Skip to main content

Generating Incident Reports

Export incident timelines as PDF reports for regulators and auditors.

CrownSync Playbooks can generate comprehensive incident reports as signed PDF documents. These reports compile the complete incident record into a structured format suitable for regulators, auditors, insurers, and board-level stakeholders.

What Is Included in an Incident Report

Each incident report PDF contains the following sections:

  • Executive summary— A high-level overview of the incident including type, severity, duration, impact, and current status. This section is designed for senior leadership and non-technical stakeholders.
  • Incident details— The formal incident record including declaration time, detection time, assigned playbook, incident lead, and severity level.
  • Complete timeline— Every logged action in chronological order, including timestamps, performers, descriptions, and key decision indicators.
  • Key decisions summary— A dedicated section listing all actions flagged as key decisions, providing a quick reference to the critical judgement calls made during the response.
  • Phase progression— A visual summary showing when each phase was entered and the duration spent in each phase.
  • Regulatory notifications— A record of all regulatory notifications sent, including the regulator, submission time, reference number, and content summary.
  • Evidence index— A catalogue of all evidence attachments with file names, descriptions, upload times, and the timeline entries they are associated with.
  • Root cause analysis— If the incident has been closed with a root cause recorded, this section presents the findings.
  • Lessons learned and improvement actions— Post-incident review outcomes and tracked improvement actions with owners and deadlines.

Generating a Report

To generate an incident report:

  1. Open the incident from the incidents list
  2. Click Generate Report in the incident toolbar
  3. Select the report scope — full report or summary only
  4. Review the preview to confirm all expected content is present
  5. Click Generate PDF to produce the signed document

Reports can be generated at any time during or after the incident. Generating a report for an active incident captures the current state — you can generate updated reports as the response progresses.

Report versioning

Each generated report receives a unique verification ID and is logged in the audit trail. If you generate multiple reports for the same incident (for example, interim reports during the response and a final report after closure), each is independently verifiable and timestamped.

Sharing with Regulators

Incident reports are designed to meet the documentation standards expected by UK regulators:

  • The ICO expects organisations to demonstrate that they responded promptly and effectively to a breach. The timeline and key decisions sections directly address this requirement.
  • FCA-regulated firms can use the report as supporting documentation alongside their formal FCA notification submission.
  • Insurers often require detailed incident documentation when processing cyber insurance claims. The report provides the structured evidence they need.

Reports include classification markings and watermarks consistent with your PDF branding settings, ensuring they are handled appropriately when shared externally.

Report Security

Incident reports contain sensitive information about your organisation's security posture and vulnerabilities. The generated PDF includes:

  • A watermark with your organisation name and generation date
  • Classification markings (OFFICIAL or OFFICIAL-SENSITIVE) in headers and footers
  • A verification QR code and URL for authenticity checking
  • An IP notice prohibiting redistribution without authorisation

Share incident reports only with authorised recipients and through secure channels. The audit log records who generated each report, providing accountability for document distribution.

Was this page helpful?