nobody on your team created is a serious red flag, since it typically means an attacker is trying to establish a persistent foothold that survives even a full password reset on the original compromised account.

Unfamiliar processes running

Reviewing Task Manager (Windows) or Activity Monitor (Mac) for processes with unusual names, high and unexplained resource usage, or anything that doesn't match software your business actually uses can surface something running in the background that a casual glance at the desktop would never reveal.

Genuinely, this step is where professional help earns its cost — a trained technician can distinguish a legitimate background process from a disguised malicious one far more reliably than most non-specialists, and a device that "looks fine" on the surface can still be actively compromised underneath. If you want a straight answer rather than a guess, IT Cares can check the device remotely and tell you plainly what was found.

First 15 Minutes — Employee Clicked a Malicious Link Checklist

  • Stop clicking anything else on the screen, including "close" or "cancel" buttons on any pop-up.
  • Disconnect the device from Wi-Fi or unplug the ethernet cable immediately.
  • Do NOT shut down or restart the device — leave it powered on and disconnected.
  • Take a photo of anything on screen instead of interacting with it further.
  • Write down what was clicked, what appeared, and whether anything was typed in.
  • Note roughly when it happened.
  • If you have IT support, disable the network switch port or remove the device from Wi-Fi at the router level.
  • Call your MSP, IT provider, or an emergency IT line if credentials were entered, a file was opened, or you see ransomware signs.
  • From a different, clean device, reset the email password first, then financial systems, then other business logins.
  • Do not punish or blame the employee — thank them for reporting it quickly.

Response Timeline by Severity: Three Scenarios Compared

Not every click carries the same weight, and the appropriate response scales with what actually happened. This comparison covers three common scenarios in the order of increasing severity.

FactorLink clicked, nothing enteredCredentials enteredFile downloaded & executed / ransomware signs
Immediate action Disconnect device, don't shut down, close the page without entering anything Disconnect device, don't shut down, note exactly which account's credentials were entered Disconnect device, don't shut down, isolate at network level immediately, do not touch further
Escalation Internal first-pass check reasonable; escalate if anything looks off Escalate to MSP/IT provider immediately Escalate to MSP/IT provider immediately, treat as active incident
Password resets Not usually required, but MFA review is still good practice Immediate, starting with email, from a different device Immediate and business-wide once scope is understood, from clean devices only
Typical resolution time Under 1 hour Same day to 24-48 hours Days to weeks depending on scope and backup recovery
Likely cost range (CAD) $0 – $200 (internal time or a quick remote check) $150 – $1,500 (remote response, password resets, monitoring) $3,000 – $50,000+ (forensics, recovery, possible downtime and ransom-related costs)

The scenario you're actually in isn't always obvious in the first few minutes, which is exactly why the "disconnect first, ask questions second" approach applies across all three columns — you don't need to correctly diagnose the severity before taking the first protective step, because that step is identical regardless of which column you end up in.

If Files Start Showing Signs of Encryption: The Ransomware Scenario

The response changes in a few specific, important ways the moment you see actual ransomware indicators: a ransom note appearing on screen or as a text file in multiple folders, file extensions suddenly changing to something unfamiliar, or files that were working fine an hour ago that now won't open at all.

Isolate further, immediately

Beyond disconnecting the affected device, check whether any shared drives or network locations that device had access to are showing the same signs, and if so, isolate those systems too. Ransomware often spreads laterally across a network within minutes of the initial compromise, so the isolation boundary may need to expand quickly beyond just the one device.

Do not pay the ransom immediately, if at all

Paying a ransom doesn't guarantee you get a working decryption key, doesn't guarantee the attacker won't come back, and in some cases can create legal exposure if the group behind the attack turns out to be under Canadian or international sanctions. This decision should never be made in the first panicked hour — it should come after consulting with an incident response professional, and ideally your cyber insurance provider if you have one, who can assess the actual situation and options properly.

Contact the Canadian Centre for Cyber Security and law enforcement

The Canadian Centre for Cyber Security (cyber.gc.ca) accepts incident reports from Canadian organizations and can provide guidance for significant incidents; report to your local police as well, particularly if you're considering any ransom payment, since law enforcement involvement is often relevant to how that decision gets handled. Also report the incident to the Canadian Anti-Fraud Centre, which tracks patterns across incidents nationally even when a single case doesn't lead to a direct resolution.

Check for backups before assuming the worst

Before any conversation about ransom payment happens, confirm what backup options actually exist — a recent, tested backup that wasn't itself reachable and encrypted by the ransomware (an offline or immutable backup) can make the entire ransom question moot. This is exactly why testing backups regularly, before an incident, matters so much; discovering during a live ransomware event that your "backup" hadn't actually been restorable in months is a devastating moment to learn that.

Seeing ransomware signs right now?

Stop reading and isolate every system you can, then call for help immediately. IT Cares SOS Emergency response is built for exactly this situation, and our technicians can assess scope and options within minutes rather than hours.

When This Crosses Into a Reportable Privacy Breach (PIPEDA)

Not every clicked link triggers a legal notification obligation, but understanding when it does matters, because Canadian federal privacy law carries real consequences for getting this wrong.

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), a business must notify the Office of the Privacy Commissioner of Canada (OPC) and affected individuals when a breach of security safeguards creates a real risk of significant harm — factors that raise this risk include the sensitivity of the personal information involved (financial details, health information, government identification numbers) and the probability that the information has been or will be misused. A click by itself, with nothing entered and no evidence the compromised account or system ever held or could reach personal information, typically doesn't meet that threshold. It becomes a different question entirely if the compromised email account had access to a customer database, if credentials entered on a fake page belonged to a system holding client financial or health records, or if forensic investigation confirms an attacker actually accessed files containing personal information.

The practical approach is to determine the actual scope of access before concluding either way — this is exactly the kind of question a forensic investigation or a knowledgeable IT provider helps answer, since guessing wrong in either direction carries real cost: under-reporting a genuine breach carries legal and regulatory risk, while over-reporting every minor incident as a formal breach creates unnecessary alarm and administrative burden. If notification is required, PIPEDA doesn't specify an exact number of days but requires notification "as soon as feasible" after determining the breach occurred, and the notification to affected individuals needs to be direct enough that they can meaningfully understand and act on the risk to them — a vague, generic notice generally doesn't satisfy the requirement. Businesses operating in Quebec should also be aware that Quebec's own private sector privacy law (Law 25) has its own breach notification obligations, which run in parallel with PIPEDA and, in some respects, are stricter.

Post-Incident: Company-Wide Rotation and Blame-Free Retraining

Once the immediate crisis is contained, the response isn't finished — what happens over the following days determines whether the organization is genuinely more resilient afterward, or just quietly hoping it doesn't happen again.

Rotate passwords more broadly, not just for the affected account

If there's any uncertainty about how far access spread — a shared password used elsewhere, a saved credential in a browser profile, an admin account with broad reach — a wider password rotation across affected systems is worth the short-term inconvenience. This doesn't need to mean every password in the business, but it should cover everything the compromised account or device could plausibly have touched.

Retrain without blame or shame

This is the single highest-leverage thing a business can do after an incident like this, and it's also the step most commonly skipped or done badly. The goal of any follow-up conversation with the employee who clicked should be entirely forward-looking — what made the message convincing, what would help them (and everyone else) spot the next one, not a recap of what they did wrong. An employee who feels safe reporting a mistake immediately is worth far more to your security than an employee who's afraid to, because the single biggest determinant of how much damage a click causes is how quickly it gets reported — and that speed depends entirely on whether people believe reporting it will get them in trouble.

Document the incident properly, especially if you have a cyber insurance policy

Keep a written record: what happened, when, what actions were taken and when, what the investigation found, and what changed afterward. If your business carries cyber insurance, this documentation is exactly what a claim requires, and building it as the incident unfolds is far easier and more credible than reconstructing it from memory weeks later. Even without a policy, this record is genuinely useful institutional memory — it's what turns "we had an incident once" into "here's specifically what we changed because of it."

Reporting should feel like a win, not a confession

The employee who tells you within two minutes of clicking a bad link should hear "thank you for telling me immediately" before anything else. That single sentence, repeated consistently after every incident, does more to prevent the next serious breach than almost any technical control — because it's what determines whether the next click gets reported in minutes or discovered by accident weeks later.

Three Real Canadian Incident Response Case Studies

The following case studies are composite, illustrative scenarios built from patterns common to Canadian small business incident response calls — names and identifying details are fictional, but the response dynamics and dollar figures reflect realistic outcomes.

Case 1 — Northlight Creative, a marketing agency in Laval, Quebec (16 employees)

An account coordinator clicked a link in what looked like a routine invoice email from a familiar vendor, landing on a fake login page before closing it without entering anything, feeling immediately uneasy. She reported it to her manager within three minutes, who disconnected the laptop from Wi-Fi and called Northlight's IT provider right away. The provider isolated the device from the network via the office router within ten minutes of the call, confirmed no credentials had been entered and no file had been downloaded, and cleared the device after a remote scan found no signs of compromise. Total cost of the response: $185 CAD for the emergency remote assessment, with zero data loss and zero downtime beyond the one laptop being briefly unavailable. The agency's owner credited the fast, blame-free reporting — not any specific technical control — as the reason the incident cost hundreds of dollars instead of tens of thousands.

Case 2 — Harbourview Dental Clinic, Victoria, British Columbia (11 staff)

A front-desk employee received an email that appeared to be an urgent Microsoft 365 security alert and entered her email login credentials on a convincing fake Microsoft page before realizing something was wrong. She told the office manager immediately, who disconnected the workstation and called the clinic's IT provider within four minutes of the click. The provider reset the email password from a separate device, enabled multi-factor authentication on the account (which hadn't been active before), and reviewed the mailbox's sign-in logs, finding one unsuccessful login attempt from an unfamiliar location roughly six minutes after the credentials were entered — the password reset had beaten the attacker to the account by a narrow but decisive margin. Because the clinic handles patient health records, the incident was reviewed against PIPEDA and Law 25 obligations; since no evidence showed the account or any patient data was actually accessed, no formal breach notification was required, though the clinic documented the full timeline in case that changed. Total resolution time: under two hours from click to confirmed containment, at a cost of roughly $340 CAD for the emergency response and account hardening.

Case 3 — Acadia Precision Manufacturing, Moncton, New Brunswick (34 employees)

An employee in the shipping department opened an attachment from what looked like a logistics partner's shipment confirmation, and within roughly twenty minutes, files on a shared production-scheduling drive began showing renamed extensions and a ransom note appeared on a shared server. By the time IT was alerted and the affected systems were isolated, ransomware had encrypted a portion of the shared drive, though the isolation stopped it from reaching the company's separate, offline backup system. Acadia's leadership, on the advice of an incident response firm, chose not to pay the ransom and instead restored the affected systems from the offline backup, a process that took just under three days given the volume of production data involved. Total downtime cost, based on lost production time and rush shipping to catch up with delayed orders, came to approximately $58,000 CAD; the forensic investigation and recovery support cost an additional $14,500. Because the backup held, no ransom was paid and no permanent data loss occurred, but the company's leadership was candid afterward that the backup system's existence — tested only twice in the prior two years — was the single factor that determined whether this became a costly but recoverable week or a business-threatening event.

Budget and Pricing: Incident Response Costs in Canada

Understanding roughly what this costs, in real Canadian dollars, helps take some of the panic out of an already stressful moment and makes it easier to decide how quickly to escalate.

ServiceTypical cost range (CAD)Notes
Emergency remote IT response, single device $150 – $400 Same-day or immediate response, assessment, and initial cleanup for one affected workstation
Emergency response with a support retainer $0 – $150 Often included or heavily discounted for businesses with an existing managed IT relationship
Digital forensic investigation $3,000 – $25,000+ Scope-dependent; determines what was actually accessed and whether notification obligations apply
Business-wide incident response (ransomware) $10,000 – $75,000+ Includes containment, recovery, forensics, and often legal/regulatory guidance for larger incidents
Managed IT / incident response retainer $75 – $250 per employee, per month Covers ongoing monitoring plus priority incident response, typically at little to no extra cost when an incident occurs

The pattern across nearly every case we see is consistent: businesses with an existing managed IT or incident response retainer pay little to nothing extra when something like this happens, because the response is already part of what they're paying for monthly, and their provider already knows their network, their systems, and their normal baseline — which meaningfully speeds up the response itself. Businesses without that relationship pay emergency rates, often at a premium for same-day response, and lose time explaining their environment from scratch to a provider who's never seen it before. Neither approach prevents every incident, but the retainer model consistently produces faster containment and a lower total cost when something does happen, which is worth weighing against the monthly cost the next time it feels like an optional expense rather than a form of insurance in its own right.

Canadian Government and Business Resources

Several Canadian federal resources exist specifically to help businesses respond to and report incidents like this, independent of whatever IT support you already have in place.

None of these resources replace having a direct relationship with an IT provider who can respond immediately when something happens, but they matter for the reporting and regulatory side of a serious incident, particularly one that turns out to involve ransomware or a confirmed breach of personal information. If you want help figuring out where your business currently stands on incident readiness before something like this happens, our cybersecurity services for Canadian businesses and remote virus removal service are built around exactly this kind of response, and SOS Emergency exists specifically for the moment when it already has.

Frequently Asked Questions

Should I turn off the computer if an employee clicked a malicious link?
No — disconnect it from the network by unplugging the ethernet cable or turning off Wi-Fi, but leave the computer powered on. Shutting down or restarting can erase volatile memory that a forensic investigator needs to determine what actually happened, and some ransomware strains are specifically built to complete or accelerate their encryption routine during a shutdown or the next startup. Disconnecting stops communication with an attacker; powering off does not, and can actively make things worse.
How fast do we actually need to isolate the device?
As close to immediately as possible — within the first few minutes, not the first hour. The window between a malicious click and meaningful damage (data exfiltration beginning, ransomware starting to encrypt files, an attacker pivoting to other systems) can be extremely short, sometimes just minutes. Every minute the device stays connected to your network and the internet is a minute an attacker who gained access can use to move, so isolation is always the first physical action, done before you even fully understand what happened.
What should we check first to see if anything was actually installed or accessed?
Once the device is isolated, look for unusual outbound network activity in your firewall or router logs from that device's IP or MAC address, new scheduled tasks or startup entries that weren't there before, any new local or domain admin accounts, and unfamiliar processes running in Task Manager or Activity Monitor. This is genuinely easier and more reliable for an IT professional to check properly than to eyeball yourself, since a compromised machine can be made to look clean at a glance while still running something in the background.
Do we need to report this to the police or the Canadian Centre for Cyber Security?
If money was stolen, ransomware encrypted files, or you suspect an organized criminal group is involved, report it to your local police and to the Canadian Anti-Fraud Centre, and consider notifying the Canadian Centre for Cyber Security (cyber.gc.ca), which accepts incident reports from Canadian organizations and can, for significant incidents, provide guidance. For a minor event with no evidence of actual compromise, formal reporting may not be necessary, but documenting it internally still is, both for your own records and in case related activity surfaces later.
Is clicking a malicious link automatically a reportable privacy breach under PIPEDA?
Not automatically — a click by itself, with nothing entered and no confirmed access to systems holding personal information, usually doesn't trigger a reportable breach. It becomes reportable under PIPEDA when there's a real risk of significant harm to individuals whose personal information was, or may reasonably have been, accessed or disclosed — for example, if the compromised account had access to a customer database or employee records. When in doubt, the safer approach is to investigate the actual scope of access before concluding either way, since the notification obligation depends on what was actually exposed, not on the fact that a link was clicked.
Should we discipline the employee who clicked the link?
Generally, no, and doing so tends to backfire. Punishing the employee who reported it teaches every other employee to hide the next click instead of reporting it immediately, which is far more dangerous than the original click itself, since a hidden incident has no chance of being contained early. The far more effective response is treating the report itself as the right behaviour, reserving any real concern for patterns of repeated risky behaviour or, separately, for failing to report an incident at all.
What if the employee doesn't remember exactly what happened or is afraid to report it?
Reassure them first, then ask what they do remember without pressing for details they're unsure about — a rough sense of what the message claimed to be, roughly when it happened, and whether a login page appeared is usually enough to start. Fear of getting in trouble is the single biggest reason incidents get reported late or not at all, so the way you respond to this report shapes whether the next one, from this employee or anyone who hears about it, gets reported within minutes or gets quietly buried for days.
How much does emergency incident response cost in Canada?
Emergency, same-day remote IT response for a single compromised device commonly runs $150 to $400 CAD depending on urgency and provider, while a formal digital forensic investigation for a business-wide incident typically ranges from $3,000 to $25,000 or more depending on scope and how many systems need review. Businesses with an existing managed IT or incident response retainer usually pay little or nothing extra for the initial response, since it's already covered, which is one of the more concrete financial arguments for having that relationship in place before an incident happens rather than after.

Dealing With This Right Now?

IT Cares handles emergency incident response for Canadian businesses — a certified technician can assess the device remotely and tell you plainly what happened and what to do next.

Comments (3)

DL
Danielle L., Laval
July 24, 2026

The "don't shut it down" part is not something I would have known on my own. Genuinely thought powering off was the safe move — glad I read this before it happened, not during.

RM
Ryan M., Halifax
July 23, 2026

We went through something close to the Acadia case study last year, minus the offline backup unfortunately. Can't overstate how much that one detail changes the whole outcome.

SP
Sophie P., Gatineau
July 22, 2026

Printed the 15-minute checklist and taped it near our front desk computer. Hoping we never need it but feels a lot better having it visible than buried in a folder somewhere.

Leave a Comment

Need Help?