# MSP Security Incident Report Template

Use this template to document what happened, what was affected, what evidence was
collected, what actions were taken, and what the client should do next. Adapt the
language and remove internal-only details before sending to clients.

> This template is an operational documentation aid. No template alone guarantees
> regulatory compliance — confirm reporting obligations with qualified
> legal/compliance counsel.

---

## 1. Incident summary

- **Incident title:**
- **Client / tenant:**
- **Incident ID:**
- **Prepared by:**
- **Date prepared:**
- **Incident status:** Open / In Progress / Resolved / Closed
- **Severity:** Low / Medium / High / Critical
- **Affected users/systems:**

**Executive summary:**
_Write a short, non-technical explanation of what happened, what was affected,
what your team did, and what remains to be done._

## 2. Initial detection

- **Date/time detected:**
- **Detected by:** Client / MSP / Monitoring / EDR / SIEM / Other
- **Source system:**
- **Related PSA ticket:**
- **Initial symptoms or alerts:**

## 3. Incident classification

- **Incident type:** Phishing / Malware / Suspicious login / Data exposure / Ransomware / Unauthorized access / Other
- **Known or suspected threat actor:**
- **Known or suspected root cause:**
- **Business impact:**
- **Data impact:**
- **Cross-border or regulatory impact:**

## 4. Timeline of events

| Time | Event type | Description | Owner | Evidence reference |
|---|---|---|---|---|
| | Detection | | | |
| | Containment | | | |
| | Eradication | | | |
| | Recovery | | | |
| | Communication | | | |
| | Closure | | | |

## 5. Evidence collected

| Evidence ID | Filename/source | Type | Description | Collected by | Collected at |
|---|---|---|---|---|---|
| EV-001 | | Screenshot / Log / PDF / IOC / Email / Export | | | |
| EV-002 | | | | | |
| EV-003 | | | | | |

Suggested evidence types: screenshots, EDR alerts, SIEM logs, email headers,
M365/Google Workspace audit logs, firewall/VPN logs, endpoint logs, IOCs, hashes,
user communication, ticket exports, recovery or remediation proof.

## 6. Actions taken

- **Containment actions:** _accounts disabled, endpoints isolated, firewall rules applied, sessions revoked, passwords reset, backups protected, other immediate containment steps._
- **Eradication actions:** _malware removal, configuration changes, persistence removal, account cleanup, threat removal steps._
- **Recovery actions:** _restored systems, verified backups, user re-enablements, monitoring, validation steps._

## 7. Client and stakeholder communication

| Time | Audience | Channel | Message summary | Owner |
|---|---|---|---|---|
| | Client contact | Email/phone/portal | | |
| | Internal team | Teams/Slack/ticket | | |
| | Management | Email/report | | |

## 8. NIS2-style milestone tracking (where applicable)

Use only when relevant and validated by your legal/compliance process.

| Milestone | Target | Status | Notes |
|---|---|---|---|
| Early warning | 24h | Pending / Completed / Not applicable | |
| Incident notification | 72h | Pending / Completed / Not applicable | |
| Final report | Around one month | Pending / Completed / Not applicable | |

## 9. Root cause and lessons learned

- **Root cause:** _What likely caused the incident?_
- **Contributing factors:** _What made the incident possible or worse?_
- **Lessons learned:** _What should change in process, tooling, configuration, training, monitoring, or escalation?_

## 10. Recommendations

| Recommendation | Priority | Owner | Target date |
|---|---|---|---|
| | High / Medium / Low | | |
| | | | |

## 11. Closure and sign-off

- **Closure status:**
- **Closure date:**
- **Reviewed by:**
- **Client approval / acknowledgement:**
- **Remaining risks:**
- **Follow-up actions:**

---

_Produced with CasePack — incident evidence packs for MSPs. https://casepack.app_
