
When an incident hits, the last thing you want is to invent a reporting format. This battle-tested template, adopted by the Multinational Industrial Security Working Group, captures everything you need to document, triage, and escalate in the first hours. Grab it before you need it.


What's inside?
Two checklists in one, across 15 device and infrastructure types:
The reporter and organization details - who's reporting, from where, and who else is affected.
The incident details - date, time, location, summary, classification level, systems and data compromised, injury and impact levels, duration, and mitigation status.
The technical classification - CND incident types (malware, known CVE exploit, DoS, access violation, user error), source-of-attack fields (IP, port, protocol, URL, malware), and systems affected (zone, OS, application, services).
What you’ll learn
By the end, you'll be able to:
Document an incident with the exact fields regulators, insurers, and boards want to see filled in.
Triage what type of incident you're actually dealing with instead of guessing.
Standardize incident reporting across teams, vendors, and geographies so nothing gets lost in translation.
Capture mitigation, follow-up, and authority-notification status in one place, so nothing falls through when leadership asks.
Adopt a defensible reporting format on day one, without building one from scratch mid-crisis.
Adopted by the Multinational Industrial Security Working Group, the same body that sets reporting standards for contractors handling classified information across allied governments.
Who’s this for?
Read this if you're a…
CISO or Head of Security building an incident response program and need a defensible reporting format.
IR lead or SOC manager who's tired of every incident write-up looking different.
IT lead at a smaller org who'll be the one filling incident reports and wants a form that already knows what to ask.