Incident Response & Breach Notification Kit
Run an incident and every notice clock it starts: bank partner, the bank regulators' 36-hour rule, NYDFS, FTC, SEC and breach laws in 54 states and territories. Workbook, guide, four playbooks, tabletop kit and Word plan templates.
Price
$69
One-time. No subscription. Use forever.
Delivered immediately after checkout — your template and guide links are emailed to you with your receipt.
Built for risk and compliance teams at financial-services organizations
◆ Quick buying summary
What you get and when you can use it
- Good fit if
- You just inherited incident response and need a working process before the next exam or bank partner review
- Format
- Five files: an editable Excel workbook (12 tabs), a 48-page PDF guide, a 44-page PDF of playbooks and a tabletop exercise kit, and two editable Word templates (incident response plan and post-incident review). Instant download after checkout.
- Need the methodology first?
- Read the Incident Response Plan Template Guide.
- Time to value
- Start reviewing, editing, and assigning owners the same day; customize to your organization before sharing outputs externally.
- After purchase
- After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account required.
◆ What's included
- ◆ 12-tab Excel workbook (v2026.10.3): Incident Log, Severity Matrix, Regulatory Clocks, Breach Notification, IR Checklist, IR Team & Contacts, Communication Templates, Federal and State Reference, and a calculated IR Dashboard
- ◆ Regulatory Clocks for 21 federal, regulator and contract obligations, including the bank regulators' 36-hour Computer-Security Incident Notification rule, the bank service provider notice, NYDFS 72-hour and extortion-payment notices, the FTC Safeguards Rule, SEC Form 8-K Item 1.05 and Regulation S-P, HIPAA, bank partner, card brand and cyber insurance terms
- ◆ State Reference for 54 jurisdictions: consumer deadline and when the clock starts, regulator notice thresholds and timing, credit bureau notice, risk-of-harm test, GLBA (Gramm-Leach-Bliley Act) treatment, penalties and a source URL for each row, verified as of 09/30/2026
- ◆ Breach Notification tab: one row per incident and state, with consumer and regulator deadlines calculated from the State Reference
- ◆ Five-factor Severity Matrix (each factor scored 1 to 4) that sets Critical, High, Medium or Low, with tunable thresholds and suggested internal response-time targets
- ◆ IR Checklist: 58 actions in seven phases, from the first hour to lessons learned, plus eight communication templates (internal alert to "Notice of Data Breach" customer letter and regulator, bank partner and media notices)
- ◆ 48-page guide (v2026.10.3) built on NIST SP 800-61 Rev. 3, with a breach notice decision tree and a state quick reference
- ◆ 44-page Playbooks and Tabletop Kit: ransomware; business email compromise and wire or ACH fraud; account takeover; vendor and bank-partner incidents; plus a facilitator guide, scribe sheet, scoring rubric and six scenario cards
- ◆ Editable Word templates: a 14-page incident response plan and a 8-page post-incident review
Use rights: customize for internal business use and use outputs with your auditors, customers, bank partners, and regulators. Do not resell or redistribute the template files.
◆ Preview
See what the template covers.
Regulatory Clocks tab with Harborline Pay sample data: one row per incident and obligation (bank partner, cyber insurance, NYDFS 72-hour, FTC Safeguards, bank service provider, OFAC check), with trigger, deadline, status and whether each notice was filed on time
Breach Notification tab: a credential-stuffing incident affecting California, Texas and New York residents, with consumer and attorney general deadlines calculated from the State Reference and the dates each notice was sent
State Reference tab: consumer notice deadline, regulator notice and timing, credit bureau notice, verification note and source URL for Alabama through Connecticut, each verified 09/30/2026
◆ Where this fits
Where this fits in your risk program
- ◆ Start here if you need a written incident response plan and a record of every notice an incident starts.
- ◆ Pair it with the Data Privacy Compliance Kit for state privacy laws and the GLBA Safeguards Rule program.
- ◆ Pair it with the BCP/DR Kit for recovery planning and continuity testing.
- ◆ Pair it with the TPRM Kit to put incident notice terms in your vendor contracts.
◆ What this isn't
Setting expectations.
- × Not legal advice: a working tool that organizes the facts and deadlines for you and your counsel.
- × Not software: an Excel workbook, two PDFs and two Word templates.
- × Not international: US federal and state law only.
- × Not a forensics or technical response guide; it covers decisions, notices and records.
◆ Regulatory alignment
Built on primary sources
Federal rules and state statutes were checked against primary sources as of September 30, 2026:
- ◆ Computer-Security Incident Notification rule: 12 CFR 53.3–53.4, 225.302–225.303 and 304.23–304.24 (the 36-hour rule and the bank service provider notice)
- ◆ FTC Safeguards Rule: 16 CFR 314.4(j) notice to the FTC and 314.4(h) written incident response plan
- ◆ NYDFS cybersecurity regulation: 23 NYCRR 500.16 and 500.17, as amended November 1, 2023
- ◆ SEC Form 8-K Item 1.05 and Regulation S-P (17 CFR 248.30, as amended in 2024)
- ◆ Interagency Guidance on Response Programs (12 CFR Part 30, Appendix B, Supplement A)
- ◆ HIPAA breach notification (45 CFR 164 Subpart D) and the FTC Health Breach Notification Rule (16 CFR Part 318)
- ◆ OFAC advisory on ransomware payments (September 21, 2021) and NIST SP 800-61 Rev. 3 (April 2025)
- ◆ Breach notification statutes of 50 states, DC, Puerto Rico, Guam and the U.S. Virgin Islands (source URL on each row)
CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act) is listed for information only: its final rule had not been issued as of September 30, 2026, so no reporting clock applies yet.
Last updated: October 2, 2026
◆ Template guide
Incident Response Plan Template Guide
How to build an incident response plan template for a US fintech or small bank: the incident log fields, five-factor severity scoring, a regulatory clock for every notice an incident starts, state breach notification tracking, and the post-incident review.
◆ FAQ
Frequently asked questions.
Does it cover the 36-hour rule and the bank service provider notice?
Yes, both are rows on Regulatory Clocks with the rule text, citation and source on Federal Reference. Under the Computer-Security Incident Notification rule (12 CFR 53, 225 and 304), a bank supervised by the OCC, Federal Reserve or FDIC must notify its primary federal regulator no later than 36 hours after it determines a notification incident occurred. A non-bank fintech doesn't file that notice; its partner bank does. If you provide covered services to a bank, the same rule requires you to notify the bank's designated contact as soon as possible once you determine an incident has materially disrupted those services, or is reasonably likely to, for four or more hours. The playbooks treat every notice to the bank as an input to the bank's own 36-hour assessment.
Which states and territories are covered?
54 jurisdictions: all 50 states, the District of Columbia, Puerto Rico, Guam and the U.S. Virgin Islands. 22 set a fixed consumer deadline (30 days in California, Colorado, Florida, Maine, New York and Washington; 45 days in 11 states; 60 days in Connecticut, Delaware, Louisiana, South Dakota and Texas); the other 32 require notice in the most expedient time possible or without unreasonable delay. Regulator notice rules differ: for example Puerto Rico requires notice to its Department of Consumer Affairs within 10 days, and Maryland requires the attorney general to be notified before residents.
How current is the state data, and how do I verify it?
State statutes and federal rules were checked against primary sources as of September 30, 2026. Each State Reference row has a source URL, a last-verified date and a verification note saying whether it was checked against official statute or attorney general text or a current code mirror. Seven rows (DC, Guam, Illinois, North Dakota, Puerto Rico, Tennessee and the U.S. Virgin Islands) are marked "Verify with counsel" where a point could not be confirmed from primary text. Laws change, so recheck the rows that matter to you at each annual review and before relying on any deadline.
Is it for banks or fintechs?
Both. It is written for non-bank fintechs under FTC jurisdiction, New York-licensed money transmitters and lenders, fintechs that deliver products through a partner bank, and small banks. You mark each obligation Yes or No for your company: a fintech marks the bank regulator 36-hour notice No and tracks its bank partner and bank service provider notices instead; a bank does the reverse. The FTC Safeguards Rule, NYDFS, SEC and HIPAA rows show who each one applies to.
What's editable?
Everything. The incident response plan and post-incident review are Word documents with yellow [BRACKETED PLACEHOLDERS] for your facts, a responsibility matrix, severity levels, an escalation and notification matrix, a ransomware payment policy and sign-off. In the workbook, white cells are inputs and gray cells are formulas; severity thresholds, response-time targets, contacts, contract notice hours and dropdown lists are all yours to change. The guide and playbooks are PDFs.
Do I need Excel 365?
No. The workbook uses only functions available in Excel 2016 and later (no XLOOKUP, LET, FILTER or other dynamic-array functions). Dates are entered as mm/dd/yyyy and times in 24-hour format.
How do the playbooks connect to the workbook?
They use the same names. Severity labels come from the Severity Matrix, the rows in each playbook's regulatory clock box are the exact dropdown values on Regulatory Clocks, templates are numbered as on Communication Templates, and roles match IR Team & Contacts. Each playbook ends with how to log the incident in the workbook. The tabletop scenarios are built on the workbook's sample company, Harborline Pay, and are run with the workbook open on a shared screen.
Can I send the notice templates as written?
No. The customer "Notice of Data Breach" letter and the regulator, bank partner, vendor and media templates are starting drafts with blanks for the facts of your incident. Some states prescribe content or headings (California, for example), and counsel should approve every external notice before it goes out.
Can I share completed outputs externally?
Yes. You can use completed outputs with auditors, customers, bank partners, regulators, and internal stakeholders. Customize the template for internal business use — just don't resell or redistribute the source template files.
How do I receive the files?
Checkout is handled through Stripe. After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account is required.
What if it's not a fit?
Email within 30 days for a full refund, no questions asked. The guarantee is meant to remove purchase risk while you evaluate whether the template fits your use case.
● First-time buyer offer
Get 20% off your first template.
Drop your email and we'll send the code.
◆ Not ready to buy?
Start with the free Risk Register.
141 pre-populated fintech risks across 21 categories. ISO 31000 structure.
Download free Risk Register →◆ Related templates
Pairs well with.
Data Privacy Compliance Kit
Which of the 23 state privacy laws apply to your fintech after GLBA, plus the GLBA checklist, request tracker, assessments and vendor terms to comply.
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Ready when you are
Get the Incident Response & Breach Notification Kit.
Start building a defensible risk program today.