The Protocol CollectiveAll guides

Guide

The 24-hour incident response protocol every fintech CCO needs

Your phone rings on a Tuesday at 4:47pm. Vendor X's CISO is calling. They've had an incident. They think your data may be in the affected scope.

You have approximately 17 hours of business time to do this right.

The CCO who improvises the next 17 hours risks burning credibility with regulators, auditors, and the board for years afterwards. The CCO who runs a pre-built protocol gets through it without panic, with clean documentation, and with the kind of calm that makes everyone trust them more after the incident than before.

Here's the protocol. Build it now, not at 4:47pm Tuesday.

Hour 0-1: Capture facts

Every fact in writing. What happened. When. Who reported it. Scope estimate (acknowledge uncertainty — don't fake confidence). Open the incident log immediately.

Specifically: ask the vendor to put it in writing within 60 minutes. Their email becomes the contemporaneous record auditors want. Schedule the call AFTER you have written facts.

Paper first. Voice second.

Hour 1-3: Loop CEO + General Counsel

15-minute call. Three people: CEO, General Counsel, you.

Decide: notification clock starts when? Outside counsel needed? PR statement required? What facts do we have, what do we still need to confirm?

Most CCOs delay this call wanting "more facts first." Wrong. The CEO needs to be in the loop within 3 hours, even with incomplete facts. The decisions made in this call shape the entire response arc.

Hour 3-6: Stakeholder map

Who needs to know what, in what order. Regulators (statutory clock?). Auditor. Top customers. Board chair. Internal team. Draft the message for each. Don't send yet.

Hour 6-12: Begin notifications in tier order

Regulators first if statutory clock requires (varies — NYDFS Part 500 has 72 hours for many incidents; GDPR has 72 hours). Then auditor. Then top customers. Internal team last (after they have a clear talking-point script).

Hour 12-24: Document the decision tree

Write out every decision made and why. Future audits will examine this in detail. Better to have it written contemporaneously than reconstructed from memory.

Hour 24+: Sustain the cadence

Daily 15-minute standups for first 7 days. Weekly thereafter until incident closed. Final post-mortem within 30 days of closure.

Why the protocol matters

Under stress, you don't rise to your training. You fall to your protocol.

If you don't have a 24-hour protocol written down, write one this week. Even a draft beats no draft. The first incident will reveal the gaps; refine for the next.

The Compliance Officer OS

General information about compliance and programme structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks; the professional judgement is yours.