Skip to main content

Development trial · sample information only

Record and manage an incident

For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.

What you will achieve

Create a clear incident record, organise the response and preserve a traceable account of what happened.

This guide explains the platform workflow. Follow your organisation's urgent-response procedure immediately where necessary; recording an incident must not delay containment or escalation.

Before you start

Confirm the organisation and your reporting authority. Gather known facts, detection time, affected services and the person coordinating the response. Keep uncertain information explicitly uncertain.

Report the incident

  1. Open the incident catalogue and select Report Incident.
  2. Enter a concise title and factual description. Separate what has been observed from the suspected cause.
  3. Select the incident type and severity using the available definitions.
  4. Record Occurred at and Detected at accurately. If the occurrence time is unknown, do not present a guess as a confirmed fact.
  5. Review the confirmed-breach field carefully. Suspicion is not confirmation; obtain the responsible specialist's decision.
  6. Record the business impact, Reported By and Incident Manager where known.
  7. Submit Report Incident and open the resulting record.

Coordinate the response

Use Command Centre for the current position. In Team, check leadership and response participants. Link confirmed affected Assets, ROPAs and Data Entities through their owning tabs.

Use Tasks for actionable response work, with clear responsibility and dates. Preserve evidence in Documents and record factual developments in the appropriate discussion or notes area.

Broadcast incident update is a communication action, not just an internal note. Check the recipients and wording before sending. Use Notifications to record and manage notification work under the responsible owner's instructions.

Advance the configured workflow only when its conditions are satisfied. Keep “contained”, “resolved”, “reviewed” and “closed” conceptually separate.

Check it worked

Reload the record and confirm the incident manager, severity, times and affected links. Ask the response team to confirm their work is visible and understood. At closure, inspect Review and Lessons, and ensure outstanding improvement tasks have owners.

If something goes wrong

Problem Next action
An affected asset is only suggested Verify it before treating it as confirmed impact
A broadcast result is uncertain Inspect communication history before sending again
A transition is blocked Resolve the stated prerequisite with the response owner
New facts contradict the initial report Correct the record transparently and retain the explanation and evidence

Human judgement matters

A platform deadline or badge does not decide a legal notification duty. Refer that judgement to the authorised privacy, security or legal owner. Avoid adding unnecessary personal data to the incident narrative.

What next?

For the wider context, see Manage risks and incidents.

Complete the lessons review and link improvement work to risks, controls and tasks so the response produces sustained changes.

Get help

Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.

Was this article helpful?