Security Incident Report Form
v1.3
Purpose. Use this form to report a suspected or confirmed security incident so that it can be triaged, contained and recorded.
1.When to use this form
Complete this form as soon as you suspect a security incident, including a phishing email that was opened or clicked, a malware alert, unexpected account activity, a lost or stolen device or client data sent to the wrong place. Do not wait until you are sure. Call the Cyber Security team first for anything that looks active.
2.Who completes it
The person who observed or was told of the event completes the first sections. The security analyst completes triage and classification. The Cyber Security Lead completes the containment and review sections.
3.Describing the event
Record what was seen, on which device or account, at what time and what has been done so far. Keep the original email, screenshot or log. Do not delete anything or reset passwords until the analyst has confirmed evidence is preserved.
4.Personal information
State whether personal information could have been accessed or disclosed, what type and roughly how many people. This drives the privacy breach assessment.
5.Records
The completed form is attached to the Security Incident Register entry. Severity one and two incidents will also have a post incident review attached.