Most conversations about data security focus on prevention. This one is about what comes after.
Brokerages hold more sensitive client information than most businesses their size: full legal names, income documentation, employment history, bank statements, government identification. That data gets collected during a transaction and often sits in systems long after the deal closes.
When a breach happens, whether through a hacked email account, an exposed database, or a compromised third-party tool, the timeline that follows is predictable. It's also rarely discussed.
The first 72 hours
You find out, usually from someone outside the organization. A client calls saying they received a suspicious message that referenced their transaction details. Or a staff member notices something strange in an account. Or, in some cases, you find out because the data is already circulating somewhere.
The immediate questions are difficult ones. What data was accessed? For how long? Who is affected?
Most brokerages don't have the logging in place to answer those questions quickly. The first 72 hours are often spent trying to understand what happened rather than actually responding to it.
What Canadian privacy law requires
Under PIPEDA, Canada's federal privacy law, organizations must report a breach to the Office of the Privacy Commissioner if there's a real risk of significant harm to the people affected. They also have to notify those individuals directly.
That notification has to describe what happened, what data was involved, and what steps are being taken. Writing that letter to clients who trusted you with sensitive financial information is not a comfortable experience.
The lasting cost
The technical fix is usually the cheapest part. A compromised account gets secured. A misconfigured system gets patched. Those are one-time costs.
The harder costs come after: clients who don't refer anyone following the incident, agents who move to a different brokerage, recruits who choose a competitor, and time that senior people spend managing the aftermath instead of growing the business.
Most breaches aren't the result of sophisticated attacks. They're the result of something basic that wasn't checked: a password policy that wasn't enforced, a system that didn't need to be accessible from the internet but was, an old account that should have been closed years ago.
Those things are easy to find when you're looking for them. They're invisible when you're not.