Incident Triage Form
Purpose
Use this form when a cybersecurity incident is first reported.
The objective is to quickly establish the known facts, immediate risk, affected systems, and required escalation.
Incident Information
Incident ID: ____________________
Date/time reported: ____________________
Reported by: ____________________
Triage owner: ____________________
Initial Description
What happened?
How was it discovered?
Current Status
Is suspicious activity still occurring?
- Yes / No / Unknown
Does the attacker potentially still have access?
- Yes / No / Unknown
Is business operation affected?
- Yes / No
Is sensitive data potentially involved?
- Yes / No / Unknown
Is financial loss possible?
- Yes / No / Unknown
Potentially Affected Assets
Accounts: ____________________
Devices: ____________________
Servers: ____________________
Applications: ____________________
Cloud services: ____________________
Email: ____________________
Data: ____________________
Vendors: ____________________
Network systems: ____________________
Incident Type
- Account compromise
- Phishing
- Business email compromise
- Malware
- Ransomware
- Data exposure
- Payment fraud
- Insider threat
- Vendor compromise
- Cloud compromise
- Website compromise
- Lost device
- Other: ____________________
Immediate Evidence Available
Security alerts: ____________________
Logs: ____________________
Emails/messages: ____________________
Screenshots: ____________________
Affected device: ____________________
Other evidence: ____________________
Initial Containment
Actions already taken:
Actions still required:
Severity
- Low
- Medium
- High
- Critical
Reason for rating:
Consider:
- Business disruption
- Sensitive data
- Attacker access
- Financial impact
- Number of systems
- Privileged accounts
- Customer impact
- Legal or regulatory obligations
Escalation
-
Leadership notified: Yes / No
-
MSP / IT notified: Yes / No
-
Insurer notified: Yes / No
-
Legal notified: Yes / No
-
Incident response provider notified: Yes / No
-
Bank notified: Yes / No / N/A
-
Vendor notified: Yes / No / N/A
Immediate Priorities
Next Review Time
Practical Rule
Triage establishes what is known, what is at risk, and what must happen next. It is not the final investigation.