Compliance
How do you handle security incident communication?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Communicate incidents to affected customers and regulators within your committed and legally required timeframes, with accurate, timely updates through a designated channel. Predefine templates and ownership so communication is consistent.What the security reviewer is checking
The reviewer is asking: if you are breached, when and how will we find out? They look for a committed notification window for incidents affecting customer data — commonly within 24, 48, or 72 hours of confirmation, and it must be consistent with your DPA and their contract, since a questionnaire answer promising 72 hours against a contract requiring 24 is a finding in itself. Beyond the initial notice, they check for defined communication channels and named roles, cadence of updates during an ongoing incident, whether a status page provides availability transparency, and whether customers receive a post-incident report with root cause and corrective actions.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.Customer communication is a defined workstream in our incident response plan with a designated communications lead, so notification is never an afterthought of the technical response. If we confirm a security incident affecting your data, we notify your designated security contact by email without undue delay and within 48 hours of confirmation — or within any shorter window your agreement specifies — including what happened, the data and services involved as understood at that time, actions taken, and a named incident contact. During an ongoing incident we provide updates at least every 24 hours until resolution, and service availability incidents are additionally tracked in real time on our public status page. After closure, affected customers receive a written post-incident report covering root cause, timeline, impact, and corrective actions. Where an incident triggers statutory obligations such as GDPR processor notification, those timelines take precedence. The notification workflow is exercised as part of our annual incident response tabletop.
Evidence reviewers expect you to attach
- Incident response plan sections covering communication roles and notification timelines
- Data processing agreement clause on breach notification
- Status page URL and an example historical incident entry
- Sample or template post-incident report (sanitized)
- Most recent incident response tabletop exercise summary
Follow-up questions reviewers ask next
- What is your contractual notification window measured from — detection or confirmation?
- Who at your company is accountable for customer notification during an incident?
- Will we be notified of incidents at a subprocessor that affect our data?
- Can we register a dedicated security contact for incident notices?
- Can you share a redacted post-incident report from a past event?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated compliance questions
Do you have a formal Information Security Policy?Do you have a documented incident response plan?What security awareness training do employees receive?Do you have a business continuity plan?Do you have cyber insurance coverage?How do you manage third-party vendor risk?
Browse the full security questionnaire question library