See what a professional incident evidence pack looks like
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
Use this practical template to document what happened, what was affected, what evidence was collected, what actions were taken, and what the client should do next.
Use this template when your MSP needs to document a client security incident, phishing event, suspicious login, malware alert, ransomware containment exercise, data exposure concern, endpoint compromise, or any incident that needs a structured record. This template is useful for:
| Time | Event type | Description | Owner | Evidence reference |
|---|---|---|---|---|
| Detection | ||||
| Containment | ||||
| Eradication | ||||
| Recovery | ||||
| Communication | ||||
| Closure |
| Evidence ID | Filename/source | Type | Description | Collected by | Collected at |
|---|---|---|---|---|---|
| EV-001 | Screenshot / Log / PDF / IOC / Email / Export | ||||
| EV-002 | |||||
| EV-003 |
Suggested evidence types:
| Time | Audience | Channel | Message summary | Owner |
|---|---|---|---|---|
| Client contact | Email/phone/portal | |||
| Internal team | Teams/Slack/ticket | |||
| Management | Email/report |
Use only when relevant and validated by your legal/compliance process.
| Milestone | Target | Status | Notes |
|---|---|---|---|
| Early warning | 24h | Pending / Completed / Not applicable | |
| Incident notification | 72h | Pending / Completed / Not applicable | |
| Final report | Around one month | Pending / Completed / Not applicable |
| Recommendation | Priority | Owner | Target date |
|---|---|---|---|
| High / Medium / Low | |||
A manual template is a good starting point, but it still requires discipline. CasePack turns the same structure into a workflow:
Use the template today, then see how CasePack turns it into a repeatable incident evidence workflow for MSP teams.
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.