Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Incident Response

Insider Threat Incident Response: The First 72 Hours for Financial Institutions

Insider threats are the incident type where almost every instinct is wrong. A step-by-step framework for financial services — from the first alert through separation, SAR filing, and breach notification — without destroying the investigation or creating wrongful termination exposure.

Table of Contents

TL;DR:

  • Insider threats require evidence preservation before containment — the opposite of external cyber incident response. Security teams trained to contain first will destroy these investigations.
  • The 2025 Ponemon Cost of Insider Risks Report puts financial services at $21.25 million average per incident — the highest of any industry. Incidents taking over 90 days to contain average $18.33M.
  • A cross-functional team (Security, Legal, HR, Internal Audit) must be assembled before any action that could tip the subject — including access reviews, manager conversations, or IT changes.
  • The 72-hour timeline covers evidence capture, scope assessment, separation execution, and regulatory notification triggers — SAR filing, breach notification, and FINRA obligations depending on what the insider accessed.

The Incident Type Where Every Instinct Is Wrong

The first instinct when an insider threat alert fires is the same as for every other security incident: contain it. Lock the account. Pull the device. Alert the manager.

Each of those actions, done before evidence is preserved, can destroy the investigation.

A subject who loses account access before their activity is fully captured will never provide the complete picture of what they accessed. A device pulled to IT before forensic imaging may be overwritten by standard reset procedures. A manager who knows too early will have a conversation with the employee — and that conversation will appear in the employee’s termination lawsuit.

Insider threats require a different priority order: evidence first, containment second. That reversal runs contrary to how most security teams are trained, and it accounts for most insider investigation failures.

The 2025 Ponemon Cost of Insider Risks Report found insider risk costs organizations an average of $17.4 million annually. For financial services specifically, the average per-incident cost is $21.25 million — a 47% increase from prior measurements and the highest of any industry. Incidents that take more than 90 days to contain cost an average of $18.33 million. The first 72 hours don’t just determine whether you understand what happened — they determine whether your evidence is usable, your notifications are timely, and your investigation is defensible.

Why Insider Threats Require a Different Response Framework

External threats — ransomware, phishing, credential stuffing — start with the attacker having no access. The investigation runs forward from the intrusion point: identify the exploit, trace lateral movement, document exfiltration.

Insider threats start with the attacker already having legitimate access to everything they need. The investigation runs backward from a signal: an unusual data export, a behavioral analytics flag, a manager’s concern, a compliance monitoring alert. You’re trying to understand what someone with valid credentials chose to do with them — often without knowing exactly what “it” is yet.

Three challenges external threat response doesn’t face:

You can’t just contain the threat. The insider hasn’t compromised a system — they are the authorized user. Revoking their access is a form of separation, not technical containment, and separation has significant legal and employment implications.

The investigation must stay confidential. An insider who knows they are under investigation has significant opportunity: delete files, communicate with co-conspirators, exfiltrate data to personal devices or cloud storage. Every person who knows about the investigation before evidence is secured is a potential path to alerting the subject.

HR and Legal must be in the room from hour one. Unlike an external incident where the first call after Security is IT Operations, an insider investigation requires Legal, HR, and Internal Audit engaged before Security takes any consequential action. Employment decisions made without HR involvement create liability. Evidence collected without legal oversight may be inadmissible or privilege-compromised.

Assembling the Cross-Functional Team

The SIFMA Insider Threat Best Practices Guide (3rd Edition, July 2024) defines the minimum team structure for financial institutions conducting insider threat investigations:

FunctionPrimary Role
Information Security / CISOAlert triage, digital evidence capture, forensic coordination, monitoring
LegalPrivilege protection, evidence collection methodology, employment law review, regulatory notification timing
Human ResourcesEmployment status verification, HR records, termination authorization, employment agreement and union considerations
Internal AuditFinancial crime investigation support, loss quantification, control gap identification
Compliance / PrivacySAR filing analysis, breach notification scope, FINRA/regulatory notification, customer data exposure assessment
Third-Party RiskAssess vendor portal access, shared infrastructure, notifications owed to partners

The critical sequencing constraint: Legal must be engaged before substantive investigation steps, not after. Evidence collected without legal oversight may not survive a privilege challenge. Employment decisions made without HR may create wrongful termination exposure. Regulatory notifications made prematurely — before the scope of customer data exposure is understood — may undermine parallel law enforcement engagement and over-notify in ways that create consumer harm.

The First 72 Hours: A Response Timeline

Hours 1–4: Alert Triage and Quiet Escalation

When a potential insider threat alert fires — a DLP trigger, a user behavior analytics flag, a manager tip, an anonymous compliance report — the first four hours are about understanding scope without alerting the subject.

Actions:

  • Escalate to Security leadership and Legal simultaneously; do not inform the subject’s manager
  • Pull available log data passively: audit logs, access logs, email metadata visible at the system level without touching the endpoint
  • Establish an out-of-band secure communication channel for the investigation team (email the insider can access is not appropriate)
  • Determine whether any regulatory clock has started — if customer personal data exposure is already confirmed, breach notification timelines may already be running
  • Assign a single investigation lead with authority to make real-time decisions

Do not:

  • Make any changes to the subject’s access, devices, or systems
  • Run queries that generate visible account alerts for the subject
  • Brief the subject’s manager or any colleague outside the investigation team
  • Begin HR processes or any action that creates a paper trail the subject might see

Hours 4–24: Evidence Preservation

Before containment — before any access revocation, device seizure, or account restriction — digital evidence must be captured. This is the hardest part of insider threat response for teams trained on external incidents.

Digital evidence to preserve before any containment action:

  • Complete system, application, and network logs for the relevant review period
  • Cloud storage and file sharing activity: SharePoint, OneDrive, Dropbox, Google Drive, Box
  • Removable media connections: USB drives, external storage, printer activity
  • After-hours and anomalous access patterns — time-of-day and volume anomalies
  • Email headers and metadata (content may require Legal sign-off on privilege questions)
  • Collaboration tool metadata: Teams, Slack, Zoom call records
  • Physical badge access records if the incident has a physical component
  • Endpoint activity: browser history, application usage, file access, download history

Legal should direct the evidence capture methodology. Evidence collected without documented chain-of-custody procedures is routinely challenged in employment litigation and criminal proceedings. Forensic consultants following strict chain-of-custody protocols are frequently engaged at this stage for anything that may become a legal or criminal matter.

If the incident may involve financial crime — unauthorized transactions, fund diversions, fraudulent credits — Internal Audit should begin a parallel financial trail documentation simultaneously with digital evidence capture.

Hours 24–48: Scope Assessment and Decision Points

With evidence secured, the investigation shifts to understanding what the insider actually accessed, took, or did.

Questions to answer by hour 48:

  1. What data was accessed or exfiltrated? Customer PII? Source code? Internal financial data? Competitive information? Employee records? The answer drives the regulatory notification analysis entirely.
  2. What is the financial impact? Unauthorized transactions, diverted funds, fraudulent credits, manipulated records?
  3. Are there co-conspirators? Internal accomplices? External parties receiving data or funds? Evidence of coordination should delay separation of the primary subject until co-conspirators are identified.
  4. What was the access mechanism? Authorized access used for unauthorized purpose? Credential theft or sharing? Exploitation of privileged access?
  5. Is this criminal? Law enforcement referral decisions should be made with Legal at this stage. Early law enforcement engagement can expand evidence collection authority but may affect your timeline for internal action.

The scope assessment drives notification decisions. If customer PII was accessed or exfiltrated, state breach notification laws apply — see the 50-state breach notification law comparison for jurisdiction-specific timelines, most of which run 30-72 hours from discovery of the breach. If financial crime occurred, SAR filing obligations attach with a 30-day clock from detection.

Hours 48–72: Separation, Regulatory Notifications, and Post-Separation Controls

By hour 72, most insider threat investigations have enough to make a separation decision — even if the full investigation continues for weeks afterward.

Separation execution protocol:

Legal and HR control timing and logistics. The separation conversation should happen simultaneously with:

  • Access revocation across all enterprise systems
  • Cloud service disconnection (Microsoft 365, Google Workspace, Salesforce)
  • VPN and remote access termination
  • Vendor portal access removal — notify relevant third parties if the insider had privileged access to their systems
  • Device surrender (executed as part of the separation meeting, not after)

Any gap between separation notification and system lockout is a window for additional harm. The subject should not be alone with any company device between the conversation and departure.

Regulatory notifications decision tree:

TriggerNotification RequiredTimelineNotes
Customer PII accessed/exfiltratedState breach notification30-72 hours from discovery (varies by state)All affected customers in relevant states
Financial crime (theft, fraud, unauthorized transactions)SAR filingWithin 30 calendar days of detectionNo dollar minimum for insider violations
Broker-dealerFINRA notificationPer Rule 3110 and Reg S-P requirementsReview 2026 FFIEC guidance on cyber incidents
OCC/FDIC-supervised bankFFIEC 36-hour notification36 hours if materially disruptiveSee FFIEC 36-hour computer security incident notification rule
Law enforcement referralFBI/FinCEN coordinationCoordinated with LegalMay affect SAR filing timing and content

Post-separation security controls:

  • Audit all privileged access grants provisioned by the insider — they may have created backdoor accounts or elevated other users
  • Sweep shared infrastructure for credentials the insider may have provided to external parties
  • Review whether co-worker accounts show unusual activity consistent with coordinated exfiltration
  • Notify relevant bank partners or sponsors if the incident touched their systems or customer data in their custody

The HR/Legal Tension That Kills Investigations

The most common insider investigation breakdown is HR and Security operating on different priorities.

Security wants to move fast — every hour the subject has access is an additional hour of exposure. HR wants documentation — termination without adequate documented process creates wrongful termination exposure. Legal wants privilege protection — investigation notes should be created under attorney-client privilege where possible.

The resolution is structured role separation established before an incident occurs: Security owns evidence capture, HR owns employment decisions, Legal owns the investigation’s legal framework. None of the three acts on anything consequential without the others’ awareness. This structure needs to be in your incident response playbook before you need it. Negotiating it in real time while an investigation is active adds hours you don’t have.

A 2021 case involving a TD Bank employee illustrates the criminal prosecution end of this framework: an insider used his position to identify high-balance customer accounts, steal confidential customer information, and facilitate millions of dollars of fraud. The prosecution built its case on access logs and digital evidence that the bank’s systems preserved — exactly the evidence the 72-hour framework is designed to protect. The insider ultimately pleaded guilty to conspiracy to commit wire fraud affecting a financial institution.

The FINRA 2026 Annual Regulatory Oversight Report explicitly identifies insider threats as an emerging risk category for member firms, noting that firm employees “advertently or inadvertently” using privileged access to cause harm have increased as a regulatory concern — and that firms’ monitoring, detection, and response capabilities are a direct examination focus.

For context on how insider threat response connects to the broader incident response architecture, our Cyber Incident Response Playbook covers the governance structure and escalation framework within which insider response sits.

So What?

Insider threats cost financial institutions an average of $21.25 million per incident. The cost difference between incidents contained in under 30 days versus those that drag past 90 is measured in millions. The first 72 hours determine which track you’re on.

The principles are counterintuitive but consistent:

  • Evidence before containment — always
  • Legal before HR before Security decisions on anything consequential
  • Scope assessment before regulatory notification
  • Separation simultaneous with system lockout, never before

Build the playbook before you need it. Run a tabletop with HR, Legal, and Security together — not separately. The first real insider threat investigation is not the time to discover that your HR team expects two weeks of documentation before any action and your Security team wants to lock accounts within the hour.

For a complete incident response framework — including breach notification timelines for all 50 states, SAR filing procedures, insider threat playbooks, and tabletop exercise scenarios — the Incident Response & Breach Notification Kit gives you the pre-built templates and notification trackers to manage these decisions under time pressure.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

When does an insider threat incident require a SAR filing?
Financial institutions must file a SAR when they know or have reason to suspect that an employee, officer, director, or agent engaged in transactions involving funds from illegal activity, facilitated a law violation, or otherwise triggered BSA reporting obligations. There is no dollar minimum for insider violations — unlike customer transaction thresholds. File when your investigation establishes reasonable grounds to suspect a violation. Don't wait for the full investigation to complete; the 30-day SAR filing window runs from the date of detection, not from case closure.
Should I alert the subject before I have sufficient evidence?
Almost never. Alerting the subject before evidence is preserved is the single most common insider threat investigation failure. A subject who knows they are under investigation will delete files, overwrite logs, communicate with co-conspirators, and exfiltrate remaining data to personal devices. Every person who knows about the investigation before evidence is secured is a potential tip-off path. Preserve all digital evidence before any action that could signal the investigation — including any HR conversations, performance discussions, IT access reviews, or manager notifications.
What's the difference between insider threat response and a standard cyber incident response?
In a standard cyber incident, first priority is containment — isolate the affected system. In an insider threat, first priority is evidence preservation — capture the complete digital record before it disappears. Containment (access revocation, device seizure) comes second, timed to happen simultaneously with or immediately after evidence capture, never before. This reversal of priorities is counterintuitive for security teams trained primarily on external threats and must be established in your playbook in advance.
What regulatory notifications are typically required for an insider threat incident?
Notification obligations depend on what the insider accessed and did. Customer PII accessed or exfiltrated: state breach notification laws apply, most requiring notification within 30-72 hours of discovering the breach. Financial crime occurred: SAR filing required within 30 days of detection. Broker-dealers: FINRA notification obligations and Reg S-P requirements. OCC-supervised banks: the FFIEC 36-hour computer security incident notification rule may apply if the incident materially disrupts operations or services.
Can I terminate the employee before completing the investigation?
Yes, but timing matters significantly. Premature separation can destroy evidence if the employee's device leaves with them before forensic imaging; create wrongful termination exposure if the investigation hasn't yet established sufficient grounds; and alert co-conspirators who haven't yet been identified. Legal counsel should control separation timing. Device surrender and access revocation across all systems must execute simultaneously with the separation conversation — any gap between notification and lockout is a window for additional harm.
What is the average cost of an insider threat incident at a financial institution?
The 2025 Ponemon Cost of Insider Risks Report found insider risk costs organizations an average of $17.4 million annually. Financial services firms face the highest per-incident cost of any industry at $21.25 million — a 47% increase from prior measurements. Incidents that take more than 90 days to contain average $18.33 million, compared to significantly lower costs for incidents contained within 30 days. The first 72 hours determine which cost track you're on.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.