Security builder & leader

How to Write Good Incident Response Reports

Writing effective incident response reports is essential for communicating critical details, instilling confidence, and facilitating organizational learning. A good report should be concise, empathetic to the reader's needs, and clearly answer what happened, why it happened, and what actions were taken to transform technical details into actionable business insights.

Creating an informative and readable report is among the many challenges of responding to cybersecurity incidents. A good report not only answers its reader’s questions but also instills confidence in the response and enables the organization to learn from the incident. This blog highlights my advice on writing such incident reports. It’s based on the presentation I delivered at the RSA Conference, which offers more details and is available to you on YouTube.

What Do Incident Report Readers Want to Know

Though you probably have your own objective for the incident report, write it with your readers in mind, addressing the questions they want the report to answer in a way that’s easy to absorb. In general, people want to know the following about a cybersecurity incident:

Each of these high-level questions conceals other questions—too many to list in this blog post. For more details, see the Report Template for Incident Response, which I created with input from colleagues. This template not only helps you capture the right information in the report but also provides a convenient way for structuring it so the readers can easily find the details they need.

To demonstrate how you can use the template, I created a simplistic report based on a fictional cybersecurity incident. Download it and take a look.

Sometimes, your reports might be as brief as this example. Sometimes, depending on the expectations of your readers, they’ll be longer and offer more details.

Key Elements of Writing

Having the right information in the report is important, but that’s not the only consideration for good writing. As I discuss in the short course I teach at SANS on this topic, good writing incorporates all five of the elements below:

When you combine these elements, your writing benefits your readers and lets you shine as the author of valuable content.

Additional Considerations for Good Reports

Watch the video of my presentation on this topic to discover additional details, including the following key considerations for good reports:

Learning Resources for Better Cybersecurity Writing

Here are more free resources I created to help people improve their cybersecurity writing skills:

About the Author

Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. As CISO at Axonius, he leads the security and IT program, focusing on trust and growth. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a popular Linux toolkit for malware analysis. Lenny shares his perspectives on security leadership and technology at zeltser.com.

Learn more →