What should I record during my first assessment?¶
Create a short, contemporaneous record that lets somebody else understand what you were given, what you could see, what was still uncertain and why the first decisions were made.
You do not need a finished incident report at this stage.
You need a reliable starting point.
Separate the report from the observation¶
If somebody says “we have been breached”, record that as the report.
Then record what you can actually establish.
For example:
That separation prevents early language becoming an assumed fact.
Record the material you have received¶
List:
- filenames;
- screenshots;
- emails;
- alerts;
- ticket references;
- provider returns;
- logs;
- device or account identifiers.
For each, note where it came from and who supplied it.
Keep the times separate¶
Record:
- first known event;
- detection time;
- report time;
- your observation time;
- first preservation action;
- containment time.
Include the time zone and mark estimates clearly.
These times often become important later.
Capture the current decision picture¶
Your first assessment should also record:
- affected systems/accounts;
- current business or victim impact;
- whether activity may still be happening;
- what evidence may disappear;
- who controls the systems;
- actions already taken;
- specialists involved;
- important unknowns.
Record why early decisions were reasonable¶
A later reviewer will know more than you knew at the time.
Preserve the facts and advice that were available when the decision was made.
The practical point is: your first assessment should preserve both the developing facts and the decision context. It should let another investigator reconstruct what you knew and why you acted.