1. Scope
This guidance provides recommended cyber incident reporting procedures for organisations of all sizes. It draws on publicly available frameworks from the NCSC and industry best practice.
Following these procedures is voluntary. However, timely reporting of incidents helps the wider community by enabling trend analysis, early warning and the sharing of indicators of compromise.
2. Suggested reporting thresholds
SUVAT recommends that organisations report cyber security incidents that meet one or more of the following thresholds:
- Unauthorised access to, or exfiltration of, sensitive data.
- Compromise of privileged accounts (administrator, root, service accounts with elevated permissions).
- Deployment of malware, ransomware or other destructive tools within the organisation's network.
- Denial of service attacks that materially disrupt organisational services.
- Compromise of the organisation's supply chain where sensitive data or systems are at risk.
- Any incident that may attract media or public interest.
- Any incident that could affect the availability or integrity of critical services.
- Loss or theft of devices containing sensitive data where encryption status is uncertain or known to be absent.
3. Severity classification
Incidents should be classified using the following suggested severity levels. The initial classification should be based on the best available information at the time of reporting and may be revised as the incident evolves.
| Severity | Description | Examples | Reporting timeline |
|---|---|---|---|
| P1 — Critical | Organisation-wide cyber emergency with actual or imminent impact on essential services or safety. | Widespread ransomware affecting multiple systems; compromise of highly sensitive data; attack on critical services. | Immediately (within 1 hour of detection) |
| P2 — Severe | Significant compromise with actual or likely impact on the confidentiality, integrity or availability of organisational services or data. | Ransomware affecting a major system; confirmed exfiltration of sensitive data; compromise of senior staff accounts. | Within 4 hours of detection |
| P3 — Substantial | Compromise or attempted compromise that requires active investigation and remediation but does not currently threaten the availability of critical services. | Phishing campaign successfully compromising multiple user accounts; malware detected on endpoint devices; brute-force attack breaching a non-critical system. | Within 24 hours of detection |
| P4 — Moderate | Low-impact incident that is contained and does not pose an ongoing threat but should be reported for situational awareness. | Isolated phishing email successfully blocked; single compromised user account promptly remediated; vulnerability scan detecting a misconfiguration. | Within 72 hours of detection |
4. Reporting timeline
4.1 Initial notification
The initial notification should be submitted within the timeline suggested for the incident's severity level (see table above). This notification should contain the best information available at the time — organisations should not delay reporting to gather additional detail.
4.2 Preliminary report
A preliminary incident report should be prepared within 72 hours of the initial notification. This report should provide a more detailed assessment of the incident, including updated scope, impact analysis and actions taken.
4.3 Ongoing updates
For P1 and P2 incidents, SUVAT recommends providing situation updates at least every 4 hours until the incident is resolved or downgraded. For P3 incidents, daily updates are suggested.
4.4 Closure report
A formal closure report should be prepared within 30 days of the incident being resolved. This report should include a root cause analysis, full timeline, impact assessment and details of remedial actions taken or planned.
5. Where to report incidents
The following organisations accept cyber incident reports:
| Recipient | When to report |
|---|---|
| SUVAT | Reports of spam, phishing, malware or other suspicious digital activity for research and analytical purposes |
| NCSC | Significant cyber incidents affecting UK organisations |
| Action Fraud | Incidents involving fraud or cybercrime |
| Information Commissioner's Office | Incidents involving a personal data breach reportable under UK GDPR |
| Your local police force | If a crime is in progress or has been committed |
6. SUVAT contact details
Email: reports@suvat.uk
Web: suvat.uk/report
Reports submitted to SUVAT are reviewed for research and analytical purposes only. SUVAT does not conduct criminal investigations and does not provide emergency response services.
7. Information useful in a report
When reporting an incident, the following information is most useful for analysis:
- Reporting organisation and contact details of the person reporting.
- Date and time the incident was detected, and estimated date and time of initial compromise if different.
- Suggested severity classification (P1–P4).
- Description of the incident — what happened, how it was detected and what is currently known.
- Systems affected — number and type of systems, whether they are internet-facing.
- Data impact — whether data has been accessed, modified, exfiltrated or encrypted.
- Containment actions taken or in progress.
- Business impact — which services are affected, estimated time to recovery.
- Indicators of compromise (IOCs) — IP addresses, domain names, file hashes, email addresses, malware families or any other technical indicators.
- Third-party involvement — whether any suppliers or external parties are involved or affected.
8. Testing your procedures
Organisations should test their incident reporting procedures at least annually through tabletop exercises or simulations. SUVAT publishes scenario-based exercises that organisations can use to test their reporting and response capabilities.