Before
Map data, authority, vendors, consent, identity, retention and access. Name the owner. Define exceptions before somebody needs one.
New obligations do not become an IT problem on the day they take effect. They become a board problem when nobody decided, in advance, how accountability, consent, identity, access, retention and auditability would actually work.
Map data, authority, vendors, consent, identity, retention and access. Name the owner. Define exceptions before somebody needs one.
Make technical controls enforce the decision. Exceptional access and de-anonymization require authority, purpose and a traceable record.
Reconstruct what happened without archaeology: which rule applied, who had authority, what the system did and what evidence proves it.
Twelve words a board can say out loud. Each one resolves to a clause somebody has to build, staff and evidence.
Section references are to Bill C-36 as tabled on 15 June 2026 and may change in committee. Each cluster pairs the statutory duty with the operational capability that produces the evidence.
ITIL draws this line on purpose. Incident Management is measured on one thing: restoration of normal service operation, as fast as possible. Problem Management is measured on something else entirely: reducing the likelihood and impact of incidents by identifying and removing their causes. Different people, different clocks, different definitions of success.
Almost every organization funds the first and improvises the second. That is affordable while the only cost of a recurring failure is the cost of fixing it again. It stops being affordable when a statute attaches a penalty and a private right of action to the recurrence, and asks the board to produce the record of what it decided beforehand.
The underlying essay: The Fireman, on Incident Management →
A board-level pre-incident governance review against Bill C-36 as it stands, plus the obligations that survived unchanged across C-11 and C-27 and are therefore the safest to build against now. The objective is not another binder. It is an organization capable of demonstrating that foreseeable governance risks were identified, assigned, engineered and monitored before they became incidents.
Request a briefing