Cybersecurity Incident Response Checklist: Capture Facts, Decisions and Evidence
Use this cybersecurity incident response checklist to coordinate triage, containment, evidence, communications, recovery and follow-up with accountable human decisions.
On this page +
- Establish command and a secure record
- Copy this cybersecurity incident response checklist
- Triage scope, impact and urgency
- Preserve evidence before it disappears
- Choose containment with explicit tradeoffs
- Investigate cause without overclaiming
- Coordinate communications and notifications
- Eradicate and recover through controlled steps
- Capture the response responsibly
- Close only with accepted evidence
- Run the final incident QA check
A cybersecurity incident response checklist creates order when evidence is incomplete and pressure is high. It should protect people and systems, preserve decision quality and make every consequential action traceable.
Use your approved incident response plan and technical playbooks as the authority. This checklist is a coordination aid, not legal advice, forensic instruction or permission to access, contain or modify systems beyond your role.
Establish command and a secure record
Open the authorized incident record and assign an incident lead. Record the start time, reporter, affected services, initial indicators and current user or business impact. Create a secure communication channel appropriate to the suspected compromise; do not assume normal email or chat is safe.
Assign leads for technical response, evidence, business continuity and communications as needed. Name a decision authority and a scribe. Keep one timeline rather than allowing contradictory copies to spread across personal documents.
Set a predictable update cadence and a route for urgent decisions between updates. Keep the active response group small enough to work, while giving leadership and affected service owners a separate briefing rhythm. This reduces repeated status requests and helps responders focus. Record attendance only where useful; the incident record should emphasize facts, actions and authority rather than meeting volume.
State what is known, inferred and unknown. Early confidence should be provisional. A disciplined “unknown, owner investigating by 14:00 UTC” is more useful than an unsupported conclusion.
Copy this cybersecurity incident response checklist
CYBERSECURITY INCIDENT RESPONSE
Incident ID / start time / timezone:
Incident lead / decision authority / scribe:
Secure coordination channel:
REPORT AND TRIAGE
[ ] Record reporter, indicators, systems and observed impact.
[ ] Confirm safe communication and evidence locations.
[ ] Assign severity provisionally under the approved model.
[ ] Identify required security, IT, business and specialist roles.
PRESERVE AND CONTAIN
[ ] Preserve relevant logs, timestamps and source context.
[ ] Record chain of custody where required.
[ ] Evaluate containment options, impact and authorization.
[ ] Log every action, actor, time, result and rollback path.
ERADICATE AND RECOVER
[ ] Define verified cause or bounded working hypothesis.
[ ] Remove persistence or exposure through approved procedures.
[ ] Restore from trusted sources and validate critical journeys.
[ ] Monitor for recurrence and reconcile affected data or work.
COMMUNICATE AND CLOSE
[ ] Route notification decisions for qualified review.
[ ] Update stakeholders with confirmed facts and uncertainty.
[ ] Obtain technical and business acceptance of recovery.
[ ] Assign remediation, evidence, owner and retest date.
Do not mark an item complete merely because someone discussed it. Link the evidence or decision record.
Triage scope, impact and urgency
Validate the initial report without requiring perfect proof. Identify affected identities, endpoints, applications, data, locations and third parties. Check whether critical services, safety, finances or sensitive information may be affected.
Ask which assets are not visible. Inventory gaps, missing endpoint coverage, disabled logs and unmanaged identities can materially change scope. Treat absent telemetry as uncertainty, not negative evidence. Assign an owner to preserve remaining sources before retention windows expire, and document any period for which reliable evidence cannot be recovered.
Assign severity using the organization’s defined criteria. Avoid both premature reassurance and automatic worst-case language. Update severity as evidence changes and preserve the rationale for each change.
Look for related indicators while respecting authorization boundaries. A symptom in one endpoint may reflect a broader identity or supplier compromise. Conversely, a widespread alert may be a detection error. State the next test that distinguishes those possibilities.
Preserve evidence before it disappears
Capture logs, alerts, screenshots, commands, file metadata, system time context and witness reports according to the forensic and retention process. Record who collected each item, when, from where, using which method and where it is stored.
Do not casually reboot, delete files, run cleanup tools or browse suspicious content. Those actions can destroy evidence or increase exposure. If immediate containment is necessary, record the reason, authority and expected evidentiary effect.
Use the event incident report template for clear fact-and-impact structure, while retaining technical artifacts in the controlled security system.
Choose containment with explicit tradeoffs
Containment options may include isolating hosts, disabling credentials, blocking indicators, restricting integrations, stopping services or segmenting networks. For each option, assess security benefit, operational impact, evidence effect, reversibility and authority.
Distinguish short-term containment from durable remediation. A block rule may reduce immediate exposure without removing persistence. Record temporary controls, expiration, monitoring and the trigger for broader action.
Use a decision log template for material choices. The log should show alternatives considered, evidence, accountable decision maker and review point—not only the selected action.
Investigate cause without overclaiming
Build a timeline from corroborated evidence. Separate initial access, execution, persistence, privilege change, movement, collection, exfiltration and impact where relevant. Absence of an alert is not proof that an action did not occur, especially when logging is incomplete.
Label hypotheses and confidence. Ask what evidence would disprove the leading explanation. Bring in qualified forensic or specialist support according to plan, contract and insurance requirements.
Avoid attributing an attacker publicly based on weak indicators. Technical similarities, infrastructure and claims can be misleading. Attribution and legal conclusions require appropriate expertise and authority.
Coordinate communications and notifications
Maintain a stakeholder map: employees, leaders, customers, partners, suppliers, insurers, law enforcement and regulators as applicable. State who owns each communication, approval route, channel and next update time.
Coordinate inbound questions as well as outbound statements. Give support, sales and frontline teams a reviewed response, escalation route and correction process. Preserve material customer reports because they may reveal scope, but do not ask frontline staff to conduct technical investigation. Track which audience received which version and when so later corrections reach the same recipients.
Messages should distinguish confirmed facts, current impact, actions underway, safe user steps and unknowns. Do not speculate about cause, data exposure or recovery time. Keep internal technical detail restricted to those who need it.
Notification duties vary by jurisdiction, contract, sector and facts. Route decisions promptly to qualified legal, privacy, regulatory and communications owners. The incident team supplies evidence; it should not invent a universal notification rule.
Eradicate and recover through controlled steps
Define what must be removed or corrected before restoration: compromised credentials, persistence, vulnerable configuration, malicious artifacts or exposed keys. Use approved rebuild and restore procedures from trusted sources. Record exceptions and residual uncertainty.
Validate security controls and critical business journeys. Reconcile delayed, missing or duplicated transactions. Increase monitoring for recurrence and define rollback criteria. Technical availability alone does not establish safe business recovery.
The equipment commissioning checklist illustrates evidence-based acceptance; apply the same principle through system-specific security and recovery runbooks.
Capture the response responsibly
Incident calls can contain credentials, personal data, attack details and privileged discussion. Record only when authorized and necessary, with clear notice, appropriate consent, restricted access and retention. Keep secrets and unnecessary personal information out of general notes.
For an authorized incident coordination call with visible, consented capture, Kuno can help create a draft timeline, decisions and actions for human review. Security owners must verify facts and keep sensitive evidence in approved systems. Explore Kuno
The meeting recording retention policy guide can help frame lifecycle controls, but incident evidence may require stricter, case-specific handling.
Close only with accepted evidence
Define closure criteria early: containment confirmed, recovery validated, monitoring stable, required communications completed, evidence secured, residual risk accepted and follow-up owned. Name the technical and business approvers.
Plan evidence retention and access review before the response team disbands. Remove temporary accounts, emergency permissions, shared links and response infrastructure that are no longer required. Preserve materials subject to investigation, contractual or legal holds through the authorized process. Ordinary cleanup must not destroy evidence that another accountable function has instructed the organization to retain.
Hold a blameless, evidence-based review. Identify control gaps, decision delays, missing telemetry and successful practices. The meeting follow-up guide can help distribute a reviewed action record without duplicating the restricted case file.
Do not close remediation because a ticket was created. Require completion evidence and a retest date. Track longer-term risk through the appropriate governance process.
Run the final incident QA check
Before closing or handing off, confirm:
- One incident lead and secure record are established.
- Facts, hypotheses and unknowns are distinguishable.
- Severity reflects current evidence and defined criteria.
- Evidence sources, timestamps and handling are recorded.
- Containment actions include authority, impact and rollback.
- Investigation conclusions state confidence and limitations.
- Sensitive communications use approved channels.
- Notification decisions received qualified review.
- Recovery includes security and business validation.
- Enhanced monitoring and recurrence triggers are defined.
- Residual risk has an accountable acceptance owner.
- Remediation has evidence requirements and retest dates.
Create a reviewable response record without automating judgment. Kuno supports authorized capture and draft organization; accountable responders authorize actions, validate evidence and own every conclusion. See Kuno