Security Incident Response Plan Template
Six documents and five sheets, including a register that turns one discovery timestamp into every notification deadline you owe, sorted by expiry.
Free download · No account needed
Notification Deadline register · one row
One obligation, its own starting gun, and the hours you actually have
Discovery, recorded once12:40 · Friday 4 December 2026
Every row in the register derives from that one field. Move it and all of them move.
Working hours actually inside the window
Nine of seventy-two. Sixty-three hours fell outside Monday to Friday, 09:00 to 18:00. The same window opened on a Tuesday holds twenty-seven, and that is the number deciding whether a weekend gets staffed.
Sorted by expiry, never by severity
At Stannary the first two deadlines were contractual notice clauses expiring Saturday lunchtime and Sunday morning, both ahead of every regulation in the file.
The securities disclosure has no deadline on day zero, because its trigger is a materiality determination nobody has made yet. What goes in the row instead is the internal deadline for making that call, and the name of whoever makes it.
A breach starts several clocks at once, and they are not variations on one deadline. A HIPAA covered entity has 60 calendar days after discovery. An SEC registrant has four business days after it determines the incident is material. A contractual notice clause is usually measured in calendar hours. Three units, four different trigger events, and an expiry order with no relationship to how serious each obligation is. Every plan on the first page of this search writes that as one bullet reading notify as required by law.
Stannary Health confirmed exfiltration at 12:40 on a Friday. The 72-hour window that opened then contained nine working hours, counting Monday to Friday, 09:00 to 18:00. The identical window from a Tuesday discovery contains twenty-seven. Same regulation, same company, three times the capacity, decided by the day of the week. Neither figure appears in any statute, both are computable in seconds from a timestamp you already have, and only one of them tells you whether to staff a weekend before it starts.
The first two deadlines in the whole file were contractual, not regulatory. Twenty-seven of forty-one master agreements carried a 24-hour notice clause, and the tightest processor obligation fell at 00:40 on a Sunday morning. Every one of those clauses is a sentence somebody signed years earlier under time pressure, which is why extracting them belongs to the policy set long before it matters here. This register only derives the dates and sorts them.
What is in the pack
Data and Obligation Map
The only sheet you fill in before an incident: every data set, whose it is, your role, and each instrument that attaches with its trigger and clock unit.
Notification Deadline by Obligation
Derived from one timestamp. Instrument, trigger, unit, duration, wall-clock deadline, working hours inside the window, and a named owner.
Affected Population
Scope in records and organisations rather than systems, split so the notification work plan falls out of it directly.
Contact and Escalation Register
Who holds each role, their out of hours route, their backup, and how fast they are actually reachable, with a last-verified date.
Tabletop Exercise Log
One row per exercise carrying the number that matters: minutes from declaration to somebody naming the first deadline and its owner.
How the Clocks Work
Three units, four trigger events, and the agency question that decides whether your customer's clock started when you discovered or when you told them.
Response Plan by Scenario
Five scenarios, each with the same five headings, ending in the specific mistake that scenario invites rather than a generic checklist.
Notification Templates
Four audiences, four shapes, each short enough to send inside the clock, and each carrying your discovery timestamp so the recipient can compute their own.
Legal and Regulatory Note
The four questions counsel has to answer, written to be settled on a quiet Tuesday and recorded as dated decisions rather than asked at 22:00 on a Sunday.
How it works
- 1
Open it in River, or download it
Edit with AI opens the pack as a private Space with the agent ready to build your obligation map. Download hands you six Word documents and five CSV sheets, no account required.
- 2
Send the contracts, not just the data inventory
Where data lives and whose it is, plus executed customer agreements with their notice clauses, any processing agreements, and whether a listed parent or an insurance condition is in scope.
- 3
Get the map before the incident
One row per data set per instrument, with the trigger event and the clock unit recorded separately. This is the only part that has to exist in advance, and it is the part everybody defers.
- 4
Enter one timestamp during
The register computes every deadline, sorts by expiry, and reports the working hours actually inside each window. Four minutes at declaration, before triage rather than after.
Frequently asked questions
Is this template free?
Yes, and the download needs no account, card or email. Edit with AI is the optional half and the one that builds the map: it reads your agreements, extracts the notice clauses, and derives every deadline. The rest of the template library works the same way.
What format are the downloaded files?
Six documents as .docx and five sheets as .csv, in one zip. Word, Pages, Google Docs, Excel, Numbers and Sheets open them with nothing to convert. The sheets arrive carrying the worked Stannary example, so you can read a filled register before replacing it.
Why compute deadlines before triage rather than after scope is known?
Because it takes four minutes and it is the only calm moment you get. The register tells you whether your first deadline falls at Saturday lunchtime, which changes who you wake in the next ten minutes. Scope changes the population, not the expiry times.
Is 72 hours the same as three working days?
No, and the difference is the point. The EDPB restates Article 33 as notification not later than 72 hours after having become aware, which is elapsed time. From a Friday lunchtime discovery that window holds nine working hours.
We are a vendor, not a covered entity. Do these clocks apply to us?
Some of them, and one is easy to misread. A business associate has 60 calendar days to notify the covered entity, but the customer is deemed to discover when their agent does. Where agency applies, using your sixty days leaves them none.
How is this different from an incident communication plan?
Different audience and a different clock. This pack owns the obligations you owe to regulators, customers and individuals under an instrument. Telling everyone else what is happening while it happens is the incident communication pack, which runs on a promised cadence rather than a statute.
Where does the plan connect to the rest of our security work?
Three places. The scope question is answered by the access register, the recovery objectives by the continuity plan, and what a subprocessor actually holds on your behalf by the vendor SOC 2 review. This pack owns the clocks and nothing else.