Feature Incident Response
Insider Threat Incident Response: The First 72 Hours for Financial Institutions
Insider threats are the incident type where almost every instinct is wrong. A step-by-step framework for financial services — from the first alert through separation, SAR filing, and breach notification — without destroying the investigation or creating wrongful termination exposure.
Table of Contents
TL;DR:
- Insider threats require evidence preservation before containment — the opposite of external cyber incident response. Security teams trained to contain first will destroy these investigations.
- The 2025 Ponemon Cost of Insider Risks Report puts financial services at $21.25 million average per incident — the highest of any industry. Incidents taking over 90 days to contain average $18.33M.
- A cross-functional team (Security, Legal, HR, Internal Audit) must be assembled before any action that could tip the subject — including access reviews, manager conversations, or IT changes.
- The 72-hour timeline covers evidence capture, scope assessment, separation execution, and regulatory notification triggers — SAR filing, breach notification, and FINRA obligations depending on what the insider accessed.
The Incident Type Where Every Instinct Is Wrong
The first instinct when an insider threat alert fires is the same as for every other security incident: contain it. Lock the account. Pull the device. Alert the manager.
Each of those actions, done before evidence is preserved, can destroy the investigation.
A subject who loses account access before their activity is fully captured will never provide the complete picture of what they accessed. A device pulled to IT before forensic imaging may be overwritten by standard reset procedures. A manager who knows too early will have a conversation with the employee — and that conversation will appear in the employee’s termination lawsuit.
Insider threats require a different priority order: evidence first, containment second. That reversal runs contrary to how most security teams are trained, and it accounts for most insider investigation failures.
The 2025 Ponemon Cost of Insider Risks Report found insider risk costs organizations an average of $17.4 million annually. For financial services specifically, the average per-incident cost is $21.25 million — a 47% increase from prior measurements and the highest of any industry. Incidents that take more than 90 days to contain cost an average of $18.33 million. The first 72 hours don’t just determine whether you understand what happened — they determine whether your evidence is usable, your notifications are timely, and your investigation is defensible.
Why Insider Threats Require a Different Response Framework
External threats — ransomware, phishing, credential stuffing — start with the attacker having no access. The investigation runs forward from the intrusion point: identify the exploit, trace lateral movement, document exfiltration.
Insider threats start with the attacker already having legitimate access to everything they need. The investigation runs backward from a signal: an unusual data export, a behavioral analytics flag, a manager’s concern, a compliance monitoring alert. You’re trying to understand what someone with valid credentials chose to do with them — often without knowing exactly what “it” is yet.
Three challenges external threat response doesn’t face:
You can’t just contain the threat. The insider hasn’t compromised a system — they are the authorized user. Revoking their access is a form of separation, not technical containment, and separation has significant legal and employment implications.
The investigation must stay confidential. An insider who knows they are under investigation has significant opportunity: delete files, communicate with co-conspirators, exfiltrate data to personal devices or cloud storage. Every person who knows about the investigation before evidence is secured is a potential path to alerting the subject.
HR and Legal must be in the room from hour one. Unlike an external incident where the first call after Security is IT Operations, an insider investigation requires Legal, HR, and Internal Audit engaged before Security takes any consequential action. Employment decisions made without HR involvement create liability. Evidence collected without legal oversight may be inadmissible or privilege-compromised.
Assembling the Cross-Functional Team
The SIFMA Insider Threat Best Practices Guide (3rd Edition, July 2024) defines the minimum team structure for financial institutions conducting insider threat investigations:
| Function | Primary Role |
|---|---|
| Information Security / CISO | Alert triage, digital evidence capture, forensic coordination, monitoring |
| Legal | Privilege protection, evidence collection methodology, employment law review, regulatory notification timing |
| Human Resources | Employment status verification, HR records, termination authorization, employment agreement and union considerations |
| Internal Audit | Financial crime investigation support, loss quantification, control gap identification |
| Compliance / Privacy | SAR filing analysis, breach notification scope, FINRA/regulatory notification, customer data exposure assessment |
| Third-Party Risk | Assess vendor portal access, shared infrastructure, notifications owed to partners |
The critical sequencing constraint: Legal must be engaged before substantive investigation steps, not after. Evidence collected without legal oversight may not survive a privilege challenge. Employment decisions made without HR may create wrongful termination exposure. Regulatory notifications made prematurely — before the scope of customer data exposure is understood — may undermine parallel law enforcement engagement and over-notify in ways that create consumer harm.
The First 72 Hours: A Response Timeline
Hours 1–4: Alert Triage and Quiet Escalation
When a potential insider threat alert fires — a DLP trigger, a user behavior analytics flag, a manager tip, an anonymous compliance report — the first four hours are about understanding scope without alerting the subject.
Actions:
- Escalate to Security leadership and Legal simultaneously; do not inform the subject’s manager
- Pull available log data passively: audit logs, access logs, email metadata visible at the system level without touching the endpoint
- Establish an out-of-band secure communication channel for the investigation team (email the insider can access is not appropriate)
- Determine whether any regulatory clock has started — if customer personal data exposure is already confirmed, breach notification timelines may already be running
- Assign a single investigation lead with authority to make real-time decisions
Do not:
- Make any changes to the subject’s access, devices, or systems
- Run queries that generate visible account alerts for the subject
- Brief the subject’s manager or any colleague outside the investigation team
- Begin HR processes or any action that creates a paper trail the subject might see
Hours 4–24: Evidence Preservation
Before containment — before any access revocation, device seizure, or account restriction — digital evidence must be captured. This is the hardest part of insider threat response for teams trained on external incidents.
Digital evidence to preserve before any containment action:
- Complete system, application, and network logs for the relevant review period
- Cloud storage and file sharing activity: SharePoint, OneDrive, Dropbox, Google Drive, Box
- Removable media connections: USB drives, external storage, printer activity
- After-hours and anomalous access patterns — time-of-day and volume anomalies
- Email headers and metadata (content may require Legal sign-off on privilege questions)
- Collaboration tool metadata: Teams, Slack, Zoom call records
- Physical badge access records if the incident has a physical component
- Endpoint activity: browser history, application usage, file access, download history
Legal should direct the evidence capture methodology. Evidence collected without documented chain-of-custody procedures is routinely challenged in employment litigation and criminal proceedings. Forensic consultants following strict chain-of-custody protocols are frequently engaged at this stage for anything that may become a legal or criminal matter.
If the incident may involve financial crime — unauthorized transactions, fund diversions, fraudulent credits — Internal Audit should begin a parallel financial trail documentation simultaneously with digital evidence capture.
Hours 24–48: Scope Assessment and Decision Points
With evidence secured, the investigation shifts to understanding what the insider actually accessed, took, or did.
Questions to answer by hour 48:
- What data was accessed or exfiltrated? Customer PII? Source code? Internal financial data? Competitive information? Employee records? The answer drives the regulatory notification analysis entirely.
- What is the financial impact? Unauthorized transactions, diverted funds, fraudulent credits, manipulated records?
- Are there co-conspirators? Internal accomplices? External parties receiving data or funds? Evidence of coordination should delay separation of the primary subject until co-conspirators are identified.
- What was the access mechanism? Authorized access used for unauthorized purpose? Credential theft or sharing? Exploitation of privileged access?
- Is this criminal? Law enforcement referral decisions should be made with Legal at this stage. Early law enforcement engagement can expand evidence collection authority but may affect your timeline for internal action.
The scope assessment drives notification decisions. If customer PII was accessed or exfiltrated, state breach notification laws apply — see the 50-state breach notification law comparison for jurisdiction-specific timelines, most of which run 30-72 hours from discovery of the breach. If financial crime occurred, SAR filing obligations attach with a 30-day clock from detection.
Hours 48–72: Separation, Regulatory Notifications, and Post-Separation Controls
By hour 72, most insider threat investigations have enough to make a separation decision — even if the full investigation continues for weeks afterward.
Separation execution protocol:
Legal and HR control timing and logistics. The separation conversation should happen simultaneously with:
- Access revocation across all enterprise systems
- Cloud service disconnection (Microsoft 365, Google Workspace, Salesforce)
- VPN and remote access termination
- Vendor portal access removal — notify relevant third parties if the insider had privileged access to their systems
- Device surrender (executed as part of the separation meeting, not after)
Any gap between separation notification and system lockout is a window for additional harm. The subject should not be alone with any company device between the conversation and departure.
Regulatory notifications decision tree:
| Trigger | Notification Required | Timeline | Notes |
|---|---|---|---|
| Customer PII accessed/exfiltrated | State breach notification | 30-72 hours from discovery (varies by state) | All affected customers in relevant states |
| Financial crime (theft, fraud, unauthorized transactions) | SAR filing | Within 30 calendar days of detection | No dollar minimum for insider violations |
| Broker-dealer | FINRA notification | Per Rule 3110 and Reg S-P requirements | Review 2026 FFIEC guidance on cyber incidents |
| OCC/FDIC-supervised bank | FFIEC 36-hour notification | 36 hours if materially disruptive | See FFIEC 36-hour computer security incident notification rule |
| Law enforcement referral | FBI/FinCEN coordination | Coordinated with Legal | May affect SAR filing timing and content |
Post-separation security controls:
- Audit all privileged access grants provisioned by the insider — they may have created backdoor accounts or elevated other users
- Sweep shared infrastructure for credentials the insider may have provided to external parties
- Review whether co-worker accounts show unusual activity consistent with coordinated exfiltration
- Notify relevant bank partners or sponsors if the incident touched their systems or customer data in their custody
The HR/Legal Tension That Kills Investigations
The most common insider investigation breakdown is HR and Security operating on different priorities.
Security wants to move fast — every hour the subject has access is an additional hour of exposure. HR wants documentation — termination without adequate documented process creates wrongful termination exposure. Legal wants privilege protection — investigation notes should be created under attorney-client privilege where possible.
The resolution is structured role separation established before an incident occurs: Security owns evidence capture, HR owns employment decisions, Legal owns the investigation’s legal framework. None of the three acts on anything consequential without the others’ awareness. This structure needs to be in your incident response playbook before you need it. Negotiating it in real time while an investigation is active adds hours you don’t have.
A 2021 case involving a TD Bank employee illustrates the criminal prosecution end of this framework: an insider used his position to identify high-balance customer accounts, steal confidential customer information, and facilitate millions of dollars of fraud. The prosecution built its case on access logs and digital evidence that the bank’s systems preserved — exactly the evidence the 72-hour framework is designed to protect. The insider ultimately pleaded guilty to conspiracy to commit wire fraud affecting a financial institution.
The FINRA 2026 Annual Regulatory Oversight Report explicitly identifies insider threats as an emerging risk category for member firms, noting that firm employees “advertently or inadvertently” using privileged access to cause harm have increased as a regulatory concern — and that firms’ monitoring, detection, and response capabilities are a direct examination focus.
For context on how insider threat response connects to the broader incident response architecture, our Cyber Incident Response Playbook covers the governance structure and escalation framework within which insider response sits.
So What?
Insider threats cost financial institutions an average of $21.25 million per incident. The cost difference between incidents contained in under 30 days versus those that drag past 90 is measured in millions. The first 72 hours determine which track you’re on.
The principles are counterintuitive but consistent:
- Evidence before containment — always
- Legal before HR before Security decisions on anything consequential
- Scope assessment before regulatory notification
- Separation simultaneous with system lockout, never before
Build the playbook before you need it. Run a tabletop with HR, Legal, and Security together — not separately. The first real insider threat investigation is not the time to discover that your HR team expects two weeks of documentation before any action and your Security team wants to lock accounts within the hour.
For a complete incident response framework — including breach notification timelines for all 50 states, SAR filing procedures, insider threat playbooks, and tabletop exercise scenarios — the Incident Response & Breach Notification Kit gives you the pre-built templates and notification trackers to manage these decisions under time pressure.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
When does an insider threat incident require a SAR filing?
Should I alert the subject before I have sufficient evidence?
What's the difference between insider threat response and a standard cyber incident response?
What regulatory notifications are typically required for an insider threat incident?
Can I terminate the employee before completing the investigation?
What is the average cost of an insider threat incident at a financial institution?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
Incident Response Decision Log: Document Why a Notification Clock Did—or Did Not—Start
When a cyber event hits, every regulator wants the same thing: proof you made a good-faith materiality determination without unreasonable delay. Here's the decision log structure that creates that proof—whether the clock started or not.
Jul 24, 2026
Incident Response
Four Months Late: What the NYDFS Healthplex $2M Penalty Says About When the Notification Clock Actually Starts
NYDFS fined Healthplex $2 million in August 2025 for notifying 4+ months after a breach. The failure wasn't forensics — it was a misunderstanding of when the 72-hour clock starts. The same mistake trips up banks under the FDIC's 36-hour rule.
Jul 23, 2026
Incident Response
Three Clocks, One Incident: How to Manage the Overlapping Cyber Notification Timelines Under OCC, NYDFS, and SEC Rules
When a cyber incident hits, you're not managing one notification obligation — you're managing six, with different triggers, different recipients, and different clocks. The OCC's 36-hour rule, NYDFS's 72-hour requirement, the SEC's 4-business-day materiality window, GLBA customer notices, FinCEN SAR filing, and bank partner contractual obligations all run simultaneously. Here's how to track them without missing one.
Jul 18, 2026