Month 1
The program and the register, built
A written incident response program naming the firm's actual custodian, CRM, portfolio software and email archive, with the assess/contain/notify procedures the rule calls for; the customer-notification letter set and a 30-day notification playbook; and a service-provider register built from the firm's vendor list that records, for each vendor, the breach-notification commitment it already publishes (contract or data-processing terms, trust-centre page, SOC 2 availability) and flags the ones with none.