Skip to content
RiskTemplates · The Daily Brief Tuesday, August 18, 2026
Wire FINRA's 24 Enforcement Review Recommendations: Read Them as Proposals, Not Rules AUG 11

Feature Incident Response

Cyber Incident Notification: Bank, SEC, State, and Future CIRCIA Clocks

Sequence live bank, SEC, and state notification analyses while keeping CIRCIA's future 72-hour workflow conditional on an effective final rule.

Table of Contents

August 17, 2026 correction: The CIRCIA 72-hour and ransom-payment clocks are future-state only. No CIRCIA final rule was in force. The bank 36-hour rule, SEC rules, and applicable state or sector duties must be analyzed under their own current text.

TL;DR

  • Use one incident fact record but a separate trigger memo and deadline for each regime.
  • The banking agencies’ 36-hour clock runs after determination of a notification incident.
  • SEC Form 8-K Item 1.05 generally runs four business days after a public company determines materiality.
  • State breach and sector rules vary; do not assign one universal 72-hour clock.
  • Keep CIRCIA conditional until CISA’s final rule is effective.

Why Sequencing Fails

Incident teams often put “36h / 72h / four days” on a slide and assume they have a notification process. The hard question is not the arithmetic. It is identifying the legally relevant event that starts each clock and preserving the evidence behind that determination.

A reliable workflow separates:

  1. awareness of a technical event;
  2. escalation into legal, risk, and executive review;
  3. regime-specific determination;
  4. deadline calculation;
  5. submission and approval; and
  6. supplemental or continuing duties.

Current Federal Banking Rule: 36 Hours

The interagency final rule requires a covered banking organization to notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a computer-security incident rises to the level of a notification incident.

The 36 hours do not automatically run from the first security alert. The institution must nevertheless escalate promptly enough to make the required determination. Preserve:

  • first alert and validation time;
  • when potential notification-incident facts emerged;
  • escalation to the accountable decision-maker;
  • determination time;
  • rationale and approver; and
  • notification time and method.

The OCC’s Bulletin 2021-55 provides an official agency reference for OCC-supervised institutions.

SEC Form 8-K: Materiality Determination

For a domestic public company, Form 8-K Item 1.05 generally requires disclosure within four business days after the registrant determines that a cybersecurity incident is material. The SEC rule requires the materiality determination without unreasonable delay after discovery.

Track the evidence considered in the materiality decision, including operational, financial, legal, customer, strategic, and reputational consequences where relevant. Do not wait for a perfectly quantified loss if qualitative facts can be material.

A national-security or public-safety delay is available only through the process in the rule. It is not a general law-enforcement exception the company can invoke on its own.

State and Sector Rules: Build a Matrix

State breach-notification duties differ in covered information, harm tests, regulator and consumer recipients, outside dates, law-enforcement delay, content, and supplemental notices. Sector rules such as NYDFS Part 500 add their own triggers and clocks.

The matrix should include:

FieldExample content
Jurisdiction and citationExact statute, rule, or regulator page
Covered entity and dataLegal-entity and information scope
TriggerDiscovery, determination, likelihood of harm, or other event
RecipientConsumer, attorney general, regulator, credit bureau, other
ClockPromptness standard or outside deadline
DelayConditions and approval evidence
Follow-upSupplemental facts, certification, payment explanation, updates

Have counsel validate the matrix and review it on a defined cadence.

Future CIRCIA: Keep It Conditional

CISA’s CIRCIA status page says covered entities will not be required to report until the final rule goes into effect. The 2024 NPRM proposes detailed coverage and procedures for the statutory 72-hour covered-incident and 24-hour ransom-payment architecture.

Do not place CIRCIA in the “live filings” column. Use this status:

CIRCIA itemCurrent treatment
CoverageProvisional assessment under NPRM; revalidate against final rule
72-hour incident workflowTabletop and data mapping only
24-hour ransom-payment workflowTabletop and data mapping only
Submission formDo not represent as final
Effective dateUnknown until final agency action

A Sequencing Workflow

Phase 1: Stabilize and open the fact record

Do not delay containment to draft a notice. At the same time, open a timestamped record with affected systems, service impact, data, customers, legal entities, vendors, recovery, and ransom facts.

Phase 2: Route separate trigger analyses

Assign named decision-makers for bank notification, SEC materiality, state breach, sector rules, contracts, insurance, and future CIRCIA. Each owner should see the same facts but answer a different legal question.

Phase 3: Record determination times

The deadline register should show both the event time and the legal determination time. A generic “incident began” field cannot support every calculation.

Phase 4: Draft from verified facts

Separate confirmed facts, reasonable assessments, unknowns, and planned follow-up. Reconcile regulator, customer, insurer, counterparty, and public statements to avoid unsupported inconsistency.

Phase 5: Track updates

Some regimes or commitments require supplemental information. Keep the matter open until legal, regulatory, contractual, and governance follow-up is complete.

Tabletop Test

Use a scenario where a critical provider fails, transaction processing is intermittent, customer impact grows over six hours, data access is uncertain, and a listed parent may face material consequences.

Require the team to produce:

  • a bank-rule determination memo;
  • an SEC materiality decision record;
  • a state and sector matrix extract;
  • a contractual-notice log;
  • a clearly labeled future CIRCIA analysis; and
  • an executive timeline showing the different clock starts.

The exercise fails if the team announces that “the 72-hour CIRCIA deadline” is live.

So What?

There is no universal cyber-notification clock. The control is disciplined trigger analysis using a shared fact base.

Keep current bank, SEC, state, sector, contract, and insurance workflows live. Prepare for CIRCIA, but activate it only after final text establishes coverage, procedures, and effective timing.

The Incident Response & Breach Notification Kit can support the trigger matrix and evidence log. Legal owners must maintain the current citations.


Primary sources: Federal banking agencies’ 36-hour rule announcement | OCC Bulletin 2021-55 | SEC Form 8-K | CISA CIRCIA status | 2024 CIRCIA NPRM

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Is CIRCIA a current reporting clock?
No. As of August 17, 2026, CISA had not issued the final rule, and CISA says mandatory reporting begins only after that rule goes into effect. Model the 72-hour and 24-hour processes as future-state readiness.
What is the current federal bank notification clock?
A covered banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a computer-security incident is a notification incident.
When does a public company file Form 8-K Item 1.05?
A domestic registrant generally files within four business days after determining that a cybersecurity incident is material, subject to the SEC rule and any authorized national-security or public-safety delay. The materiality determination must be made without unreasonable delay after discovery.
Can one master timer manage all notices?
No. Different regimes can start from discovery, determination, reasonable belief, materiality, harm, payment, or another event. Use one fact record with separate legal trigger and clock records.
What should an incident commander track?
Track discovery, escalations, affected services, customer and data impact, materiality, regulator-specific determinations, ransom-payment facts, decisions, approvers, deadlines, submissions, and follow-up obligations.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.