Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Incident Response

When One Cyber Incident Triggers Four Notification Clocks: Sequencing FFIEC, CIRCIA, SEC, and State Breach Law Obligations

A single cyber incident at a bank or fintech can simultaneously trigger the FFIEC 36-hour rule, CIRCIA's 72-hour CISA notification, the SEC's 4-business-day Form 8-K requirement, and state breach notification deadlines — each starting from a different legal trigger. Here's how to sequence them without missing one.

Table of Contents

It’s Monday morning. Your security team detects unusual network traffic at 7:02 a.m. By 8:30 a.m., you’ve confirmed ransomware has encrypted three core banking systems. The CEO is in the room. The general counsel is on the phone.

Someone asks: “What do we have to report, and when?”

The answer is: four different things, to four different recipients, with four different deadlines that started running at four different times based on four different legal standards.

Most financial institution incident response plans have a “regulatory notification” section. Most of them were written before this regulatory complexity existed. If yours doesn’t specifically address the sequencing problem — FFIEC versus CIRCIA versus SEC versus state breach laws — it has a gap that will cost you under pressure.

TL;DR

  • A single cyber incident at a bank or fintech can simultaneously trigger four separate notification obligations: the FFIEC 36-hour rule (to banking regulators), CIRCIA (to CISA within 72 hours), the SEC Form 8-K Item 1.05 requirement (within 4 business days of materiality determination), and state breach notification laws (30–72 hours depending on state and affected residents)
  • Each obligation starts from a different legal trigger: CIRCIA uses “reasonably believes” (earlier, lower bar); FFIEC and SEC use “determines” (later, higher standard)
  • CISA and banking regulators have not finalized harmonization rules — you cannot assume FFIEC notification satisfies CIRCIA
  • Your IR playbook needs a decision tree that explicitly maps which regulator gets notified first, by whom, with what information, and how the clocks interact

The Four Clocks and When They Start

FrameworkWho NotifiesNotify WhomTrigger StandardTimeline
FFIEC 36-Hour RuleBanking org + bank service providersPrimary federal banking regulator (OCC, FDIC, or Fed)“Determines” a notification incident occurred36 hours from determination
CIRCIAAny covered entity (includes financial institutions)CISA”Reasonably believes” a covered cyber incident occurred72 hours from reasonable belief
SEC Form 8-K Item 1.05SEC registrants (public companies)SEC (public filing)“Determines” the incident is material4 business days from materiality determination
State breach notification lawsAny entity holding affected state residents’ dataState AG + affected residents”Discovers” or becomes aware of a breach30–72 hours depending on state (NY: 72 hrs to AG; Maine: 7 days; CA: “expedient time”)

Three of the four frameworks require “determining” or “discovering” something. CIRCIA alone uses a “reasonable belief” standard — deliberately set lower so that early reporting allows CISA to coordinate sector-wide response before the full scope of an incident is known.

The practical consequence: your CIRCIA clock starts before your internal assessment is done.

By the time your IR team has isolated the affected systems, confirmed the attack vector, and assessed whether you’ve crossed the FFIEC “notification incident” threshold, you may have already used 12-18 hours of your 72-hour CIRCIA window.

The Triggering Standards Problem

The difference between “reasonably believes” and “determines” is not semantic. It represents a meaningfully different point in your incident timeline.

At hour 8 of a ransomware incident, you almost certainly “reasonably believe” you have a covered cyber incident. Ransomware is ransomware. It has substantially affected the availability of your systems. CIRCIA clock is running.

At hour 8, you may not have “determined” whether this is a “notification incident” under the FFIEC rule. You’re still assessing how many systems are affected, whether customer-facing services are degraded, whether banking operations are materially disrupted. The FFIEC determination might come at hour 18 or hour 30 — after your incident commander and general counsel have reviewed the scope.

At hour 8, you definitely have not “determined” materiality for SEC purposes. That assessment requires evaluating financial impact, customer harm, operational duration, and regulatory consequences — a multi-day process for complex incidents.

And state breach notification clocks start when you “discover” that personal information was accessed without authorization — which might be hour 2 (if logs show exfiltration) or hour 72 (if forensics is needed to determine whether data was accessed).

The same incident, four different starting points.

Your IR playbook needs to address all four starting points explicitly. Most don’t.

For more on the FFIEC rule specifically, the FFIEC 36-Hour Computer Security Incident Notification Rule covers what constitutes a notification incident, what the notification must contain, and what examiners test during exam review.

CIRCIA’s Harmonization Provision — What It Does and Doesn’t Do

Section 2242(k) of CIRCIA directs CISA to work with sector risk management agencies to harmonize cyber incident reporting requirements and create exemptions where covered entities are already satisfying substantially similar obligations through sector-specific regulators.

For banking, the sector risk management agency is the prudential regulators — OCC, FDIC, and Federal Reserve. In theory, this provision could allow banks that notify their primary federal banking regulator to satisfy their CIRCIA obligation without a separate CISA filing.

In practice, CISA has not finalized those harmonization rules. As of mid-2026, there is no formal exemption in place that allows FFIEC notification to substitute for CISA notification under CIRCIA. The interagency agreements and reporting-to-CISA exemptions authorized by the statute are still being developed.

Until CISA publishes final harmonization guidance:

  • File your FFIEC notification with your primary banking regulator within 36 hours of determination
  • File your CIRCIA report with CISA within 72 hours of reasonable belief — separately, even if you’ve already notified your banking regulator
  • Do not assume one substitutes for the other

The CIRCIA 72-Hour Reporting Guide for Financial Institutions covers the technical specifics of what CISA’s reporting portal requires and how to file a preliminary versus substantive report.

The SEC Form 8-K Layer

The SEC’s cyber disclosure rule (effective December 2023) adds a fourth clock that operates on a different axis entirely. This one isn’t about operational notification to regulators — it’s about public disclosure to investors.

Under Item 1.05, SEC registrants must file a Form 8-K describing any material cybersecurity incident within four business days of determining materiality. The materiality determination is what starts the clock — not discovery, not initial determination that an incident occurred, but the completed assessment that the incident meets the “material” threshold under the securities law standard.

For banks that are also SEC registrants, this creates a layered obligation: FFIEC notification (operational, to banking regulators) and SEC Form 8-K (public, to investors). These serve different purposes and cannot substitute for each other.

The SEC’s materiality standard for cybersecurity incidents borrows from general securities law: information is material if there is a substantial likelihood that a reasonable investor would consider it important. In practice, this means:

  • Not every incident requires an 8-K
  • The materiality assessment must be documented, not just decided
  • The 4-day clock runs from documented determination, not from initial discovery
  • Delay of filing is only permitted under limited national security circumstances

For a detailed look at the triggering analysis, the SEC Cyber Disclosure Rule: 8-K Item 1.05 Materiality covers the specific factors SEC staff have indicated they evaluate.

State Breach Notification: The 50th Complexity

State breach notification laws add a 50-state variable to a problem that’s already complex. All 50 states have breach notification laws. They share some common elements (they all require notification of affected residents and most require AG notification) but differ dramatically on:

  • Timeline: From Maine’s extended window to New York’s 72-hour AG notification requirement under the SHIELD Act to various states’ “most expedient time” standards
  • Trigger: Some states trigger on unauthorized “access,” others require proof of “acquisition”
  • Covered information: State definitions of what personal information triggers notification vary
  • Small-breach exceptions: Some states have thresholds (a breach affecting fewer than X residents may trigger different requirements)

The 50-State Breach Notification Law Comparison breaks down the specific trigger and timeline requirements that matter most for financial institutions, including the states with the shortest deadlines.

For the sequencing problem: state breach notification obligations often run in parallel to your federal regulatory notifications. A ransomware attack that affects customer records in New York, California, and Texas simultaneously triggers three separate state notification frameworks — each with different timelines and content requirements — in addition to your FFIEC and CIRCIA obligations.

Building Your Multi-Regulator Notification Decision Tree

Your IR playbook needs a decision tree that maps the notification sequence explicitly. Here’s the framework most playbooks are missing:

Hour 0 — Incident Detected

  • Who holds the decision on whether to activate the notification sequence?
  • What evidence threshold triggers the CIRCIA “reasonable belief” assessment?
  • Who has authority to make that assessment?

Hour 2-6 — Initial Assessment

  • Document your assessment of whether you “reasonably believe” this is a covered cyber incident under CIRCIA. If yes: CIRCIA clock is running.
  • Assign the CISA notification owner. This person’s job in the next 66 hours is to file or prepare to file with CISA, regardless of what else is happening in the incident.
  • Begin parallel tracks: (a) incident containment, (b) regulatory notification preparation.

Hour 12-24 — FFIEC Assessment

  • Has the incident caused or is it “reasonably likely to cause” material disruption to banking operations? If yes: FFIEC clock starts. You have 36 hours from this determination.
  • Notify your primary federal banking regulator (OCC, FDIC, or Federal Reserve) as soon as possible. The 36-hour deadline is a ceiling, not a target.
  • Document what you notified, when, to whom, and via what channel.

Hour 24-72 — CISA Notification

  • File with CISA at CISA’s Cyber Incident Reporting Portal by hour 72 from reasonable belief.
  • A preliminary report is acceptable if full details are not available. CIRCIA requires follow-up supplemental reports as more information becomes available.
  • Note: If ransom is paid, a separate 24-hour notification to CISA is required.

Ongoing — Materiality Assessment (for SEC registrants)

  • Begin parallel materiality assessment process.
  • Assign general counsel and CFO to lead the materiality determination.
  • Set a deadline: materiality determination must be completed within 3 business days to avoid 8-K deadline risk.
  • If material: file Form 8-K within 4 business days of determination.

Day 2-30 — State Breach Notification

  • Once forensics confirms whether personal information was accessed, determine which states’ residents are affected.
  • Apply each state’s trigger and timeline. Prioritize states with shortest deadlines (NY 72-hour AG notification).
  • Coordinate consumer notice language with legal counsel.

For your incident triage methodology, the Incident Triage Techniques: Severity Classification, Materiality, and the SEC 4-Day Clock covers the scoring rubrics and escalation criteria that feed into this decision framework.

So What? Three Immediate Fixes for Your IR Playbook

1. Add an explicit notification sequencing section. Your playbook probably has a “regulatory notification” step. That step should be broken into four named obligations with explicit timelines, trigger standards, responsible owners, and escalation paths. “Notify regulators” is not a plan.

2. Assign dedicated owners for each notification stream. In a major incident, the IR team is consumed by containment. Regulatory notification has to have a separate owner who is not pulled off notification duties to help with technical response. The CISA notification owner, the banking regulator notification owner, and the SEC materiality assessment team all need to be pre-designated.

3. Build a template for each notification type. CIRCIA, FFIEC, SEC Form 8-K, and state breach notices all have different required elements. Pre-drafting templates with placeholders — incident description, affected systems, initial scope assessment, contact information — saves critical hours when clocks are running.

The Incident Response & Breach Notification Kit includes notification playbooks, regulatory notification templates, and a state-by-state breach law compliance tracker for financial institutions.


External Resources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Do the FFIEC 36-hour rule and CIRCIA 72-hour reporting requirement both apply to banks?
Yes. Banks and their bank service providers are subject to the FFIEC 36-hour notification rule (final rule issued November 2021, effective April 2022), which requires notification to the primary federal banking regulator (OCC, FDIC, or Federal Reserve). Financial institutions are also covered entities under CIRCIA, subject to the 72-hour CISA notification requirement for covered cyber incidents. These are separate requirements with different triggers, different recipients, and different scopes — and they are not yet fully harmonized.
What is the difference between when the FFIEC and CIRCIA notification clocks start running?
The FFIEC 36-hour clock starts when the banking organization 'determines' that a notification incident has occurred — a determination standard. CIRCIA's 72-hour clock starts when the covered entity 'reasonably believes' a covered cyber incident has occurred — a lower-bar, earlier standard. In practice, your CIRCIA clock may start running several hours or even a full day before you've completed the internal assessment needed to make a formal FFIEC determination. This means you may need to file a preliminary CISA report before your internal incident classification is complete.
If I notify my primary banking regulator under the FFIEC rule, does that satisfy my CIRCIA obligation to notify CISA?
Not automatically. CIRCIA includes a harmonization provision (Section 2242(k)) that allows CISA to establish reporting exemptions for covered entities that are already reporting substantially similar information to their sector risk management agency — which for banking is the prudential regulators. However, CISA has not yet published final harmonization guidance that formally designates FFIEC notification as an exemption pathway. Until that guidance is finalized, the conservative compliance position is to file both: notify your primary federal banking regulator within 36 hours and file separately with CISA within 72 hours.
What triggers the SEC Form 8-K cyber incident disclosure under Item 1.05?
The SEC's final rule (effective December 2023) requires registrants to file a Form 8-K under Item 1.05 within four business days of 'determining' that a material cybersecurity incident has occurred. The 'materiality' determination is what starts the clock — not detection of the incident. This is a separate assessment from the FFIEC and CIRCIA triggers, and the timeline can be substantially longer. An incident may be serious enough to trigger FFIEC and CIRCIA reporting immediately but not be 'material' for SEC purposes for several more days, depending on the scope and impact assessment.
What happens if I notify CISA or my banking regulator late?
Under the FFIEC rule, failure to provide timely notification is an unsafe and unsound banking practice and can result in supervisory action, including examination findings, MRAs, and enforcement actions. CIRCIA's civil penalty authority for non-reporting covered entities is still being established in implementing regulations, but the statute authorizes civil money penalties for violation of the reporting requirements. For the SEC Form 8-K, failure to file timely is a securities law violation subject to SEC enforcement, fines, and potential 10-K disclosure obligations about the violation itself.
What is a 'notification incident' under the FFIEC rule vs. a 'covered cyber incident' under CIRCIA?
The FFIEC rule defines a 'notification incident' as a computer security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the banking organization's ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base. CIRCIA defines a 'covered cyber incident' more broadly to include substantial loss of confidentiality, integrity, or availability of an information system; disruption of business operations; unauthorized access; or serious impacts on safety. CIRCIA's scope is generally broader, meaning more incidents trigger CIRCIA reporting than FFIEC reporting.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.