River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Security Incident Response Plan Template

Six documents and five sheets, including a register that turns one discovery timestamp into every notification deadline you owe, sorted by expiry.

Free download  ·  No account needed

Notification Deadline register · one row

One obligation, its own starting gun, and the hours you actually have

Discovery, recorded once12:40  ·  Friday 4 December 2026

Every row in the register derives from that one field. Move it and all of them move.

Trigger eventDiscovery. Not awareness, not a materiality determination, and not the date somebody signed the contract.
Clock unitCalendar hours, which are elapsed time, so the weekend counts. Calendar days and business days do not behave like this.
Duration72
DeadlineMonday 7 December, 12:40. The same time of day the window opened.
OwnerA named person, confirmed reachable at the hour the deadline falls.

Working hours actually inside the window

Nine of seventy-two. Sixty-three hours fell outside Monday to Friday, 09:00 to 18:00. The same window opened on a Tuesday holds twenty-seven, and that is the number deciding whether a weekend gets staffed.

Sorted by expiry, never by severity

At Stannary the first two deadlines were contractual notice clauses expiring Saturday lunchtime and Sunday morning, both ahead of every regulation in the file.

The securities disclosure has no deadline on day zero, because its trigger is a materiality determination nobody has made yet. What goes in the row instead is the internal deadline for making that call, and the name of whoever makes it.

A breach starts several clocks at once, and they are not variations on one deadline. A HIPAA covered entity has 60 calendar days after discovery. An SEC registrant has four business days after it determines the incident is material. A contractual notice clause is usually measured in calendar hours. Three units, four different trigger events, and an expiry order with no relationship to how serious each obligation is. Every plan on the first page of this search writes that as one bullet reading notify as required by law.

Stannary Health confirmed exfiltration at 12:40 on a Friday. The 72-hour window that opened then contained nine working hours, counting Monday to Friday, 09:00 to 18:00. The identical window from a Tuesday discovery contains twenty-seven. Same regulation, same company, three times the capacity, decided by the day of the week. Neither figure appears in any statute, both are computable in seconds from a timestamp you already have, and only one of them tells you whether to staff a weekend before it starts.

The first two deadlines in the whole file were contractual, not regulatory. Twenty-seven of forty-one master agreements carried a 24-hour notice clause, and the tightest processor obligation fell at 00:40 on a Sunday morning. Every one of those clauses is a sentence somebody signed years earlier under time pressure, which is why extracting them belongs to the policy set long before it matters here. This register only derives the dates and sorts them.

One timestamp, seven obligations, and a weekend nobody had modelled

Every deadline below derives from a single discovery timestamp entered once. Nothing was typed in by hand.

Notification Deadline by Obligation

Stannary Health, a scheduling vendor to 41 US clinics and 6 EU clinics, with a listed parent. Discovery Friday 4 December 2026, 12:40.

InstrumentTriggerUnitQtyDeadlineWorking hrs inside
BAA notice clause, 27 of 41 customersDiscoveryCalendar hours24Sat 5 Dec 12:405.3
EU processor DPA, Havenbrook ClinicsDiscoveryCalendar hours36Sun 6 Dec 00:405.3
GDPR Art 33, own EU controller recordsAwarenessCalendar hours72Mon 7 Dec 12:409.0
SEC Form 8-K Item 1.05, listed parentMateriality determinationBusiness days4Fri 11 Decnot keyed on discovery
HIPAA 164.410(b), notify the covered entitiesDiscoveryCalendar days60Tue 2 Feb 2027plenty
HIPAA 164.404(b), covered entity to individualsTheir discoveryCalendar days60Tue 2 Feb 2027plenty
HIPAA 164.408(b), Secretary, 500 or moreDiscoveryCalendar days60Tue 2 Feb 2027plenty

Sorted by expiry, the first two rows are contracts and the third is a regulation. The room had assumed the 72-hour clock was the tightest thing they had. Rows five and six landing on the same date is the finding that changed the plan: the outer regulatory limit gives the vendor sixty days and gives its customer none.

Data and Obligation Map

Filled in before an incident. This is the only sheet in the pack that has to exist in advance, and everything else derives from it.

Data setWhoseRecordsOur roleInstrumentTriggerUnitQty
Patient appointment records41 clinics141,200Business associateBAA notice clauseDiscoveryCal. hours24
Patient appointment records41 clinics141,200Business associateHIPAA 164.410(b)DiscoveryCal. days60
Patient intake forms41 clinics19,100Business associateHIPAA 164.410(b)DiscoveryCal. days60
EU clinic appointment records6 EU clinics9,260ProcessorProcessor DPA clauseDiscoveryCal. hours36
Stannary EU staff and enquiriesOurs2,940ControllerGDPR Art 33AwarenessCal. hours72
Any material incidentn/a0Registrant subsidiarySEC Item 1.05DeterminationBus. days4
Payment card datan/a0Out of scopeTokenised, never storednonenone0

The same data set appears twice when two instruments attach to it, because they have different triggers and different units. The out-of-scope row earns its place: without it, somebody asks the question during the incident and nobody is sure.

Affected Population

Scope expressed in records and organisations, because that is the unit every obligation is written in. Servers are not.

SegmentOrganisationsRecordsTightest obligation
US customers with a 24h BAA clause27118,40024 calendar hours
US customers with no notice clause1441,90060 calendar days
EU clinics under a processor DPA69,26036 calendar hours
Stannary EU records, controller2,94072 calendar hours
Total47172,500

Split by organisation because notice clauses attach per agreement, and a total of 172,500 tells nobody which of 41 customers to call first. All 27 contractual notices went out fourteen hours inside the clause. The Article 33 filing used seven of the nine available working hours.

What is in the pack

01

Data and Obligation Map

The only sheet you fill in before an incident: every data set, whose it is, your role, and each instrument that attaches with its trigger and clock unit.

02

Notification Deadline by Obligation

Derived from one timestamp. Instrument, trigger, unit, duration, wall-clock deadline, working hours inside the window, and a named owner.

03

Affected Population

Scope in records and organisations rather than systems, split so the notification work plan falls out of it directly.

04

Contact and Escalation Register

Who holds each role, their out of hours route, their backup, and how fast they are actually reachable, with a last-verified date.

05

Tabletop Exercise Log

One row per exercise carrying the number that matters: minutes from declaration to somebody naming the first deadline and its owner.

06

How the Clocks Work

Three units, four trigger events, and the agency question that decides whether your customer's clock started when you discovered or when you told them.

07

Response Plan by Scenario

Five scenarios, each with the same five headings, ending in the specific mistake that scenario invites rather than a generic checklist.

08

Notification Templates

Four audiences, four shapes, each short enough to send inside the clock, and each carrying your discovery timestamp so the recipient can compute their own.

09

Legal and Regulatory Note

The four questions counsel has to answer, written to be settled on a quiet Tuesday and recorded as dated decisions rather than asked at 22:00 on a Sunday.

How it works

  1. 1

    Open it in River, or download it

    Edit with AI opens the pack as a private Space with the agent ready to build your obligation map. Download hands you six Word documents and five CSV sheets, no account required.

  2. 2

    Send the contracts, not just the data inventory

    Where data lives and whose it is, plus executed customer agreements with their notice clauses, any processing agreements, and whether a listed parent or an insurance condition is in scope.

  3. 3

    Get the map before the incident

    One row per data set per instrument, with the trigger event and the clock unit recorded separately. This is the only part that has to exist in advance, and it is the part everybody defers.

  4. 4

    Enter one timestamp during

    The register computes every deadline, sorts by expiry, and reports the working hours actually inside each window. Four minutes at declaration, before triage rather than after.

Frequently asked questions

Is this template free?

Yes, and the download needs no account, card or email. Edit with AI is the optional half and the one that builds the map: it reads your agreements, extracts the notice clauses, and derives every deadline. The rest of the template library works the same way.

What format are the downloaded files?

Six documents as .docx and five sheets as .csv, in one zip. Word, Pages, Google Docs, Excel, Numbers and Sheets open them with nothing to convert. The sheets arrive carrying the worked Stannary example, so you can read a filled register before replacing it.

Why compute deadlines before triage rather than after scope is known?

Because it takes four minutes and it is the only calm moment you get. The register tells you whether your first deadline falls at Saturday lunchtime, which changes who you wake in the next ten minutes. Scope changes the population, not the expiry times.

Is 72 hours the same as three working days?

No, and the difference is the point. The EDPB restates Article 33 as notification not later than 72 hours after having become aware, which is elapsed time. From a Friday lunchtime discovery that window holds nine working hours.

We are a vendor, not a covered entity. Do these clocks apply to us?

Some of them, and one is easy to misread. A business associate has 60 calendar days to notify the covered entity, but the customer is deemed to discover when their agent does. Where agency applies, using your sixty days leaves them none.

How is this different from an incident communication plan?

Different audience and a different clock. This pack owns the obligations you owe to regulators, customers and individuals under an instrument. Telling everyone else what is happening while it happens is the incident communication pack, which runs on a promised cadence rather than a statute.

Where does the plan connect to the rest of our security work?

Three places. The scope question is answered by the access register, the recovery objectives by the continuity plan, and what a subprocessor actually holds on your behalf by the vendor SOC 2 review. This pack owns the clocks and nothing else.

Put the deadlines on a sheet before you need them

Edit with AI