Incidents
Record and manage security and data incidents from detection through to closure — track severity, build a timeline, link the assets, risks and vendors involved, and manage GDPR breach-notification deadlines.
Overview
The Incidents module is your incident register: a structured record of security and data incidents, from the moment one is detected through investigation, containment, resolution and closure. Each incident captures what happened, how severe it was, who owns the response, and everything it touched: the assets, risks, vendors, controls and treatment actions involved.
Incidents also handle personal-data breaches: flag one and devguard tracks the GDPR Article 33 notification deadline for you, so the 72-hour clock is never missed.
Lifecycle
An incident moves through five statuses. You set the status as the response progresses; the timestamps below are captured to give you an accurate record.
| Status | Meaning |
|---|---|
Open | Logged, response not yet started |
Investigating | Being actively investigated |
Contained | The immediate threat is contained |
Resolved | Fully resolved; resolvedAt is recorded |
Closed | Reviewed and closed; closedAt is recorded |
Incident fields
| Field | Description | Example |
|---|---|---|
Name | The name of the incident (required) | Phishing compromise of finance mailbox |
Owner | Business role responsible for the response (required) | Security Team |
Severity | How serious the incident is | Low, Medium, High, Critical |
Status | Where the incident is in its lifecycle | Investigating |
Threat class | The category of threat, if known | Unauthorized access |
Description | What happened | A finance user entered credentials on a spoofed login page… |
Occurred at | When the incident actually happened | 2026-02-03 14:20 |
Detected at | When you became aware of it (defaults to now) | 2026-02-04 09:10 |
Root cause | The underlying cause, filled in during investigation | Missing MFA on the mailbox |
Lessons learned | What you would do differently, captured at closure | Enforce MFA on all mailboxes |
Labels | Free-form tags to group and filter incidents | PII, Q1-initiative |
Severity
Severity ranges from Low to Critical and reflects the impact of the incident on your organisation. Use it to prioritise the response and to filter the incident list to what matters most.
Timeline
The Timeline tab is the running log of what happened and when. Add an entry for each meaningful step, such as detection, actions taken, findings and decisions, each with its own time and note. Together the entries form the chronological narrative you can hand to an auditor or regulator.
Data-breach notifications
When an incident is a personal-data breach, turn on This is a personal-data breach. devguard then anchors the clock at Detected at and derives the GDPR Article 33 notification deadline automatically, 72 hours from detection. You can override the deadline manually if your circumstances differ.
Record your progress against the obligation:
| Field | Description |
|---|---|
Notification deadline | When the supervisory authority must be notified (auto-derived, or set manually) |
Authority notified at | When you notified the supervisory authority |
Data subjects notified at | When you notified the affected individuals |
Notification notes | Context on the notifications made |
The notification deadline appears in Deadlines so an approaching breach-notification obligation surfaces alongside your other due dates. Turning the breach flag off clears the deadline.
Related data
An incident rarely stands alone. Link the things it involved so the impact is traceable:
- Assets affected by the incident
- Risks the incident realised or relates to
- Vendors involved, when a third party is a factor
- Controls that failed or are relevant
- Treatment actions, the remediation work tracked to closure
These links are visible from the incident and from the related entity, so you can see an asset's or vendor's incident history in one place.
Evidence
Attach proof to an incident from its Evidence tab: forensic reports, notification records, screenshots, or any artefact that documents the incident and your response. This keeps the supporting material with the record for audits and regulatory enquiries.
Tasks
Each incident's detail view has a Tasks tab for the follow-up work it generates: the containment step someone still owes, the post-incident review, the fix that has to land before you can close it. Use Add task and it is attached to the incident automatically. These tasks appear in the central Tasks worklist and, with a deadline, on the Roadmap.
History
Every change to an incident is recorded in the History tab and the organisation-wide audit log, giving you a complete, attributable trail of who changed what and when.
Comments
Every incident's detail view has a Comments tab for discussing it in place, so the reasoning behind a decision stays attached to the record instead of living in a chat thread nobody can find later. Comments complement the Timeline: the timeline records what happened and when, while the comments capture the discussion around it.
Write a comment with light formatting (bold, italic, underline, lists), reply to any comment (replies cannot be nested further), and edit or delete your own. Deleting a comment that has replies leaves a placeholder so the conversation still reads in order.
Type @ to mention a colleague. They are notified in the app and by email, and can adjust how often they hear about comments under Account → Notifications.
How is this guide?
Security Questionnaires
Answer the security questionnaires your customers send you. Upload, review and export them, while every approved answer grows a reusable answer library so the next questionnaire is faster.
Tasks
Tasks are the concrete units of work that move your compliance program forward. Track what needs to be done, who owns it, and when it is due across every framework, control, and record.