Incident Response Policy
How the Company classifies, contains, and closes security, operational, and compliance incidents, and who it tells, on what clock, when one happens.
| Field | Value |
|---|---|
| Document | Incident Response Policy |
| Version | 1.0 |
| Owner | Compliance Officer |
| Review | Annual, or on material change to systems, vendors, or requirements |
Authorities
This policy implements, within the sponsor bank's program:
- Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice (12 CFR Part 364, Appendix B, Supplement A, or the equivalent issued by the sponsor bank's primary federal regulator), the Gramm-Leach-Bliley Act safeguards guidance that requires a response program covering assessment, containment, notice to the regulator, and notice to affected customers.
- Computer-Security Incident Notification Rule (12 CFR Part 53, Part 225 Subpart N, and Part 304 Subpart C), which requires the sponsor bank to notify its regulator within 36 hours of determining that a notification incident has occurred, and reaches the Company through the rule's bank service provider duty to notify the bank as soon as possible of a material disruption of four hours or more.
- FFIEC IT Examination Handbook, Information Security booklet, which sets the examination expectations for incident identification, assessment, containment, and response that the sponsor bank applies to its service providers.
- State breach notification laws, which govern notice to affected individuals, state attorneys general, and consumer reporting agencies when personal information is accessed without authorization.
- The sponsor bank's program agreement, which sets the breach and incident notice duties, the security contacts, and the bank's right to assess the Company after an incident.
1. Purpose and Scope
This policy sets out how the Company identifies, classifies, contains, remediates, and reports security, operational, and compliance incidents. It defines the severity levels, the response roles, the clocks for triage and containment, the notices owed to the sponsor bank, to customers, and to regulators, the post-incident review, and the testing and upkeep of the plan itself.
The policy applies to every system, dataset, and service the Company operates or relies on, including services provided by its vendors, and to every employee and contractor. Detailed procedures, contact rosters, and technical playbooks sit in the incident response runbook maintained under this policy; this document states the obligations the runbook must satisfy.
2. Incident Definition and Classification
2.1 Definition
An incident is an event or condition that threatens the confidentiality, integrity, or availability of the Company's systems, data, or services, or that violates applicable law or a sponsor bank requirement. A suspected incident is handled as an incident until triage shows otherwise.
2.2 Severity Levels
Every incident is assigned one of four severity levels at triage, from its impact, its scope, and its effect on business continuity. The severity level sets the containment clock, the activation of the response team, and the notices that follow.
| Severity | Definition | Examples |
|---|---|---|
| Critical | Unauthorized access to or disclosure of customer data; a complete outage of payment processing, settlement, or account access lasting more than one hour; ransomware or destructive malware; a compromise at a vendor that takes down a service the Company depends on; fraudulent or unauthorized transaction volumes that require an immediate freeze of accounts or channels; any event that triggers a regulatory or sponsor bank notice | Customer records exposed outside the Company; cloud infrastructure compromised; settlement down for more than an hour; a payment corridor suspended by the sponsor bank |
| High | Unauthorized access to systems or data without confirmed exfiltration of customer data; partial degradation of a specific function; suspected malware on Company equipment; loss of a device holding customer or proprietary data; a vendor security event whose scope is unclear; a significant control failure or process deviation | A stolen laptop, even when encrypted; a credential committed to a code repository and rotated; a customer activated before verification completed; database queries from an unexpected address |
| Moderate | A phishing or social-engineering attempt that did not result in compromise; non-critical downtime or degradation resolved within two hours; a minor data or configuration error detected and corrected; a vendor advisory affecting a non-critical service; a single failed access attempt or minor audit finding | A staff member reports an impersonation email; a payment API returns errors for half an hour; reconciliation finds and corrects a small overpayment |
| Low | An informational security alert or third-party vulnerability disclosure with no direct impact; a routine policy violation or housekeeping issue; minor degradation with no user impact | An unrelated vendor security bulletin; an unlocked workstation; a background job running slower than baseline |
Classification is a judgment made by the Compliance Officer as Incident Commander. A severity may be raised at any time as facts emerge, and is not lowered until containment is confirmed.
3. Roles and Activation
3.1 Response Roles
| Role | Held by | Responsibility |
|---|---|---|
| Incident Commander | Compliance Officer | Directs the response, classifies severity, coordinates communication, and authorizes containment and remediation. For Critical incidents the chief executive is notified and joins command decisions |
| Technical Lead | Engineering or operations | Investigates, contains, eradicates, and recovers: isolating devices, patching, rotating credentials, reverting changes, and restoring from backup |
| Communications Lead | Compliance Officer or delegate | Owns every external message: customer notices, sponsor bank reports, and regulatory notifications |
| Legal counsel | Outside counsel | Engaged for any incident with regulatory implications or significant reputational risk; advises on disclosure duties, notification timing, and litigation exposure |
| Forensics specialist | Outside forensics firm | Retained for any breach, malware, unauthorized access, or compromise that needs deep investigation |
3.2 Activation
The full response team is activated on discovery of any High or Critical incident. Moderate and Low incidents are managed by the Compliance Officer without full activation unless their complexity warrants it. Counsel and forensics are engaged by the Incident Commander as soon as an incident appears to involve customer data, unauthorized access, or a possible regulatory notice.
4. Detection, Triage, and Containment
4.1 Detection and Triage
Incidents reach the Company through security tooling alerts, monitoring and log review, vendor and sponsor bank notifications, staff reports, and customer complaints. Whoever receives the first report notifies the Compliance Officer immediately. The Compliance Officer triages the report the same business day, assigns a severity under section 2.2, opens the incident record, and decides whether the response team is activated.
4.2 Containment Clocks
Containment stops the spread of a compromise or the growth of its impact. The clock runs from confirmation of the incident:
| Severity | Containment begins |
|---|---|
| Critical | Within 30 minutes of confirmation |
| High | Within 2 hours of confirmation |
| Moderate | Within 8 business hours of confirmation |
| Low | In the ordinary course, tracked in the incident log |
Containment actions include isolating a device from the network, disabling compromised accounts or keys, restricting access to affected systems or data, pausing payment processing or blocking an account, rotating credentials, and shutting down or isolating an affected component. The Technical Lead executes containment under the Incident Commander's direction; a containment step that interrupts customer service or settlement is a decision of the Incident Commander.
4.3 Eradication and Recovery
Eradication removes the root cause: patching vulnerable systems, removing malware or unauthorized code, restoring from clean backups where a compromise is confirmed, revoking and reissuing credentials, and fixing the misconfiguration or process failure behind the incident. Eradication is completed before any affected system returns to production.
Recovery restores normal operation: rebuilding compromised systems from clean media, restoring data from backups with integrity checks, verifying function, restoring settlement and payment processing in stages, and watching for recurrence. The Technical Lead and the Incident Commander both confirm recovery before the incident is treated as contained.
5. Sponsor Bank Notification
5.1 Data Security Breach
The Company notifies the sponsor bank immediately of any breach of security at the Company or at any of its critical service providers that results in unauthorized disclosure of account holder data or other sponsor bank confidential information. The notice describes the nature of the breach and the corrective action taken. The Company immediately limits, stops, or otherwise remedies the disclosure. The sponsor bank may engage an assessor, and the Company provides the facilities, records, and personnel access the assessor requests.
5.2 Computer-Security Incident
The Company notifies the sponsor bank as soon as possible once it determines that it has experienced a computer-security incident, whether or not unauthorized access is involved, that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the services or activities it provides to the sponsor bank for four hours or more. This is the bank service provider notice under the Computer-Security Incident Notification Rule; it feeds the sponsor bank's own duty to notify its regulator within 36 hours, so it is not held for a completed investigation.
5.3 Critical Incident Notice and Ongoing Updates
Any Critical incident affecting the Company's systems or customer data is reported to the sponsor bank's chief compliance officer and chief risk officer within four hours of confirmation. The initial notice gives a brief description of the incident, the severity classification and preliminary business impact, the containment actions taken, whether customer notification appears to be required, and the timeline for further communication.
For Critical incidents the Company updates the sponsor bank at least daily until resolution, covering the status of containment and recovery, forensics findings and root cause, the projected timeline, the customers affected, and the regulatory notifications made or planned.
5.4 Incident Closure Report
Within ten business days of resolving an incident that was reported to the sponsor bank, the Company delivers a written closure report covering the incident timeline, the root cause and analysis, forensics findings where applicable, the remediation taken, the process or control improvements adopted, and evidence of any customer notification.
5.5 Security Contacts
The Company keeps a primary and a secondary security contact on file with the sponsor bank for breach and incident notification, as the program agreement requires, and updates them within five business days of any change.
6. Customer Notification
Customers are notified of any incident involving unauthorized access to their data, including identity and verification documents, account details, and transaction records, or a compromise of their systems through the Company. A contained incident with no customer data exposure, such as a stolen but encrypted device or malware found on a non-production server, does not require notice.
The Compliance Officer decides whether notice is required, and its timing, in consultation with outside counsel. Notice goes out as soon as practical after containment and root cause analysis, typically within five to ten business days of confirmation, and its timing is coordinated with regulatory notices and the sponsor bank's preferences.
A customer notice describes what happened and which data was affected; when the incident occurred and when it was discovered; the actions the Company has taken to contain and remediate it; the steps customers should take to protect themselves; and a contact for questions. The language is approved by counsel and neither assigns blame nor assumes liability.
7. Regulatory Notification
7.1 State Breach Notification Laws
Where an incident involves unauthorized access to personal information of customers, their principals, or their employees, state breach notification laws may apply. Outside counsel reviews the facts and the laws of each affected state to determine what notice is required. The Company notifies affected individuals, the state attorney general where required, and consumer reporting agencies where required, within the timing each state law sets, typically within 30 days of discovery. State notices are coordinated with the sponsor bank so that the bank's own customer notice under the Interagency Guidance and the Company's notice are consistent.
7.2 Notifications Made Through the Sponsor Bank
Where an incident affects deposit or account services, the sponsor bank, as the insured institution, owes notice to its primary federal regulator on that regulator's timeline, including the 36-hour notice under the Computer-Security Incident Notification Rule. Where an incident touches the Company's participation in ACH, wire, or real-time payment systems, notice to the Federal Reserve or the payment system operator may be required. In both cases the sponsor bank makes the notice and the Company supplies the incident details it needs; the Compliance Officer coordinates with the bank's compliance team so that the bank's clock can be met.
8. Post-Incident Review
Every High or Critical incident, and any Moderate incident the Compliance Officer selects, receives a post-incident review. Forensics or the technical team establishes the root cause and timeline. Counsel and the Compliance Officer assess the notification obligations to the sponsor bank, regulators, customers, and the public.
Within five business days of containment the response team holds a facilitated lessons-learned meeting covering what happened and why, what went well and what did not, the control or process changes needed to prevent recurrence, and the improvements agreed. Each item is assigned an owner and a completion date and is tracked to closure; high-impact items are added to the compliance roadmap. The findings are shared with the sponsor bank through the closure report under section 5.4.
9. Testing the Plan
The Company runs a tabletop exercise at least once a year. A scenario is prepared in advance, such as a payment system outage, a customer data breach, or a vendor compromise. The response team and relevant staff walk through the response, with the facilitator introducing new facts as the exercise proceeds, and discuss decisions, communication, and coordination. The facilitator documents observations and improvement areas, and the findings are carried into the next plan update.
10. Recordkeeping
Every incident, at any severity, is recorded in the incident log with the date and time of detection, the severity and type, a description, the response actions and their timeline, the root cause analysis, forensics findings where applicable, the remediation and lessons-learned items, and the regulatory and sponsor bank notifications made. Incident records are retained for at least seven years and are available to the independent auditor and to the sponsor bank's compliance reviews.
11. Plan Maintenance and Approval
This policy and the runbook beneath it are reviewed and updated at least annually, and sooner on a material change to systems, infrastructure, vendors, or the organization; on lessons learned from an actual incident or tabletop exercise; on a change to regulatory or sponsor bank requirements; or on a change in the threat landscape. Changes are approved by the Compliance Officer, communicated to the response team, distributed to all employees and applicable contractors, and provided to the sponsor bank's compliance team.