Foundation articleU.S. & Canada
Employee Data Breach Response Plan: A Practical Guide for Employers
Build a durable, cross-functional response plan covering data mapping, decision authority, escalation, evidence, notification analysis, employee support, vendors and recovery.
- Plan ownership
- Response framework
- Tabletop testing
Foundation articleU.S. & Canada
Supporting Employees After Personal Information Is Exposed: An Employer Playbook
Build a coordinated employee-support workstream with clear communications, exposure-matched guidance, provider evaluation, case escalation and ongoing follow-up.
- Employee communications
- Support options
- Escalation framework
Foundation articleU.S. & Canada
Employee Data Breach Notification in the U.S. and Canada: A Decision Framework for Employers
Organize incident facts, affected jurisdictions, applicable legal regimes, notification triggers, recipients, timing and documented decisions without relying on a universal deadline.
- U.S. state and federal layers
- Canadian federal and provincial regimes
- Decision checklist
Foundation articleU.S. & Canada
Vendor Data-Risk Assessment: A Practical Due-Diligence Guide for Employers
Evaluate each vendor relationship with proportional risk tiers, evidence-based control review, documented decisions, ongoing monitoring and a verified exit.
- Risk-tiering method
- Evidence-based review
- Lifecycle governance
Foundation articleU.S. & Canada
Workplace AI Governance Framework: A Practical Starting Point for Employers
Enable responsible AI adoption through accountable ownership, use-case inventory, proportionate review, data safeguards, human oversight and lifecycle monitoring.
- Risk-based approval
- Human accountability
- Eight-stage lifecycle
Foundation articleU.S. & Canada
Business Email Compromise Response: A Playbook for HR, Finance and Leadership
Stop suspicious payments and account changes, verify independently, contain compromised accounts, preserve evidence and coordinate reporting without promising recovery.
- Payment and payroll response
- Account containment
- Eight-step playbook
Incident response8 pages
Employee Data Breach Response Checklist
Organize the people side of a breach response—from establishing facts and notification obligations to employee communication, follow-on attacks and support.
- Cross-functional response
- Employee communication
- Identity-risk support
Executive response7 pages
The First 24–48 Hours After a Data Breach
A time-sequenced leadership roadmap for activating the response, preserving evidence, building the fact base and supporting affected people.
- 0–4 hour actions
- 4–24 hour decisions
- 24–48 hour stabilization
Vendor governance8 pages
Third-Party Vendor Risk Checklist
Assess outside providers before onboarding, control data and system access, plan for vendor incidents and verify obligations throughout the relationship.
- Supplier due diligence
- Data and access controls
- Incident and exit planning
AI governance8 pages
Workplace AI Governance Checklist
Create accountable AI use with an inventory, data rules, tool approval, human oversight, agent permissions, employee policy and incident readiness.
- Approved AI use
- Data and agent controls
- Human accountability