As artificial intelligence enables more sophisticated cyber attacks, cyber-enabled fraud incidents are becoming both more frequent and more costly. Global incident costs are projected to reach USD $265 billion by 2031, not including the significant indirect costs of reputational damage and long-term recovery.1
Cyber risk is now a constant in the operating environment, with incidents carrying the potential to create widespread and cascading disruption across everyday business and social systems. Yet many organizations remain underprepared. When incidents impact operations, data, payments, clients, or reputation, there is little time to establish leadership, set priorities, or coordinate communications. Without a defined response approach, organizations are forced to make high-stakes decisions under pressure—often increasing the risk of disruption, delayed recovery, and loss of trust.
This gap between risk and readiness is reflected in global executive sentiment. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, cyber-enabled fraud and phishing are now the top cyber risk concerns for CEOs, with 77% of organizations reporting an increase in incidents. At the same time, only 19% believe their cyber resilience exceeds baseline requirements, while 45% cite skills shortages as a key barrier to improvement2.
These findings underscore a broader reality: for many organizations, incident response is still not fully embedded as a core business capability. That is why building an incident response plan is critical.
Incidents impact businesses of all sizes
This challenge is not limited to large enterprises. The United Nations Office for Disaster Risk Reduction estimates that 40% of small and medium-sized businesses do not reopen after a major disruption, and only 20–30% have written business continuity plans in place.3 In Canada, preparedness gaps may be even more pronounced. Ann Wyganowski, vice-president at HZX Business Continuity Planning and an instructor at Disaster Recovery Institute Canada, estimates that close to 90% of small businesses do not have a continuity plan4. While not specific to cyber incidents, these findings underscore a broader truth—organizations that prepare in advance are better positioned to adapt, recover, and continue operating when disruption occurs.
Regardless of size, the organizations best positioned to navigate disruption are those that have prepared in advance—establishing the structures needed to respond quickly, make informed decisions, and maintain continuity when it matters most.
Minimizing the impact of an incident
An effective incident response plan provides the foundation for rapid, coordinated action.
By defining roles, escalation paths, and decision-making frameworks in advance, organizations can contain issues more quickly, reduce operational disruption, and maintain continuity during high-impact events before they escalate into broader business disruption.
The value of this preparedness is measurable. IBM’s Cost of a Data Breach Report found that organizations with an incident response team and formal plans reduce breach costs by an average of USD $473,706.5
Beyond cost, a clear plan also helps protect the systems, information, and data that are critical to day-to-day operations and long-term business resilience.
Strengthening long-term growth
The impact of incident response planning extends beyond immediate containment. In high-stakes moments, clients, partners, employees, and other stakeholders are not only watching how quickly an organization responds, but how clearly and credibly it leads. Businesses that can act with coordination and transparency are better positioned to strengthen their reputation as a secure organization, reinforce customer and partner confidence, and preserve trust even under pressure.
Over time, the process of building and maintaining a response plan also strengthens the organization itself. It helps identify vulnerabilities, clarify dependencies, and improve coordination before an incident occurs. As the Canadian Centre for Cyber Security advises, organizations should define critical services, document response procedures, and regularly test continuity plans6.
In that sense, incident response planning is not only about managing disruption—it is a practical way to build a more resilient, adaptive organization over the long term.
Information sharing protects the business community
As incident response capabilities mature, leading organizations are expanding their focus beyond internal coordination to include external reporting and information sharing. Guidance from the Canadian Anti-Fraud Centre emphasizes the importance of reporting fraud and cyber incidents to both law enforcement and national systems, enabling authorities to identify patterns, connect cases, and strengthen prevention efforts across the broader economy7.
Ultimately, the organizations best positioned to withstand disruption are often those that invested time in preparation before an incident occurred. In an environment where trust, continuity, and responsiveness carry significant weight, building a plan is not just about responding to crises. It is about ensuring the organization can lead with clarity, credibility, and control when it matters most, and emerge having protected the trust on which long-term relationships depend.
To learn more on how to protect your business visit us at www.scotiabank.com/BusinessProtection
Disclaimer
This article is provided for information purposes only. It is not to be relied upon as financial, tax or investment advice or guarantees about the future, nor should it be considered a recommendation to buy or sell. Information contained in this article, including information relating to interest rates, market conditions, tax rules, and other investment factors are subject to change without notice and The Bank of Nova Scotia is not responsible to update this information. All third-party sources are believed to be accurate and reliable as of the date of publication and The Bank of Nova Scotia does not guarantee its accuracy or reliability. Readers should consult their own professional advisor for specific financial, investment and/or tax advice tailored to their needs to ensure that individual circumstances are considered properly, and action is taken based on the latest available information.
Sources
1. Vergara Cobos, Estefania; and Cakir, Selcen. (2024). A Review of the Economic Costs of Cyber Incidents. Washington, DC: World Bank. https://documents1.worldbank.org/curated/en/099092324164536687/pdf/P17876919ffee4079180e81701969ad0a18.pdf
2. World Economic Forum. (2026, January). Global Cybersecurity Outlook 2026. https://www.weforum.org/reports/global-cybersecurity-outlook-2026
3. United Nations Office for Disaster Risk Reduction. (2025, June 27). Continuity planning empowers businesses to adapt, recover, and thrive. https://www.undrr.org/news/continuity-planning-empowers-businesses-adapt-recover-and-thrive
4. The Globe and Mail. (2025, May). After a crisis, can your small business keep going? https://www.theglobeandmail.com/business/adv/article-after-a-crisis-can-your-small-business-keep-going
5. IBM. (n.d.). Incident response. IBM Think. https://www.ibm.com/think/topics/incident-response
6. Canadian Centre for Cyber Security. (2026, January). Developing your business continuity plan (ITSAP.10.005). Government of Canada. https://www.cyber.gc.ca/en/guidance/developing-your-business-continuity-plan-itsap10005
7. Canadian Anti-Fraud Centre. (2025, November 27). Report fraud and cybercrime. Government of Canada. https://antifraudcentre-centreantifraude.ca/report-signalez-eng.htm