What Nearly 600 Investigations Taught Me About the Gap Between Your Policy and Your Breach
There is a moment in almost every incident response engagement I've run where someone — usually a senior executive, often visibly stunned — says some version of: "But we had a policy for this."
They did. The policy was real. It was written, approved, and filed. And it made no difference whatsoever to what just happened to them.
I've spent 17 years and nearly 600 cases in the space between the policy and the breach. That space is where Canadian regulation is now pointing, and it's worth being honest about what actually lives there.
Regulation has moved from documents to outcomes — your program should too
Last month I wrote about Bill C-8 and the coming federal cybersecurity regime. This month I want to talk about the regulatory regime that's already live and already teaching us something: OSFI's Guideline B-13.
B-13 came into effect for federally regulated financial institutions in January 2024. What I find most instructive about it isn't any single requirement — it's the philosophy. When OSFI finalized the guideline, it deliberately made it less prescriptive than the draft, streamlining it down to three domains and emphasizing a risk-based approach over a checklist. It defines technology and cyber risk broadly — covering not just technical failures but the people and processes that support your technology — and it expects the work to be an enterprise-wide exercise at both the technical and governance levels.
Read alongside its companion guideline B-10 on third-party risk, B-13 is essentially OSFI saying: don't show me a binder, show me resilience. The institutions that will stand out won't be the ones with the fewest incidents — they'll be the ones whose readiness lets them respond and recover seamlessly.
That distinction — between having a document and having a capability — is exactly what every breach investigation exposes.
Lesson one: you cannot protect what you never inventoried
The single most common root cause I see isn't a clever zero-day. It's an asset nobody knew was there, or knew was still there.
The forgotten server still running an old application. The departed employee's account that was never disabled. The third-party integration that quietly retained API access long after the project ended. The external drive that someone plugged in.
Both B-13 and the coming CCSPA framework lead with the same unglamorous demand: inventory your critical systems. There's a reason. In incident after incident, the attacker's path runs straight through the asset that fell off the map. Your inventory is not a compliance artifact. It is the literal map of your attack surface, and if it's stale, you are defending blind.
Lesson two: the breach usually walks in through someone you trusted
When B-13 and B-10 put third-party risk at the centre, they are encoding a hard lesson that my team relearns on nearly every major engagement.
The institution itself is often well-defended. The compromise comes through a vendor with weaker controls and trusted access — a managed service provider, a software supplier, a cloud platform. A single soft third party can become a systemic threat to an entire organization, and the regulators know it. B-13 expects you to assess the criticality of every third-party arrangement and to scale your scrutiny to the risk each one carries.
In practice, this is where I see the widest gap between policy and reality. Organizations have a vendor risk policy. What they often don't have is a current, honest answer to a simple question: which of our vendors could end us, and when did we last actually verify their controls rather than collect a questionnaire?
Lesson three: the insider threat is real, and it's quieter than you think
Not every investigation is about an external attacker. Some of the most damaging cases I've worked involve trusted insiders — and the most dangerous window is often the one around a departure.
A departing employee with retained access. Data quietly moved to a personal external drive in the final days. Files deleted to cover the trail. By the time anyone notices, the person is gone and so, frequently, is the evidence — unless you had the logging, monitoring, and chain-of-custody discipline in place before it mattered.
This is where forensic readiness pays for itself many times over. The difference between a clean, defensible investigation and a guess is whether the right telemetry was being captured all along. You cannot retroactively log what already happened. The decision to be forensically ready is one you make on a calm Tuesday, not in the middle of a crisis.
Lesson four: a plan you've never rehearsed is fiction
B-13's emphasis on resilience and recovery — and the CCSPA's proposed 72-hour incident reporting window — both assume something that is frequently untrue: that the organization can actually execute its response plan under pressure.
I've watched well-resourced teams freeze during a live incident not because they lacked a plan, but because they'd never run it. Who declares an incident? Who contacts the regulator, and within what window? Who has authority to take a system offline? Where are the backups, and has anyone confirmed recently that they restore? When you're discovering the answers to these questions for the first time during an actual breach, you've already lost hours you didn't have.
The fix is not more documentation. It's exercising the plan until the muscle memory is real — tabletop exercises, restore tests, simulated reporting drills. The 72-hour clock is unforgiving, and it starts at detection, not at the moment you finish figuring out what to do.
Closing the gap
Here's the thread that runs through all of it. Canadian regulation — B-13 today, the CCSPA tomorrow — has quietly shifted from rewarding the existence of policies to demanding demonstrable capability. That shift is correct. It matches what every investigation already proves: attackers don't care what your policy says. They care whether you can see your assets, vouch for your vendors, detect a quiet insider, and execute under a clock.
The good news is that closing this gap doesn't require waiting for any bill to pass or any regulator to knock. The work is the same whether you're motivated by B-13, by the CCSPA, or simply by not wanting to be my next case file:
- Make your asset inventory current and keep it that way.
- Know which third parties could sink you, and verify them for real.
- Build forensic readiness before you need it — logging, monitoring, chain of custody.
- Rehearse your incident response until it's reflex, including the 72-hour reporting drill.
I've stood in a lot of rooms with executives the day after. The ones who recover well are never the ones with the thickest binders. They're the ones who did this quiet, unglamorous work before anything went wrong.
Close the gap now, while it's calm. The calm is the only time you ever get to.