## Purpose

Use this form when a cybersecurity incident is first reported.

The objective is to quickly establish the known facts, immediate risk, affected systems, and required escalation.

## Incident Information

Incident ID: ____________________

Date/time reported: ____________________

Reported by: ____________________

Triage owner: ____________________

## Initial Description

What happened?

---

How was it discovered?

---

## Current Status

Is suspicious activity still occurring?

- Yes / No / Unknown

Does the attacker potentially still have access?

- Yes / No / Unknown

Is business operation affected?

- Yes / No

Is sensitive data potentially involved?

- Yes / No / Unknown

Is financial loss possible?

- Yes / No / Unknown

## Potentially Affected Assets

Accounts: ____________________

Devices: ____________________

Servers: ____________________

Applications: ____________________

Cloud services: ____________________

Email: ____________________

Data: ____________________

Vendors: ____________________

Network systems: ____________________

## Incident Type

- Account compromise
- Phishing
- Business email compromise
- Malware
- Ransomware
- Data exposure
- Payment fraud
- Insider threat
- Vendor compromise
- Cloud compromise
- Website compromise
- Lost device
- Other: ____________________

## Immediate Evidence Available

Security alerts: ____________________

Logs: ____________________

Emails/messages: ____________________

Screenshots: ____________________

Affected device: ____________________

Other evidence: ____________________

## Initial Containment

Actions already taken:

---

Actions still required:

---

## Severity

- Low
- Medium
- High
- Critical

Reason for rating:

---

**Consider:**

- Business disruption
- Sensitive data
- Attacker access
- Financial impact
- Number of systems
- Privileged accounts
- Customer impact
- Legal or regulatory obligations

## Escalation

- Leadership notified: Yes / No

- MSP / IT notified: Yes / No

- Insurer notified: Yes / No

- Legal notified: Yes / No

- Incident response provider notified: Yes / No

- Bank notified: Yes / No / N/A

- Vendor notified: Yes / No / N/A

## Immediate Priorities

1. ---
    
2. ---
    
3. ---
    
## Next Review Time

---

## Practical Rule

Triage establishes what is known, what is at risk, and what must happen next. It is not the final investigation.
