Core workflows6 min readUpdated May 2026
Open an incident
- 1Open Breach Notification.
- 2Create a new incident.
- 3Record what happened, when it was discovered, and who is handling it.
- 4Add affected data categories and estimated subject count.
Work the timeline
Keep the timeline current as facts change. Add containment actions, investigation notes, notification decisions, and final post-incident lessons.
Before closing
- 1Confirm affected systems are contained.
- 2Attach supporting evidence.
- 3Record notification decisions.
- 4Complete the post-incident review.