Short answer: A useful security incident report distinguishes what the writer observed, what another person reported and what remains uncertain. It records a clear sequence and the action taken without turning an assumption into an allegation.
The reader may not have been on site. They need enough reliable information to make the next decision, not dramatic language or a confident explanation that the evidence does not support.
Start with the purpose of the report
Record the incident reference, report author, relevant date and the broad circumstances. Follow the organisation’s approved reporting process and share the report only with the people who need it. Detailed site arrangements belong in restricted records.
Separate the event time from the time it was reported or entered into the system. If a time is approximate, say so. Where a device clock or another record is used, identify the source and note any known uncertainty rather than inventing precision.
Use three clear kinds of information
Observation: something the writer directly saw, heard or did. Describe it plainly. Account: information supplied by someone else, attributed to its source. Assessment: a conclusion or possibility based on the available information, clearly marked as such.
A fictional example shows the distinction. “I found the store-room door open” is an observation. “The supervisor said it had been secured earlier” is an account. “The opening may have occurred after that check” is an assessment that still needs investigation.
Avoid labels such as “thief”, “intruder” or “employee responsible” when identity or intent has not been established. Describe the relevant conduct and the information available. This helps a manager evaluate the event without being pushed towards an unsupported conclusion.
Build a timeline that can be followed
Put material events and actions in sequence. Record who was contacted, when, what instruction was received and what happened next. If an instruction was not received, record the attempt and the subsequent escalation rather than implying approval.
- What prompted the report?
- What did the reporting officer personally observe?
- Which facts came from another source?
- What immediate action was taken and by whose authority?
- Which questions or actions remain open?
A timeline does not need every routine movement. Include information that explains the incident and the response. A concise report with a clear unresolved question is more useful than a long account that buries it.
Handle personal information carefully
The ICO’s accuracy guidance explains the importance of making the source and status of personal information clear, including matters of opinion. Its data-minimisation guidance supports collecting only information needed for the purpose.
Use relevant identifiers through the approved process. Do not add unrelated medical details, speculation about personal circumstances or copied identity documents simply to make the file look complete. Keep any sensitive supporting material under appropriate access controls.
Reference evidence without circulating it casually
Identify where authorised people can find relevant photographs, access records or footage. Keep the original material under the site’s evidence-handling arrangements and avoid putting incident clips in personal messaging groups.
If new information changes the account, add a traceable correction or clarification through the approved system. Do not silently rewrite a historical report so that it looks as if the writer knew the later facts from the beginning.
End with ownership of the next step
State what has been completed, what requires a decision and who owns that decision. A supervisor’s review should check clarity and missing information, not add an invented explanation. Use fictional examples for report-writing exercises.
For help discussing reporting expectations within a guarding brief, explore ZimCos Security’s services or send an enquiry. This is general operational guidance; individual privacy and disclosure decisions should follow current guidance and the organisation’s procedures.
Featured image: an illustrative security officer, not a photograph of an incident.