Tools Compliance

Incident Notification Clock

After a breach, who do you owe notice to, and by when?

Pick your industry, the rules you fall under and the states your customers live in. See every regulator, customer and partner notice you would owe, on one timeline that starts the moment you discover an incident.

  • SEC
  • Banks & NCUA
  • HIPAA
  • DFARS / CUI
  • NYDFS
  • State laws
  • 4 minutes

Step 1 · Who you are

Map your notification clocks

Start from the example closest to you, then check every box that applies. Most organizations fall under more than one rule, and the shortest clock sets the pace.

Example

Rules you fall under

Where affected people live

Each state sets its own rules for notifying residents and its attorney general.

The incident

Several rules change at 250, 500 or 1,000 people.
people
Defaults to now. Change it to plan around a past or practice incident.
Which rules are included
Banks OCC, FDIC and Federal Reserve rule: notify your primary regulator within 36 hours of determining a notification incident occurred
Credit unions NCUA: within 72 hours of reasonably believing a reportable cyber incident occurred
Public companies SEC Form 8-K Item 1.05: within 4 business days of determining the incident is material
Healthcare HIPAA: individuals within 60 days of discovery; HHS within 60 days if 500 or more people, otherwise in the annual log; media if more than 500 residents of one state. Business associates notify the covered entity within 60 days, or sooner if the agreement says so.
Defense contractors DFARS 252.204-7012: report to DoD through DIBNet within 72 hours of discovery; preserve images for 90 days
NYDFS Part 500.17: within 72 hours of determining a cybersecurity incident occurred; 24 hours after any extortion payment
Non-bank financial FTC Safeguards Rule: notify the FTC within 30 days of discovery if 500 or more consumers are affected
Broker-dealers & advisers SEC Regulation S-P: notify affected individuals within 30 days of becoming aware
Insurance licensees States that adopted the NAIC Insurance Data Security Model Law: notify the insurance commissioner within 72 hours
EU residents GDPR: notify the lead supervisory authority within 72 hours of becoming aware
States Fixed resident deadlines where a state sets one (30, 45 or 60 days); attorney general notice where the state's threshold is met

Step 2 · Your notification playbook

Have the first 72 hours written down before you need them

Unlock where and how each notice is filed, what each regulator expects in it, and an hour-by-hour escalation plan your team can run on day one.

Where to file

The portal, form or contact for every notice you owe.

What each notice must say

Required content for each regulator and for the people affected.

Hour-by-hour plan

Who does what from hour 0 to day 60.

No cost, no obligation. MALA is vendor-sponsored.

Next step

Shorten the time from discovery to decision.

MALA lines up an incident response retainer, 24x7 detection and cyber insurance that work together, so your team is not choosing vendors while the clock runs. No consulting fee.

An advisor responds within one business day. Call +1 (603) 802-2469.