Resources · 21

Triage a cyber incident and preserve early evidence

Turn a confusing signal into a timeline, hypotheses, decisions and proportionate escalation.

· 18 min

Incident response team examining a timeline and technical traces

What this guide helps achieve

  • Receive a useful signal
  • Preserve context
  • Assess impact
  • Organise decisions

Quick check

  • Who saw what, where and when?
  • Which sources or traces may disappear?
  • Which services, accounts and data could be affected?
  • Who authorises immediate measures?
  • When will the assessment be revisited?

Step-by-step method

  1. 01

    Open one case record

    Record the initial signal, time, observer, affected systems and reporting channel. Assign a case owner and deputy.

    Deliverable: timestamped incident record.

  2. 02

    Separate fact from hypothesis

    List verifiable observations, sources and confidence. State possible scenarios without assuming origin or scope.

    Deliverable: factual timeline and testable hypotheses.

  3. 03

    Preserve volatile material

    Identify useful logs, alerts, messages and system states; retain copies under internal procedures and record access. Avoid changes that destroy traces.

    Deliverable: initial evidence inventory and handling record.

  4. 04

    Assess scope and impact

    Map potentially affected assets, accounts, data and business journeys. Record what is confirmed, ruled out or unknown and the cost of waiting.

    Deliverable: scope map and provisional impact level.

  5. 05

    Decide and escalate

    Choose proportionate protective steps, specialists and stakeholders to inform under applicable requirements. Log the decision maker and rationale.

    Deliverable: decision log and communication plan.

  6. 06

    Reassess and learn

    Set the next situation update, add new evidence and connect causes and gaps to corrective work after closure.

    Deliverable: dated updates and lessons learned.

Management indicators

IndicatorWhat it measuresFirst action
Time to triageTime from signal to first documented scopeClarify escalation
Decision traceDecisions with time, owner and rationaleComplete the log
Evidence coverageCritical sources identified and preservedFix collection gaps
ReassessmentHypotheses revisited at agreed checkpointsUpdate scope

Common pitfalls

  • Erasing traces through premature action
  • Announcing a cause before validation
  • Keeping contradictory timelines
  • Failing to date a decision or revisit an assumption

Frequently asked questions

Is every alert an incident?

No. Triage determines whether the observations warrant a formal response and can change as evidence develops.

Must protection wait until everything is known?

No. Proportionate measures can limit harm while investigation continues, provided their effects on evidence and service are recorded.

What can be communicated initially?

Confirmed facts, known effects, current actions and the next update. Cause and scope remain provisional until established.

Official references