The SOC Incident Report Template is the go-to document for security operations teams to capture, analyze, and close incidents with a consistent, auditable format.
What's inside
Incident Overview
Timeline & Events
Affected Assets & Impact
Evidence & Logs
Root Cause Analysis
Containment, Mitigation & Recovery
Stakeholders & Communications
Decision Log
Action Items
How to use this template
Create a new incident record using the fields in Incident Overview.
Gather evidence and fill the Timeline with key events in order.
Contain the incident, apply initial mitigations, and document containment actions.
Perform root cause analysis and document the remediation plan.
Sign off, share with stakeholders, and archive the final report for audit.
Why it works
What makes this template effective?
A consistent structure reduces noise, speeds up containment, and creates a reliable audit trail for post-incident reviews.
How do I customize for different incidents?
Keep placeholders for data you will fill in in real time, and adjust sections based on incident type, severity, and scope.
Can I reuse for audits?
Yes. The evidence & logs table and decision log provide a clear, verifiable record that supports regulatory and leadership reviews.