Resources · 21
Triage a cyber incident and preserve early evidence
Turn a confusing signal into a timeline, hypotheses, decisions and proportionate escalation.
· 18 min
What this guide helps achieve
- Receive a useful signal
- Preserve context
- Assess impact
- Organise decisions
Quick check
- Who saw what, where and when?
- Which sources or traces may disappear?
- Which services, accounts and data could be affected?
- Who authorises immediate measures?
- When will the assessment be revisited?
Step-by-step method
- 01
Open one case record
Record the initial signal, time, observer, affected systems and reporting channel. Assign a case owner and deputy.
Deliverable: timestamped incident record.
- 02
Separate fact from hypothesis
List verifiable observations, sources and confidence. State possible scenarios without assuming origin or scope.
Deliverable: factual timeline and testable hypotheses.
- 03
Preserve volatile material
Identify useful logs, alerts, messages and system states; retain copies under internal procedures and record access. Avoid changes that destroy traces.
Deliverable: initial evidence inventory and handling record.
- 04
Assess scope and impact
Map potentially affected assets, accounts, data and business journeys. Record what is confirmed, ruled out or unknown and the cost of waiting.
Deliverable: scope map and provisional impact level.
- 05
Decide and escalate
Choose proportionate protective steps, specialists and stakeholders to inform under applicable requirements. Log the decision maker and rationale.
Deliverable: decision log and communication plan.
- 06
Reassess and learn
Set the next situation update, add new evidence and connect causes and gaps to corrective work after closure.
Deliverable: dated updates and lessons learned.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Time to triage | Time from signal to first documented scope | Clarify escalation |
| Decision trace | Decisions with time, owner and rationale | Complete the log |
| Evidence coverage | Critical sources identified and preserved | Fix collection gaps |
| Reassessment | Hypotheses revisited at agreed checkpoints | Update scope |
Common pitfalls
- Erasing traces through premature action
- Announcing a cause before validation
- Keeping contradictory timelines
- Failing to date a decision or revisit an assumption
Frequently asked questions
Is every alert an incident?
No. Triage determines whether the observations warrant a formal response and can change as evidence develops.
Must protection wait until everything is known?
No. Proportionate measures can limit harm while investigation continues, provided their effects on evidence and service are recorded.
What can be communicated initially?
Confirmed facts, known effects, current actions and the next update. Cause and scope remain provisional until established.






