Incident in progress right now? Call the Security Operations Centre on +1-867-765-2020. Do not wait for this form.
CasCom Security Operations Centre

Report a Cybersecurity IncidentWe respond around the clock

This form opens a ticket with the CasCom Security Operations Centre and creates a formal record of the incident. Give us what you know now. You do not need every answer to submit.

P1 CRITICAL15 minutes
P2 HIGH1 hour
P3 MEDIUM4 hours
P4 LOW1 business day

Cybersecurity incidents only. This form is not for technical support, password resets, hardware or software faults, new user setup, or service outages with no security cause. Use it only for a current or suspected cybersecurity incident. For everything else, contact the CasCom helpdesk at helpdesk@cascom.ca or +1-867-765-2020. If you are not sure which this is, submit it here and we will redirect it.

What happens next. You will receive an emailed copy of this report and a reference number within a few minutes. A CasCom analyst is alerted immediately and will contact you within the response time shown for the severity you select.

A

Reporter Information

So we know who to contact and how quickly we can reach you
Enter your full name.
Enter your job title or role.
Enter the organization this incident affects.
Your copy of this report goes here. If your mailbox may be compromised, use a different address.
Enter a valid email address.
We call rather than email when an account is compromised.
Enter a phone number we can reach you on.
B

Incident Details

When it happened, how bad it looks, and what kind of incident it is
Enter the date the incident was first noticed.
Leave blank if this is the same as detection, or if you do not know.
Estimated severity *
Estimate is fine. A CasCom analyst confirms the final severity, and we would rather you over-report than under-report.
Choose a severity level.
Incident category *
Select at least one category, or describe it under Other.
C

Affected Systems and Data

What is touched, and whether regulated data is involved

Never enter passwords here. If a credential was exposed, name the account, not the password. Change the password separately, and tell us that you have done so under Actions already taken.

Approximate names are better than nothing.
Sensitive or regulated data involved
This drives our breach notification obligations, so flag it even if you are unsure.
D

Incident Description

The part an analyst reads first
Plain language is ideal. Write it the way you would explain it to a colleague.
Describe what happened in at least a couple of sentences.
Paste anything technical you have. Leave blank if none of this is familiar.
Include times where you can. This becomes part of the incident timeline.
E

Business Impact

What has stopped working, and who else is affected
Systems or services currently unavailable
Data lost, stolen, or modified
Clients directly affected
Clients notified
Hold off on client notification until CasCom has confirmed the facts, unless a contract requires otherwise.
F

Evidence and Attachments

Screenshots, headers, logs, anything you have

Do not delete anything. Leave suspicious emails, files, and log entries in place. Deleting evidence removes our ability to trace what the attacker did and can compromise an insurance claim.

Drop files here, or click to browse You can also paste a screenshot directly from your clipboard
If a file is too large to attach, tell us where it is instead.
G

Declaration

Confirm and send
Confirm the declaration before sending.

Submitting opens a ticket with the CasCom Security Operations Centre and emails you a copy of this report.