◆ Quick answer
An incident response plan template should include an incident log (detected and determined times, systems, data, people and states affected, owner, contained and closed dates, root cause, lessons learned), a severity matrix, a regulatory clock tracker with one row per incident and obligation (bank partner, bank service provider notice, NYDFS, FTC, SEC, insurance), a state-by-state breach notification tracker, a phase-by-phase checklist, contacts and notice templates, and a post-incident review.
Guide vs. template
This guide explains what belongs in the template. The paid template gives you the editable working files so you're not rebuilding from a blank page.
Paid template includes
- ◆ 12-tab Excel workbook (v2026.10.3): Incident Log, Severity Matrix, Regulatory Clocks, Breach Notification, IR Checklist, IR Team & Contacts, Communication Templates, Federal and State Reference, and a calculated IR Dashboard
- ◆ Regulatory Clocks for 21 federal, regulator and contract obligations, including the bank regulators' 36-hour Computer-Security Incident Notification rule, the bank service provider notice, NYDFS 72-hour and extortion-payment notices, the FTC Safeguards Rule, SEC Form 8-K Item 1.05 and Regulation S-P, HIPAA, bank partner, card brand and cyber insurance terms
- ◆ State Reference for 54 jurisdictions: consumer deadline and when the clock starts, regulator notice thresholds and timing, credit bureau notice, risk-of-harm test, GLBA (Gramm-Leach-Bliley Act) treatment, penalties and a source URL for each row, verified as of 09/30/2026
- ◆ Breach Notification tab: one row per incident and state, with consumer and regulator deadlines calculated from the State Reference
What is this template for?
An incident response plan template has two halves. The written plan sets policy and decision rights: who declares an incident, how severity is set, who can approve a customer notice or a ransom decision. The working record is what the team fills in during the incident: an incident log with the times that start each clock, a severity score, one row for every notice obligation that might apply with its deadline, one row per state for breach notices, and the post-incident review. Most plans fail not in the technical response but in the hours when nobody is sure which notices are due, to whom, and by when, so the record matters as much as the policy.
◆ Audience
Who needs this.
- ◆ You just inherited incident response and need a defensible process before the next exam or bank partner review.
- ◆ Your fintech provides services to a partner bank and you need to know what the bank needs from you, and how fast, for its own 36-hour assessment.
- ◆ You have customers in many states and could not look up each breach law in the middle of an incident.
- ◆ You are licensed in New York and need the NYDFS 72-hour notice tracked from the moment of determination.
- ◆ Past incidents were handled from memory and chat threads, with no consistent log, severity or record of when each notice went out.
◆ Required fields
What every row needs.
The fields that make this template defensible to an auditor, bank partner, or examiner — and what goes in each.
| Field | Why it matters | Example |
|---|---|---|
| Incident ID, detected time and determined-to-be-an-incident time | Several clocks run from determination, not detection, and reviewers compare the two. Record who made the call. | IR-2026-002: detected 06/02/2026 08:40; determined 06/02/2026 10:30 |
| Incident type | Routes the right playbook and makes trend reporting possible. | Account takeover / credential stuffing; Business email compromise / payment fraud; Vendor / third-party incident; Ransomware / extortion |
| Data involved, personal info flag and people affected | Decides whether state breach laws and the FTC Safeguards Rule notice (500 or more consumers) come into play. | Login credentials; personal info Yes; 1,240 people |
| States affected and personal-info breach determined date | State clocks run from the date a breach of personal information is discovered or determined, which can be days after the incident was declared. | California, Texas, New York; breach determined 06/09/2026 |
| Bank partner or service provider impact | A fintech providing covered services to a bank must notify it as soon as possible when those services are, or are reasonably likely to be, materially disrupted for four or more hours. | Yes: core processor outage halted card and ACH (automated clearing house) services for about 30 hours |
| Five severity factor scores, final severity and any override reason | A scored severity is consistent and explainable; an override needs a written reason. | Scores 2, 1, 1, 1, 2 (Low), overridden to Medium: attempted $186,400 wire to a new payee |
| Owner (Incident Commander) | One named person runs the response and the decisions log. | M. Okafor (Security) |
| Contained and closed times | Time to detect, contain and resolve are the metrics boards and bank partners ask for, and they only exist if the times are logged. | Contained 06/03/2026 18:00; closed 07/31/2026 17:00 |
| Root cause, lessons learned and linked issue ID | Ties the fix to your issues tracker so it is followed to completion. | Credential compromise; add bot mitigation and step-up multi-factor authentication for new devices; ISS-2026-031 |
◆ Worked example
Example incident: Harborline Pay credential stuffing (sample data, fictional company)
| Incident Log | IR-2026-002, account takeover / credential stuffing. Detected 06/02/2026 08:40, determined to be an incident 10:30, contained 06/03 18:00. 1,240 customer accounts accessed; names, account numbers and transaction history viewed. Residents of California, Texas and New York. |
|---|---|
| Severity | Scores of 3, 4, 1, 3, 3 on the five factors (data sensitivity, people affected, operational impact, regulatory exposure, bank partner impact): total 14. One factor at 4 sets the floor at High; the Critical threshold is 15. |
| Clocks and notices | Bank partner notice within the 24 hours in the program agreement, cyber insurer within 72 hours, NYDFS within 72 hours and the FTC within 30 days (500 or more consumers). State notices from the 06/09 breach determination: California and New York residents within 30 days, Texas within 60. Regulator notices go to the attorney general in all three states, plus New York's Department of State and State Police. SEC Form 8-K marked No: private company. |
◆ Implementation roadmap
How to roll this out.
Load contacts, retainers and contract notice terms before you need them
Owner · Compliance or security lead
Output · IR Team & Contacts with named primary and backup contacts, the bank partner incident contact, breach counsel, forensics firm and insurer, and the notice hours in each program agreement and policy
Set the severity rule
Owner · Incident response lead with risk and compliance
Output · Severity Matrix: five factors scored 1 to 4, thresholds for Critical, High and Medium, and internal response-time targets the plan repeats
Run a regulatory clock check in the first 24 hours of every High or Critical incident
Owner · Chief Compliance Officer with counsel
Output · A Regulatory Clocks row for every obligation that might apply, marked Yes or No with a reason, and a deadline calculated from the trigger time
Work state breach notices from the breach determination
Owner · Privacy officer with breach counsel
Output · One Breach Notification row per state with consumer and regulator deadlines, in the order some states require (Maryland, for example, wants the attorney general notified before residents)
Close with a post-incident review and test the plan
Owner · Incident Commander
Output · A post-incident review for every Critical and High incident with actions linked to issue IDs, and a tabletop exercise at least once a year
◆ Ready to use it?
Download the Incident Response & Breach Notification Kit.
Use the guide to understand the structure, or buy the editable template to move faster.
◆ FAQ
Frequently asked questions.
What should an incident response plan template include? ⌄
A written plan (scope, authority, roles, severity levels, escalation and notification, evidence handling, communications, third-party incidents, ransomware payment decisions, review and testing) and a working record: an incident log, a severity matrix, a tracker for every notice obligation, a state breach notice tracker, a checklist, contacts, notice templates and a post-incident review. The FTC Safeguards Rule (16 CFR 314.4(h)) and the NYDFS cybersecurity regulation (23 NYCRR 500.16) both require a written incident response plan from the institutions they cover.
What is the difference between an incident and a breach? ⌄
Every breach is an incident, but not every incident is a breach. A phishing email stopped before anyone acted is an incident with no notice obligation. State breach laws generally turn on unauthorized acquisition of, or in some states access to, unencrypted personal information as each statute defines it, and their clocks run from when the breach is discovered or determined. Log both dates, because they are often days apart.
How fast do I have to notify after a breach? ⌄
It depends on the law. Of 54 state and territory laws, 22 set a fixed consumer deadline: 30 days in California, Colorado, Florida, Maine, New York and Washington, 45 days in 11 states, and 60 days in Connecticut, Delaware, Louisiana, South Dakota and Texas. The rest require notice in the most expedient time possible or without unreasonable delay. Regulator notices have their own thresholds and timing. Federal and regulator clocks run separately: NYDFS within 72 hours of determining a cybersecurity incident, the FTC within 30 days for 500 or more consumers, SEC Form 8-K within four business days of a materiality determination. Verify with counsel before relying on any deadline.
Does the 36-hour rule apply to fintechs? ⌄
Not directly. The Computer-Security Incident Notification rule (12 CFR 53, 225 and 304) requires banks supervised by the OCC, Federal Reserve or FDIC to notify their primary federal regulator no later than 36 hours after determining a notification incident occurred. A fintech that provides covered services to a bank has a different duty under the same rule: notify the bank-designated contact as soon as possible once it determines an incident has materially disrupted or degraded those services, or is reasonably likely to, for four or more hours. Your program agreement usually adds its own notice deadline.
Do vendor incidents go in my incident log? ⌄
Yes. If a vendor that holds your data or runs your services has an incident, open your own record; do not wait for the vendor's conclusions. Your clocks can start even when none of your systems was touched: the NYDFS notice covers incidents at third-party service providers, and an outage at your processor can trigger your bank service provider notice.
How do I test an incident response plan? ⌄
Run a tabletop exercise: a facilitator walks the response team through a realistic scenario one inject at a time, and a scribe records decisions, times and gaps. 60 to 90 minutes is enough. NYDFS requires covered entities to test the plan at least annually (23 NYCRR 500.16(d)); the FTC Safeguards Rule does not prescribe tabletops, but bank partners commonly ask for evidence of testing. Track every gap as an action with an owner and a due date.