How to Answer Customer Security Incident Notification Questions

Your customer asked: “How do you notify customers of a security incident?”

The short answer

Describe the company process for deciding when and how affected customers are notified. Be careful with exact deadlines: notification timing can depend on contracts, laws, the facts of the incident, and the commitments your company has actually made.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

The customer is asking how they will learn about a security event that may affect them. This is both an operational and potentially contractual or legal topic, so questionnaire wording should not casually create new notification commitments.

How to answer accurately

Start with the version that matches reality.

1

If a notification process is documented

Describe the responsible role and general process. Use an exact number of hours or days only if the commitment has been approved and applies to the question's scope.

2

If contracts set different timelines

Avoid presenting one timeline as universal. The correct answer may depend on the applicable customer agreement.

3

If you are unsure

Escalate the question to the person responsible for legal, privacy, security, or customer commitments rather than guessing.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Incident response or notification procedure
  • Customer contract or data-processing terms
  • Notification templates
  • Prior incident communications where appropriate

What not to say

  • “We notify all customers within 24 hours” unless that is an approved and supportable commitment.
  • That every security event triggers customer notification.
  • That a legal notification requirement applies without confirming jurisdiction and facts.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra should preserve customer-notification language as an approved commitment, not generate a deadline merely because a questionnaire asks for one.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions