Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What should I record during my first assessment?

Create a short, contemporaneous record that lets somebody else understand what you were given, what you could see, what was still uncertain and why the first decisions were made.

You do not need a finished incident report at this stage.

You need a reliable starting point.

Separate the report from the observation

If somebody says “we have been breached”, record that as the report.

Then record what you can actually establish.

For example:

Reported“Files have been encrypted across the network.”What the caller or ticket says.
ObservedFILE-03 inaccessible; ransom note present; endpoint alert active.What has actually been seen or recorded so far.

That separation prevents early language becoming an assumed fact.

Record the material you have received

List:

  • filenames;
  • screenshots;
  • emails;
  • alerts;
  • ticket references;
  • provider returns;
  • logs;
  • device or account identifiers.

For each, note where it came from and who supplied it.

Keep the times separate

Record:

  • first known event;
  • detection time;
  • report time;
  • your observation time;
  • first preservation action;
  • containment time.

Include the time zone and mark estimates clearly.

These times often become important later.

Capture the current decision picture

Your first assessment should also record:

  • affected systems/accounts;
  • current business or victim impact;
  • whether activity may still be happening;
  • what evidence may disappear;
  • who controls the systems;
  • actions already taken;
  • specialists involved;
  • important unknowns.
Example first-assessment note
06:42 local · incident reported by dispatch managerAffected: FILE-03, FILE-04Current impact: dispatch files unavailableKnown evidence: endpoint alerts + ransom noteUnknown: initial access, wider spread, data theftDecision: preserve active-session data before isolation where safe

Record why early decisions were reasonable

A later reviewer will know more than you knew at the time.

Preserve the facts and advice that were available when the decision was made.

The practical point is: your first assessment should preserve both the developing facts and the decision context. It should let another investigator reconstruct what you knew and why you acted.

Reference: CIM-014Cyber Incidents & Offender Methods