Feature Incident Response
When One Cyber Incident Triggers Four Notification Clocks: Sequencing FFIEC, CIRCIA, SEC, and State Breach Law Obligations
A single cyber incident at a bank or fintech can simultaneously trigger the FFIEC 36-hour rule, CIRCIA's 72-hour CISA notification, the SEC's 4-business-day Form 8-K requirement, and state breach notification deadlines — each starting from a different legal trigger. Here's how to sequence them without missing one.
Table of Contents
It’s Monday morning. Your security team detects unusual network traffic at 7:02 a.m. By 8:30 a.m., you’ve confirmed ransomware has encrypted three core banking systems. The CEO is in the room. The general counsel is on the phone.
Someone asks: “What do we have to report, and when?”
The answer is: four different things, to four different recipients, with four different deadlines that started running at four different times based on four different legal standards.
Most financial institution incident response plans have a “regulatory notification” section. Most of them were written before this regulatory complexity existed. If yours doesn’t specifically address the sequencing problem — FFIEC versus CIRCIA versus SEC versus state breach laws — it has a gap that will cost you under pressure.
TL;DR
- A single cyber incident at a bank or fintech can simultaneously trigger four separate notification obligations: the FFIEC 36-hour rule (to banking regulators), CIRCIA (to CISA within 72 hours), the SEC Form 8-K Item 1.05 requirement (within 4 business days of materiality determination), and state breach notification laws (30–72 hours depending on state and affected residents)
- Each obligation starts from a different legal trigger: CIRCIA uses “reasonably believes” (earlier, lower bar); FFIEC and SEC use “determines” (later, higher standard)
- CISA and banking regulators have not finalized harmonization rules — you cannot assume FFIEC notification satisfies CIRCIA
- Your IR playbook needs a decision tree that explicitly maps which regulator gets notified first, by whom, with what information, and how the clocks interact
The Four Clocks and When They Start
| Framework | Who Notifies | Notify Whom | Trigger Standard | Timeline |
|---|---|---|---|---|
| FFIEC 36-Hour Rule | Banking org + bank service providers | Primary federal banking regulator (OCC, FDIC, or Fed) | “Determines” a notification incident occurred | 36 hours from determination |
| CIRCIA | Any covered entity (includes financial institutions) | CISA | ”Reasonably believes” a covered cyber incident occurred | 72 hours from reasonable belief |
| SEC Form 8-K Item 1.05 | SEC registrants (public companies) | SEC (public filing) | “Determines” the incident is material | 4 business days from materiality determination |
| State breach notification laws | Any entity holding affected state residents’ data | State AG + affected residents | ”Discovers” or becomes aware of a breach | 30–72 hours depending on state (NY: 72 hrs to AG; Maine: 7 days; CA: “expedient time”) |
Three of the four frameworks require “determining” or “discovering” something. CIRCIA alone uses a “reasonable belief” standard — deliberately set lower so that early reporting allows CISA to coordinate sector-wide response before the full scope of an incident is known.
The practical consequence: your CIRCIA clock starts before your internal assessment is done.
By the time your IR team has isolated the affected systems, confirmed the attack vector, and assessed whether you’ve crossed the FFIEC “notification incident” threshold, you may have already used 12-18 hours of your 72-hour CIRCIA window.
The Triggering Standards Problem
The difference between “reasonably believes” and “determines” is not semantic. It represents a meaningfully different point in your incident timeline.
At hour 8 of a ransomware incident, you almost certainly “reasonably believe” you have a covered cyber incident. Ransomware is ransomware. It has substantially affected the availability of your systems. CIRCIA clock is running.
At hour 8, you may not have “determined” whether this is a “notification incident” under the FFIEC rule. You’re still assessing how many systems are affected, whether customer-facing services are degraded, whether banking operations are materially disrupted. The FFIEC determination might come at hour 18 or hour 30 — after your incident commander and general counsel have reviewed the scope.
At hour 8, you definitely have not “determined” materiality for SEC purposes. That assessment requires evaluating financial impact, customer harm, operational duration, and regulatory consequences — a multi-day process for complex incidents.
And state breach notification clocks start when you “discover” that personal information was accessed without authorization — which might be hour 2 (if logs show exfiltration) or hour 72 (if forensics is needed to determine whether data was accessed).
The same incident, four different starting points.
Your IR playbook needs to address all four starting points explicitly. Most don’t.
For more on the FFIEC rule specifically, the FFIEC 36-Hour Computer Security Incident Notification Rule covers what constitutes a notification incident, what the notification must contain, and what examiners test during exam review.
CIRCIA’s Harmonization Provision — What It Does and Doesn’t Do
Section 2242(k) of CIRCIA directs CISA to work with sector risk management agencies to harmonize cyber incident reporting requirements and create exemptions where covered entities are already satisfying substantially similar obligations through sector-specific regulators.
For banking, the sector risk management agency is the prudential regulators — OCC, FDIC, and Federal Reserve. In theory, this provision could allow banks that notify their primary federal banking regulator to satisfy their CIRCIA obligation without a separate CISA filing.
In practice, CISA has not finalized those harmonization rules. As of mid-2026, there is no formal exemption in place that allows FFIEC notification to substitute for CISA notification under CIRCIA. The interagency agreements and reporting-to-CISA exemptions authorized by the statute are still being developed.
Until CISA publishes final harmonization guidance:
- File your FFIEC notification with your primary banking regulator within 36 hours of determination
- File your CIRCIA report with CISA within 72 hours of reasonable belief — separately, even if you’ve already notified your banking regulator
- Do not assume one substitutes for the other
The CIRCIA 72-Hour Reporting Guide for Financial Institutions covers the technical specifics of what CISA’s reporting portal requires and how to file a preliminary versus substantive report.
The SEC Form 8-K Layer
The SEC’s cyber disclosure rule (effective December 2023) adds a fourth clock that operates on a different axis entirely. This one isn’t about operational notification to regulators — it’s about public disclosure to investors.
Under Item 1.05, SEC registrants must file a Form 8-K describing any material cybersecurity incident within four business days of determining materiality. The materiality determination is what starts the clock — not discovery, not initial determination that an incident occurred, but the completed assessment that the incident meets the “material” threshold under the securities law standard.
For banks that are also SEC registrants, this creates a layered obligation: FFIEC notification (operational, to banking regulators) and SEC Form 8-K (public, to investors). These serve different purposes and cannot substitute for each other.
The SEC’s materiality standard for cybersecurity incidents borrows from general securities law: information is material if there is a substantial likelihood that a reasonable investor would consider it important. In practice, this means:
- Not every incident requires an 8-K
- The materiality assessment must be documented, not just decided
- The 4-day clock runs from documented determination, not from initial discovery
- Delay of filing is only permitted under limited national security circumstances
For a detailed look at the triggering analysis, the SEC Cyber Disclosure Rule: 8-K Item 1.05 Materiality covers the specific factors SEC staff have indicated they evaluate.
State Breach Notification: The 50th Complexity
State breach notification laws add a 50-state variable to a problem that’s already complex. All 50 states have breach notification laws. They share some common elements (they all require notification of affected residents and most require AG notification) but differ dramatically on:
- Timeline: From Maine’s extended window to New York’s 72-hour AG notification requirement under the SHIELD Act to various states’ “most expedient time” standards
- Trigger: Some states trigger on unauthorized “access,” others require proof of “acquisition”
- Covered information: State definitions of what personal information triggers notification vary
- Small-breach exceptions: Some states have thresholds (a breach affecting fewer than X residents may trigger different requirements)
The 50-State Breach Notification Law Comparison breaks down the specific trigger and timeline requirements that matter most for financial institutions, including the states with the shortest deadlines.
For the sequencing problem: state breach notification obligations often run in parallel to your federal regulatory notifications. A ransomware attack that affects customer records in New York, California, and Texas simultaneously triggers three separate state notification frameworks — each with different timelines and content requirements — in addition to your FFIEC and CIRCIA obligations.
Building Your Multi-Regulator Notification Decision Tree
Your IR playbook needs a decision tree that maps the notification sequence explicitly. Here’s the framework most playbooks are missing:
Hour 0 — Incident Detected
- Who holds the decision on whether to activate the notification sequence?
- What evidence threshold triggers the CIRCIA “reasonable belief” assessment?
- Who has authority to make that assessment?
Hour 2-6 — Initial Assessment
- Document your assessment of whether you “reasonably believe” this is a covered cyber incident under CIRCIA. If yes: CIRCIA clock is running.
- Assign the CISA notification owner. This person’s job in the next 66 hours is to file or prepare to file with CISA, regardless of what else is happening in the incident.
- Begin parallel tracks: (a) incident containment, (b) regulatory notification preparation.
Hour 12-24 — FFIEC Assessment
- Has the incident caused or is it “reasonably likely to cause” material disruption to banking operations? If yes: FFIEC clock starts. You have 36 hours from this determination.
- Notify your primary federal banking regulator (OCC, FDIC, or Federal Reserve) as soon as possible. The 36-hour deadline is a ceiling, not a target.
- Document what you notified, when, to whom, and via what channel.
Hour 24-72 — CISA Notification
- File with CISA at CISA’s Cyber Incident Reporting Portal by hour 72 from reasonable belief.
- A preliminary report is acceptable if full details are not available. CIRCIA requires follow-up supplemental reports as more information becomes available.
- Note: If ransom is paid, a separate 24-hour notification to CISA is required.
Ongoing — Materiality Assessment (for SEC registrants)
- Begin parallel materiality assessment process.
- Assign general counsel and CFO to lead the materiality determination.
- Set a deadline: materiality determination must be completed within 3 business days to avoid 8-K deadline risk.
- If material: file Form 8-K within 4 business days of determination.
Day 2-30 — State Breach Notification
- Once forensics confirms whether personal information was accessed, determine which states’ residents are affected.
- Apply each state’s trigger and timeline. Prioritize states with shortest deadlines (NY 72-hour AG notification).
- Coordinate consumer notice language with legal counsel.
For your incident triage methodology, the Incident Triage Techniques: Severity Classification, Materiality, and the SEC 4-Day Clock covers the scoring rubrics and escalation criteria that feed into this decision framework.
So What? Three Immediate Fixes for Your IR Playbook
1. Add an explicit notification sequencing section. Your playbook probably has a “regulatory notification” step. That step should be broken into four named obligations with explicit timelines, trigger standards, responsible owners, and escalation paths. “Notify regulators” is not a plan.
2. Assign dedicated owners for each notification stream. In a major incident, the IR team is consumed by containment. Regulatory notification has to have a separate owner who is not pulled off notification duties to help with technical response. The CISA notification owner, the banking regulator notification owner, and the SEC materiality assessment team all need to be pre-designated.
3. Build a template for each notification type. CIRCIA, FFIEC, SEC Form 8-K, and state breach notices all have different required elements. Pre-drafting templates with placeholders — incident description, affected systems, initial scope assessment, contact information — saves critical hours when clocks are running.
The Incident Response & Breach Notification Kit includes notification playbooks, regulatory notification templates, and a state-by-state breach law compliance tracker for financial institutions.
External Resources
- OCC: Computer-Security Incident Notification Requirements Final Rule (November 2021)
- CISA: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)
- SEC: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Final Rule
- BPI: Cyber Incident Reporting Requirements and Notification Timelines for Financial Institutions
- NCSL: Security Breach Notification Laws
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Do the FFIEC 36-hour rule and CIRCIA 72-hour reporting requirement both apply to banks?
What is the difference between when the FFIEC and CIRCIA notification clocks start running?
If I notify my primary banking regulator under the FFIEC rule, does that satisfy my CIRCIA obligation to notify CISA?
What triggers the SEC Form 8-K cyber incident disclosure under Item 1.05?
What happens if I notify CISA or my banking regulator late?
What is a 'notification incident' under the FFIEC rule vs. a 'covered cyber incident' under CIRCIA?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
Incident Response Decision Log: Document Why a Notification Clock Did—or Did Not—Start
When a cyber event hits, every regulator wants the same thing: proof you made a good-faith materiality determination without unreasonable delay. Here's the decision log structure that creates that proof—whether the clock started or not.
Jul 24, 2026
Incident Response
Four Months Late: What the NYDFS Healthplex $2M Penalty Says About When the Notification Clock Actually Starts
NYDFS fined Healthplex $2 million in August 2025 for notifying 4+ months after a breach. The failure wasn't forensics — it was a misunderstanding of when the 72-hour clock starts. The same mistake trips up banks under the FDIC's 36-hour rule.
Jul 23, 2026
Incident Response
Three Clocks, One Incident: How to Manage the Overlapping Cyber Notification Timelines Under OCC, NYDFS, and SEC Rules
When a cyber incident hits, you're not managing one notification obligation — you're managing six, with different triggers, different recipients, and different clocks. The OCC's 36-hour rule, NYDFS's 72-hour requirement, the SEC's 4-business-day materiality window, GLBA customer notices, FinCEN SAR filing, and bank partner contractual obligations all run simultaneously. Here's how to track them without missing one.
Jul 18, 2026