Incident Triage Form

Purpose

Use this form when a cybersecurity incident is first reported.

The objective is to quickly establish the known facts, immediate risk, affected systems, and required escalation.

Incident Information

Incident ID: ____________________

Date/time reported: ____________________

Reported by: ____________________

Triage owner: ____________________

Initial Description

What happened?


How was it discovered?


Current Status

Is suspicious activity still occurring?

  • Yes / No / Unknown

Does the attacker potentially still have access?

  • Yes / No / Unknown

Is business operation affected?

  • Yes / No

Is sensitive data potentially involved?

  • Yes / No / Unknown

Is financial loss possible?

  • Yes / No / Unknown

Potentially Affected Assets

Accounts: ____________________

Devices: ____________________

Servers: ____________________

Applications: ____________________

Cloud services: ____________________

Email: ____________________

Data: ____________________

Vendors: ____________________

Network systems: ____________________

Incident Type

  • Account compromise
  • Phishing
  • Business email compromise
  • Malware
  • Ransomware
  • Data exposure
  • Payment fraud
  • Insider threat
  • Vendor compromise
  • Cloud compromise
  • Website compromise
  • Lost device
  • Other: ____________________

Immediate Evidence Available

Security alerts: ____________________

Logs: ____________________

Emails/messages: ____________________

Screenshots: ____________________

Affected device: ____________________

Other evidence: ____________________

Initial Containment

Actions already taken:


Actions still required:


Severity

  • Low
  • Medium
  • High
  • Critical

Reason for rating:


Consider:

  • Business disruption
  • Sensitive data
  • Attacker access
  • Financial impact
  • Number of systems
  • Privileged accounts
  • Customer impact
  • Legal or regulatory obligations

Escalation

  • Leadership notified: Yes / No

  • MSP / IT notified: Yes / No

  • Insurer notified: Yes / No

  • Legal notified: Yes / No

  • Incident response provider notified: Yes / No

  • Bank notified: Yes / No / N/A

  • Vendor notified: Yes / No / N/A

Immediate Priorities




Next Review Time


Practical Rule

Triage establishes what is known, what is at risk, and what must happen next. It is not the final investigation.