devguard

Incidents

Record and manage security and data incidents from detection through to closure — track severity, build a timeline, link the assets, risks and vendors involved, and manage GDPR breach-notification deadlines.

Overview

The Incidents module is your incident register: a structured record of security and data incidents, from the moment one is detected through investigation, containment, resolution and closure. Each incident captures what happened, how severe it was, who owns the response, and everything it touched: the assets, risks, vendors, controls and treatment actions involved.

Incidents also handle personal-data breaches: flag one and devguard tracks the GDPR Article 33 notification deadline for you, so the 72-hour clock is never missed.

Lifecycle

An incident moves through five statuses. You set the status as the response progresses; the timestamps below are captured to give you an accurate record.

StatusMeaning
OpenLogged, response not yet started
InvestigatingBeing actively investigated
ContainedThe immediate threat is contained
ResolvedFully resolved; resolvedAt is recorded
ClosedReviewed and closed; closedAt is recorded

Incident fields

FieldDescriptionExample
NameThe name of the incident (required)Phishing compromise of finance mailbox
OwnerBusiness role responsible for the response (required)Security Team
SeverityHow serious the incident isLow, Medium, High, Critical
StatusWhere the incident is in its lifecycleInvestigating
Threat classThe category of threat, if knownUnauthorized access
DescriptionWhat happenedA finance user entered credentials on a spoofed login page…
Occurred atWhen the incident actually happened2026-02-03 14:20
Detected atWhen you became aware of it (defaults to now)2026-02-04 09:10
Root causeThe underlying cause, filled in during investigationMissing MFA on the mailbox
Lessons learnedWhat you would do differently, captured at closureEnforce MFA on all mailboxes
LabelsFree-form tags to group and filter incidentsPII, Q1-initiative

Severity

Severity ranges from Low to Critical and reflects the impact of the incident on your organisation. Use it to prioritise the response and to filter the incident list to what matters most.

Timeline

The Timeline tab is the running log of what happened and when. Add an entry for each meaningful step, such as detection, actions taken, findings and decisions, each with its own time and note. Together the entries form the chronological narrative you can hand to an auditor or regulator.

Data-breach notifications

When an incident is a personal-data breach, turn on This is a personal-data breach. devguard then anchors the clock at Detected at and derives the GDPR Article 33 notification deadline automatically, 72 hours from detection. You can override the deadline manually if your circumstances differ.

Record your progress against the obligation:

FieldDescription
Notification deadlineWhen the supervisory authority must be notified (auto-derived, or set manually)
Authority notified atWhen you notified the supervisory authority
Data subjects notified atWhen you notified the affected individuals
Notification notesContext on the notifications made

The notification deadline appears in Deadlines so an approaching breach-notification obligation surfaces alongside your other due dates. Turning the breach flag off clears the deadline.

An incident rarely stands alone. Link the things it involved so the impact is traceable:

  • Assets affected by the incident
  • Risks the incident realised or relates to
  • Vendors involved, when a third party is a factor
  • Controls that failed or are relevant
  • Treatment actions, the remediation work tracked to closure

These links are visible from the incident and from the related entity, so you can see an asset's or vendor's incident history in one place.

Evidence

Attach proof to an incident from its Evidence tab: forensic reports, notification records, screenshots, or any artefact that documents the incident and your response. This keeps the supporting material with the record for audits and regulatory enquiries.

History

Every change to an incident is recorded in the History tab and the organisation-wide audit log, giving you a complete, attributable trail of who changed what and when.

How is this guide?

On this page