Security Incident Report Form
Standardised form for documenting and reporting security incidents.
Purpose
Every security incident must be documented consistently for investigation, compliance, and prevention. This form captures all required information.
Section 1: Incident Details
- Incident ID: Unique identifier (e.g., SEC-2026-001)
- Reported Date & Time: When the incident was reported
- Reported By: Name, department, contact
- Category: Phishing, malware, unauthorised access, data breach, physical security
- Severity: Critical, High, Medium, Low
Section 2: Description
Chronological description of what happened, when it started, how it was discovered, and immediate actions taken.
Section 3: Impact Assessment
- Data Affected: What data was potentially compromised?
- Systems Affected: Which systems were impacted?
- Users Affected: How many users were impacted?
- Business Impact: Revenue, productivity, reputation impact
Section 4: Response Actions
Document all containment, investigation, and recovery actions with timestamps.
Related reading
Security Incident Report Template
A standardised template for documenting and reporting security incidents — from phishing attempts to data breaches.
Read moreResourceAccess Request Form
Standardised form for requesting access to systems, applications, or data.
Read moreResourceEmployee Security Awareness Training Guide
Train employees on security basics — phishing, passwords, data handling, and incident reporting.
Read moreArticleHow to Handle a Data Breach: Step-by-Step Guide
What to do when a data breach happens — immediate response, investigation, notification, and prevention.
Read moreArticleHow to Build an IT Asset Disposal Policy That Auditors Love
Disposing of old laptops is not just about finding a scrap dealer. Learn how to create a disposal policy that satisfies auditors, protects data, and stays compliant.
Read morePut this into practice with workro desk.