Cyber incident reporting: recommended procedures for organisations

Recommended procedures for reporting cyber security incidents, including suggested severity classification, notification timelines and the information that is most useful when making a report. This guidance is advisory only.

Advisory guidance. This document provides recommended best practice for organisations developing their incident reporting capabilities. It is based on publicly available frameworks and SUVAT's independent research. SUVAT does not have authority to mandate reporting from any organisation. In case of an active crime, contact your local police force.

1. Scope

This guidance provides recommended cyber incident reporting procedures for organisations of all sizes. It draws on publicly available frameworks from the NCSC and industry best practice.

Following these procedures is voluntary. However, timely reporting of incidents helps the wider community by enabling trend analysis, early warning and the sharing of indicators of compromise.

2. Suggested reporting thresholds

SUVAT recommends that organisations report cyber security incidents that meet one or more of the following thresholds:

  • Unauthorised access to, or exfiltration of, sensitive data.
  • Compromise of privileged accounts (administrator, root, service accounts with elevated permissions).
  • Deployment of malware, ransomware or other destructive tools within the organisation's network.
  • Denial of service attacks that materially disrupt organisational services.
  • Compromise of the organisation's supply chain where sensitive data or systems are at risk.
  • Any incident that may attract media or public interest.
  • Any incident that could affect the availability or integrity of critical services.
  • Loss or theft of devices containing sensitive data where encryption status is uncertain or known to be absent.

3. Severity classification

Incidents should be classified using the following suggested severity levels. The initial classification should be based on the best available information at the time of reporting and may be revised as the incident evolves.

Severity Description Examples Reporting timeline
P1 — Critical Organisation-wide cyber emergency with actual or imminent impact on essential services or safety. Widespread ransomware affecting multiple systems; compromise of highly sensitive data; attack on critical services. Immediately (within 1 hour of detection)
P2 — Severe Significant compromise with actual or likely impact on the confidentiality, integrity or availability of organisational services or data. Ransomware affecting a major system; confirmed exfiltration of sensitive data; compromise of senior staff accounts. Within 4 hours of detection
P3 — Substantial Compromise or attempted compromise that requires active investigation and remediation but does not currently threaten the availability of critical services. Phishing campaign successfully compromising multiple user accounts; malware detected on endpoint devices; brute-force attack breaching a non-critical system. Within 24 hours of detection
P4 — Moderate Low-impact incident that is contained and does not pose an ongoing threat but should be reported for situational awareness. Isolated phishing email successfully blocked; single compromised user account promptly remediated; vulnerability scan detecting a misconfiguration. Within 72 hours of detection

4. Reporting timeline

4.1 Initial notification

The initial notification should be submitted within the timeline suggested for the incident's severity level (see table above). This notification should contain the best information available at the time — organisations should not delay reporting to gather additional detail.

4.2 Preliminary report

A preliminary incident report should be prepared within 72 hours of the initial notification. This report should provide a more detailed assessment of the incident, including updated scope, impact analysis and actions taken.

4.3 Ongoing updates

For P1 and P2 incidents, SUVAT recommends providing situation updates at least every 4 hours until the incident is resolved or downgraded. For P3 incidents, daily updates are suggested.

4.4 Closure report

A formal closure report should be prepared within 30 days of the incident being resolved. This report should include a root cause analysis, full timeline, impact assessment and details of remedial actions taken or planned.

5. Where to report incidents

The following organisations accept cyber incident reports:

Recipient When to report
SUVAT Reports of spam, phishing, malware or other suspicious digital activity for research and analytical purposes
NCSC Significant cyber incidents affecting UK organisations
Action Fraud Incidents involving fraud or cybercrime
Information Commissioner's Office Incidents involving a personal data breach reportable under UK GDPR
Your local police force If a crime is in progress or has been committed

6. SUVAT contact details

SUVAT Research Team
Email: reports@suvat.uk
Web: suvat.uk/report

Reports submitted to SUVAT are reviewed for research and analytical purposes only. SUVAT does not conduct criminal investigations and does not provide emergency response services.

7. Information useful in a report

When reporting an incident, the following information is most useful for analysis:

  1. Reporting organisation and contact details of the person reporting.
  2. Date and time the incident was detected, and estimated date and time of initial compromise if different.
  3. Suggested severity classification (P1–P4).
  4. Description of the incident — what happened, how it was detected and what is currently known.
  5. Systems affected — number and type of systems, whether they are internet-facing.
  6. Data impact — whether data has been accessed, modified, exfiltrated or encrypted.
  7. Containment actions taken or in progress.
  8. Business impact — which services are affected, estimated time to recovery.
  9. Indicators of compromise (IOCs) — IP addresses, domain names, file hashes, email addresses, malware families or any other technical indicators.
  10. Third-party involvement — whether any suppliers or external parties are involved or affected.

8. Testing your procedures

Organisations should test their incident reporting procedures at least annually through tabletop exercises or simulations. SUVAT publishes scenario-based exercises that organisations can use to test their reporting and response capabilities.