Free template

MSP security incident report template

Use this practical template to document what happened, what was affected, what evidence was collected, what actions were taken, and what the client should do next.

When to use this template

Use this template when your MSP needs to document a client security incident, phishing event, suspicious login, malware alert, ransomware containment exercise, data exposure concern, endpoint compromise, or any incident that needs a structured record. This template is useful for:

  • internal incident review
  • client communication
  • executive summary reporting
  • audit preparation
  • insurer communication
  • NIS2-style reporting preparation
  • post-incident lessons learned

1. Incident summary

Incident title
Client / tenant
Incident ID
Prepared by
Date prepared
Incident status
Open / In Progress / Resolved / Closed
Severity
Low / Medium / High / Critical
Affected users/systems
Executive summary
Write a short, non-technical explanation of what happened, what was affected, what your team did, and what remains to be done.

2. Initial detection

Date/time detected
Detected by
Client / MSP / Monitoring / EDR / SIEM / Other
Source system
Related PSA ticket
Initial symptoms or alerts

3. Incident classification

Incident type
Phishing / Malware / Suspicious login / Data exposure / Ransomware / Unauthorized access / Other
Known or suspected threat actor
Known or suspected root cause
Business impact
Data impact
Cross-border or regulatory impact

4. Timeline of events

TimeEvent typeDescriptionOwnerEvidence reference
Detection
Containment
Eradication
Recovery
Communication
Closure

5. Evidence collected

Evidence IDFilename/sourceTypeDescriptionCollected byCollected at
EV-001Screenshot / Log / PDF / IOC / Email / Export
EV-002
EV-003

Suggested evidence types:

  • screenshots
  • EDR alerts
  • SIEM logs
  • email headers
  • M365/Google Workspace audit logs
  • firewall/VPN logs
  • endpoint logs
  • IOCs
  • hashes
  • user communication
  • ticket exports
  • recovery or remediation proof

6. Actions taken

Containment actions
List accounts disabled, endpoints isolated, firewall rules applied, sessions revoked, passwords reset, backups protected, or other immediate containment steps.
Eradication actions
List malware removal, configuration changes, persistence removal, account cleanup, or threat removal steps.
Recovery actions
List restored systems, verified backups, user re-enablements, monitoring, and validation steps.

7. Client and stakeholder communication

TimeAudienceChannelMessage summaryOwner
Client contactEmail/phone/portal
Internal teamTeams/Slack/ticket
ManagementEmail/report

8. NIS2-style milestone tracking where applicable

Use only when relevant and validated by your legal/compliance process.

MilestoneTargetStatusNotes
Early warning24hPending / Completed / Not applicable
Incident notification72hPending / Completed / Not applicable
Final reportAround one monthPending / Completed / Not applicable

9. Root cause and lessons learned

Root cause
What likely caused the incident?
Contributing factors
What made the incident possible or worse?
Lessons learned
What should change in process, tooling, configuration, training, monitoring, or escalation?

10. Recommendations

RecommendationPriorityOwnerTarget date
High / Medium / Low

11. Closure and sign-off

Closure status
Closure date
Reviewed by
Client approval / acknowledgement
Remaining risks
Follow-up actions

How CasePack improves this template

A manual template is a good starting point, but it still requires discipline. CasePack turns the same structure into a workflow:

  • incidents store severity, status, description, affected users, root cause, and lessons learned
  • evidence is uploaded to an incident evidence vault
  • timeline entries create a chronological response record
  • report templates generate structured outputs
  • NIS2 milestones can be tracked per incident where relevant
  • audit logs capture significant activity
  • PDF/ZIP evidence packs can be exported

Ready to stop filling this template by hand?

Use the template today, then see how CasePack turns it into a repeatable incident evidence workflow for MSP teams.

Frequently asked questions

It should include the incident summary, detection details, classification, timeline, evidence, actions taken, communication notes, impact, root cause, lessons learned, recommendations, and closure/sign-off details.

Yes. Adapt the language and remove internal-only details before sending it to clients.

No template alone guarantees regulatory compliance. Use this as an operational documentation aid and confirm reporting obligations with qualified legal/compliance counsel.

CasePack structures the same information inside the product, then helps generate reports and evidence pack exports from the incident record.

Not necessarily. Use a lightweight triage report for lower-severity incidents and a fuller evidence pack for incidents involving material impact, client concern, audit needs, insurance, or regulatory reporting.

See what a professional incident evidence pack looks like

Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.