Incidents
Record and manage security and data incidents from detection through to closure — track severity, build a timeline, link the assets, risks and vendors involved, and manage GDPR breach-notification deadlines.
Overview
The Incidents module is your incident register: a structured record of security and data incidents, from the moment one is detected through investigation, containment, resolution and closure. Each incident captures what happened, how severe it was, who owns the response, and everything it touched: the assets, risks, vendors, controls and treatment actions involved.
Incidents also handle personal-data breaches: flag one and devguard tracks the GDPR Article 33 notification deadline for you, so the 72-hour clock is never missed.
Lifecycle
An incident moves through five statuses. You set the status as the response progresses; the timestamps below are captured to give you an accurate record.
| Status | Meaning |
|---|---|
Open | Logged, response not yet started |
Investigating | Being actively investigated |
Contained | The immediate threat is contained |
Resolved | Fully resolved; resolvedAt is recorded |
Closed | Reviewed and closed; closedAt is recorded |
Incident fields
| Field | Description | Example |
|---|---|---|
Name | The name of the incident (required) | Phishing compromise of finance mailbox |
Owner | Business role responsible for the response (required) | Security Team |
Severity | How serious the incident is | Low, Medium, High, Critical |
Status | Where the incident is in its lifecycle | Investigating |
Threat class | The category of threat, if known | Unauthorized access |
Description | What happened | A finance user entered credentials on a spoofed login page… |
Occurred at | When the incident actually happened | 2026-02-03 14:20 |
Detected at | When you became aware of it (defaults to now) | 2026-02-04 09:10 |
Root cause | The underlying cause, filled in during investigation | Missing MFA on the mailbox |
Lessons learned | What you would do differently, captured at closure | Enforce MFA on all mailboxes |
Labels | Free-form tags to group and filter incidents | PII, Q1-initiative |
Severity
Severity ranges from Low to Critical and reflects the impact of the incident on your organisation. Use it to prioritise the response and to filter the incident list to what matters most.
Timeline
The Timeline tab is the running log of what happened and when. Add an entry for each meaningful step, such as detection, actions taken, findings and decisions, each with its own time and note. Together the entries form the chronological narrative you can hand to an auditor or regulator.
Data-breach notifications
When an incident is a personal-data breach, turn on This is a personal-data breach. devguard then anchors the clock at Detected at and derives the GDPR Article 33 notification deadline automatically, 72 hours from detection. You can override the deadline manually if your circumstances differ.
Record your progress against the obligation:
| Field | Description |
|---|---|
Notification deadline | When the supervisory authority must be notified (auto-derived, or set manually) |
Authority notified at | When you notified the supervisory authority |
Data subjects notified at | When you notified the affected individuals |
Notification notes | Context on the notifications made |
The notification deadline appears in Deadlines so an approaching breach-notification obligation surfaces alongside your other due dates. Turning the breach flag off clears the deadline.
Related data
An incident rarely stands alone. Link the things it involved so the impact is traceable:
- Assets affected by the incident
- Risks the incident realised or relates to
- Vendors involved, when a third party is a factor
- Controls that failed or are relevant
- Treatment actions, the remediation work tracked to closure
These links are visible from the incident and from the related entity, so you can see an asset's or vendor's incident history in one place.
Evidence
Attach proof to an incident from its Evidence tab: forensic reports, notification records, screenshots, or any artefact that documents the incident and your response. This keeps the supporting material with the record for audits and regulatory enquiries.
History
Every change to an incident is recorded in the History tab and the organisation-wide audit log, giving you a complete, attributable trail of who changed what and when.
How is this guide?
Security Questionnaires
Answer the security questionnaires your customers send you. Upload, review and export them, while every approved answer grows a reusable answer library so the next questionnaire is faster.
Tasks
Tasks are the concrete units of work that move your compliance program forward. Track what needs to be done, who owns it, and when it is due across every framework, control, and record.