PRACTICAL GUIDE · VERSION 1.0.0

Keep a useful incident record

Separate facts, decisions and remaining work without losing the original timeline.

Content and source check: October 1, 2026 · Operational suggestions

01

Start with the known facts

Name the record, describe what is known and leave uncertain scope, classification and times unresolved. Use your response plan and involve the people authorized to coordinate the response.

02

Separate the clocks

Occurrence, firm awareness, provider awareness and record creation are different facts. Enter the time and its UTC offset, record the source of the information, and leave unknown times blank. A later record entry never grants a new external notification window.

03

Preserve the timeline

Add observations, response steps, decisions and communications with an event time and responsible role. Add a correction linked to the original entry when facts change. In the firm pilot, original entries cannot be overwritten and saves preserve the authenticated actor and prior version.

04

Record the review, not an automatic determination

Capture containment, recovery validation and your team's notification assessment with its basis and responsible role. The SEC's Regulation S-P amendments address incident-response programs and customer notification; this tool does not determine applicability, calculate deadlines or send notices. Review obligations with your qualified advisers.

05

Close deliberately and keep follow-up open

Record the closure basis and lessons. In an enabled firm program, a designated reviewer approves closure. A separate reviewed summary can share selected lessons and corrective actions without copying the incident timeline, awareness times, affected scope or evidence. Closure does not close those actions.

Source & applicability

NIST-61-3 — SP 800-61 Rev. 3 — Incident Response Recommendations

Incident response spans preparation, response, recovery and improvement within cybersecurity risk management. General guidance, not a notification deadline or RIA-specific legal determination.

SEC-registered and state-registered firms may have different obligations. Have the appropriate professionals review what applies to your firm. No regulatory determination is made here.

Start an incident record →