When Clop exploited CVE-2026-12569 in PTC's Windchill software and claimed data theft from over 40 companies, the affected organizations faced a common problem: assessing the scope, notifying stakeholders, and containing the damage quickly. Most didn't have a ready-to-use response template.
This template provides a structured process for responding to a third-party software vulnerability that leads to unauthorized access. You can adapt it whether you're the software vendor, an affected customer, or managing the incident response.
Purpose of This Template
Use this template when:
- A vendor announces a vulnerability in software you use.
- You discover unauthorized access through a third-party application.
- Your organization needs to assess exposure from a supply-chain incident.
- You're coordinating response across legal, IT, and communications teams.
The template covers the first 72 hours of response, from initial notification through containment and preliminary assessment. It doesn't replace your Computer Security Incident Response Team playbook but provides a checklist when the breach originates outside your direct control.
Prerequisites
Before using this template effectively, ensure you have:
- Asset inventory: A current list of third-party software, including version numbers and deployment locations.
- Vendor contact registry: Security contacts for each vendor, not just account managers.
- Data classification map: Types of data flowing through each third-party system.
- Notification matrix: Pre-defined thresholds for notifying customers, regulators, or partners.
- Authority to act: Clear decision rights so your team can isolate systems without waiting for executive approval.
If you lack these, start building them now. The template will be faster to execute with proper preparation.
The Template
Hour 0-4: Initial Assessment
Incident lead: [Name]
Date/Time notified: [YYYY-MM-DD HH:MM UTC]
Vendor: [Company name]
Affected product: [Product name and version]
CVE identifier: [If available]
Immediate Actions Checklist
- Confirm vendor notification is legitimate (call vendor directly, don't rely on email alone).
- Identify all instances of affected software in your environment.
- Document current patch/version status for each instance.
- Assess whether the vulnerability has been exploited in your environment (check logs for indicators of compromise the vendor provides).
- Determine if the affected system processes regulated data (HIPAA, General Data Protection Regulation, PCI DSS, etc.).
- Brief executive sponsor and legal counsel.
Preliminary Scope Assessment
Systems affected:
- [System name, location, business function]
- [System name, location, business function]
Data types potentially exposed:
- Customer personal data
- Financial records
- Intellectual property (CAD files, product designs, source code)
- Authentication credentials
- Business communications
- System backups
- Other: [Specify]
Estimated records/users impacted: [Number or "Under investigation"]
Hour 4-24: Containment and Evidence Preservation
Containment Actions
- Apply vendor patch if available (document patch version and deployment time).
- If no patch available, implement vendor-recommended workarounds.
- Isolate affected systems from network (document isolation method and time).
- Disable affected user accounts pending credential reset.
- Block network indicators of compromise at perimeter.
- Preserve system logs and memory dumps before remediation changes system state.
Containment completion time: [YYYY-MM-DD HH:MM UTC]
Evidence Collection
Log sources preserved:
- Application logs (specify date range)
- Network flow logs (specify date range)
- Authentication logs (specify date range)
- Database query logs (specify date range)
- Endpoint detection and response telemetry
- Cloud service provider logs
Chain of custody established: [Yes/No]
Evidence storage location: [Secure location, access restricted to incident team]
Hour 24-72: Assessment and Notification Preparation
Detailed Impact Analysis
Was the vulnerability exploited?: [Yes/No/Unknown]
Evidence of exploitation: [Describe specific indicators found or state "None detected"]
Data confirmed exfiltrated: [List specific data types or "None confirmed"]
Timeframe of unauthorized access: [Start date - End date or "Under investigation"]
Regulatory Notification Requirements
Based on data types affected, assess notification obligations:
- General Data Protection Regulation 72-Hour Notification Requirement (if EU personal data affected)
- HIPAA Breach Notification Rule (if protected health information affected)
- State breach notification laws (check where affected individuals reside)
- SEC 8-K filing (if material to publicly traded company)
- Contractual notification obligations to customers
Notification deadline: [Earliest date based on regulations]
Notification owner: [Name and role]
Stakeholder Communication Plan
Internal:
- Executive briefing scheduled: [Date/time]
- Board notification: [Date/time if required]
- All-hands communication: [Date/time]
External:
- Customer notification: [Method and timing]
- Regulatory notification: [Agencies and timing]
- Media response prepared: [Yes/No]
- Cyber insurance carrier notified: [Date]
Customization Options
For software vendors: If you're the vendor who discovered the vulnerability, focus on the communication sections. Your customers need specific indicators of compromise, not just CVE details. Include sample log queries they can run to detect exploitation.
For affected customers: Adjust the data classification section to match your data inventory. If you use the affected software only for internal operations with no customer data, your notification obligations differ significantly from a scenario where customer personal data flows through it.
For regulated industries: Add industry-specific requirements. Healthcare organizations should include HITECH Act breach analysis steps. Financial services firms should add GLBA Safeguards Rule considerations and check if the incident triggers NYDFS Cybersecurity Regulation reporting within 72 hours.
For multi-vendor incidents: If multiple vendors are affected (common in supply-chain attacks), create a separate assessment row for each vendor but consolidate your containment actions to avoid duplicated effort.
Validation Steps
After completing the template, validate your response:
Completeness check: Can you answer these questions without "Under investigation"?
- What data was exposed?
- When did unauthorized access begin and end?
- Have you contained the vulnerability?
- Do you need to notify regulators or customers?
Timeline verification: Compare your containment time against your incident response plan targets. If you took longer than planned, document why and update your plan.
Evidence integrity: Confirm your forensic evidence chain of custody will hold up if you need it for legal proceedings or regulatory inquiries.
Notification accuracy: Before you send notifications, have legal counsel review them. Premature or inaccurate notifications create more problems than delayed accurate ones.
Lessons captured: Schedule a post-incident review within two weeks. The template should get faster each time you use it.
The companies affected by the PTC vulnerability had to work through these steps in real time. Shell, GE, and others assessed their exposure, isolated systems, and determined what data was affected. Your template should make that process repeatable and faster next time a vendor calls with bad news.



