Skip to content

🛡️ Add incident response program - #9

Merged
JFWooten4 merged 6 commits into
mainfrom
incident-response-program
Jun 1, 2026
Merged

🛡️ Add incident response program#9
JFWooten4 merged 6 commits into
mainfrom
incident-response-program

Conversation

@JFWooten4

Copy link
Copy Markdown
Member

Adds a written incident response program for Regulation S-P compliance under 17 CFR § 248.30(a)(3). The program should define how BlockTransfer detects, assesses, contains, controls, recovers from, and escalates unauthorized access to or use of customer information, including when customer notification procedures must be triggered.

Recordkeeping implementation is out of scope for this PR and should be handled separately under the transfer-agent recordkeeping issue.

Regulatory basis

17 CFR § 248.30(a)(3): response program

Written policies and procedures in paragraph (a)(1) of this section must include a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including customer notification procedures.

This response program must include procedures for the covered institution to:

(i) Assess the nature and scope of any incident involving unauthorized access to or use of customer information and identify the customer information systems and types of customer information that may have been accessed or used without authorization;

(ii) Take appropriate steps to contain and control the incident to prevent further unauthorized access to or use of customer information; and

(iii) Notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization in accordance with paragraph (a)(4) of this section unless the covered institution determines, after a reasonable investigation of the facts and circumstances of the incident of unauthorized access to or use of sensitive customer information, that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience.

17 CFR § 248.30(a)(4)(i): notification obligation

Unless a covered institution has determined, after a reasonable investigation of the facts and circumstances of the incident of unauthorized access to or use of sensitive customer information that occurred at the covered institution or one of its service providers that is not itself a covered institution, that sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience, the covered institution must provide a clear and conspicuous notice, or ensure that such notice is provided, to each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.

The notice must be transmitted by a means designed to ensure that each affected individual can reasonably be expected to receive actual notice in writing.

17 CFR § 248.30(a)(4)(iii): notice timing

A covered institution must provide the notice as soon as practicable, but not later than 30 days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred unless the United States Attorney General determines that the notice required under this rule poses a substantial risk to national security or public safety, and notifies the Commission of such determination in writing.

17 CFR § 248.30(a)(5): service providers

A covered institution's response program prepared in accordance with paragraph (a)(3) of this section must include the establishment, maintenance, and enforcement of written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring, of service providers, including to ensure that the covered institution notifies affected individuals as set forth in paragraph (a)(4) of this section.

The policies and procedures must be reasonably designed to ensure service providers take appropriate measures to:

(A) Protect against unauthorized access to or use of customer information; and

(B) Provide notification to the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider. Upon receipt of such notification, the covered institution must initiate its incident response program adopted pursuant to paragraph (a)(3) of this section.

Notwithstanding a covered institution's use of a service provider in accordance with paragraphs (a)(5)(i) and (ii) of this section, the obligation to ensure that affected individuals are notified in accordance with paragraph (a)(4) of this section rests with the covered institution.

Changes to be made

  • [] Create a written incident response program for unauthorized access to or use of customer information.
  • Define incident intake, triage, escalation, assessment, containment, control, recovery, and closeout procedures.
  • Add procedures to identify affected customer information systems and the types of customer information involved.
  • Add a reasonable-investigation workflow for determining whether sensitive customer information was or is reasonably likely to have been accessed or used without authorization.
  • Add customer notification decision procedures tied to the 30-day notice requirement.
  • Add service-provider escalation requirements, including the 72-hour provider breach notice expectation.
  • Define internal roles responsible for legal, technical, vendor, customer-notice, and executive escalation.
  • Cross-reference the separate customer notice template/procedure and vendor oversight workstreams.

Co-authored-by: Codex <noreply@openai.com>
@JFWooten4 JFWooten4 self-assigned this May 18, 2026
@JFWooten4
JFWooten4 marked this pull request as draft May 18, 2026 17:46
@JFWooten4 JFWooten4 changed the title 🛡️ Add incident response program item 🛡️ Add incident response program May 18, 2026
@JFWooten4

Copy link
Copy Markdown
Member Author

There are bits of this that are written without full contextualization or independent implementation for the sake of (i) time and (ii) merge order. It is not generally possible to cross-reference the other policies that haven't been written yet in the other PRs.

@JFWooten4
JFWooten4 marked this pull request as ready for review June 1, 2026 23:51
@JFWooten4
JFWooten4 merged commit 06b0de1 into main Jun 1, 2026
@JFWooten4
JFWooten4 deleted the incident-response-program branch June 1, 2026 23:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant