Keep a useful incident record
Separate facts, decisions and remaining work without losing the original timeline.
Content and source check: October 1, 2026 · Operational suggestions
Start with the known facts
Name the record, describe what is known and leave uncertain scope, classification and times unresolved. Use your response plan and involve the people authorized to coordinate the response.
Separate the clocks
Occurrence, firm awareness, provider awareness and record creation are different facts. Enter the time and its UTC offset, record the source of the information, and leave unknown times blank. A later record entry never grants a new external notification window.
Preserve the timeline
Add observations, response steps, decisions and communications with an event time and responsible role. Add a correction linked to the original entry when facts change. In the firm pilot, original entries cannot be overwritten and saves preserve the authenticated actor and prior version.
Record the review, not an automatic determination
Capture containment, recovery validation and your team's notification assessment with its basis and responsible role. The SEC's Regulation S-P amendments address incident-response programs and customer notification; this tool does not determine applicability, calculate deadlines or send notices. Review obligations with your qualified advisers.
Close deliberately and keep follow-up open
Record the closure basis and lessons. In an enabled firm program, a designated reviewer approves closure. A separate reviewed summary can share selected lessons and corrective actions without copying the incident timeline, awareness times, affected scope or evidence. Closure does not close those actions.
Source & applicability
NIST-61-3 — SP 800-61 Rev. 3 — Incident Response Recommendations
Incident response spans preparation, response, recovery and improvement within cybersecurity risk management. General guidance, not a notification deadline or RIA-specific legal determination.
SEC-registered and state-registered firms may have different obligations. Have the appropriate professionals review what applies to your firm. No regulatory determination is made here.