Skip to main content

Using the Incident Timeline

Real-time chronological logging of actions and key decisions.

The incident timeline is the central record of everything that happens during an incident response. It provides a real-time, chronological log of actions taken, decisions made, and phase transitions. A well-maintained timeline is essential for regulatory compliance, post-incident review, and audit evidence.

The Timeline View

When you open an active incident, the timeline is displayed as a vertical sequence of entries, with the most recent entry at the top. Each entry appears as a card on the timeline and includes:

  • A timestamp showing when the action occurred
  • The name of the person who performed or logged the action
  • A description of what was done
  • Any attached evidence or notes
  • Badges indicating whether the entry is a key decision, a phase transition, or a routine action

The timeline updates in real time for all team members viewing the incident. When a colleague logs a new action, it appears on your screen without needing to refresh the page.

Logging Actions to the Timeline

To add an entry to the timeline, click the Log Action button at the top of the timeline view. This opens a form where you provide:

  • Description— A clear, factual account of what was done. Use plain language and be specific. For example, “Disabled compromised user account [email protected] in Azure AD” is better than “Disabled account”.
  • Timestamp— Defaults to the current time, but can be backdated if you are recording an action that happened earlier. See logging actions for details.
  • Performed by— Defaults to your name, but can be changed if you are logging an action taken by someone else.
  • Key decision flag— Toggle this on if the action represents a significant decision (e.g., deciding to take systems offline, choosing to notify the ICO).

Log as you go

During an active incident, log actions as they happen rather than writing them up afterwards. Real-time logging provides the most accurate timeline and ensures nothing is forgotten in the pressure of a response. Even brief entries are valuable.

Key Decisions

Certain actions during an incident carry particular significance — they represent judgement calls that affected the course of the response. Flagging these as key decisions makes them stand out in the timeline with a distinct visual indicator and ensures they are highlighted in incident reports.

Examples of key decisions include:

  • Deciding to isolate a system or network segment
  • Authorising a regulatory notification
  • Choosing to engage external forensic investigators
  • Deciding to invoke business continuity plans
  • Approving communication to affected data subjects
  • Escalating the incident severity level

Key decisions are surfaced prominently in incident reports and during post-incident reviews.

Phase Transitions

The timeline automatically records phase transitions when the incident lead moves the response from one phase to the next (e.g., from Containment to Eradication). Phase transition entries are displayed with a distinctive banner in the timeline, making it clear when the response strategy shifted.

To transition to the next phase, click the Advance Phase button in the incident toolbar. You will be prompted to confirm the transition and optionally add a note explaining why the response is moving forward.

Filtering the Timeline

For longer incidents, the timeline can contain dozens or hundreds of entries. Use the filter controls above the timeline to narrow the view:

  • By phase — Show only entries from a specific response phase
  • By person — Show only entries logged by a specific team member
  • Key decisions only — Filter to show only flagged key decisions
  • Date range — Show entries within a specific time window

Filters do not modify the underlying data — they only change what is displayed. The complete timeline is always preserved and available for export.

Exporting the Timeline

The incident timeline can be exported as part of a full incident report. The exported timeline includes all entries, key decision flags, phase transitions, and attached evidence references. This is particularly valuable when providing evidence to regulators, insurers, or during legal proceedings.

Was this page helpful?