| Incident intake and severity record | Establish known facts, affected systems, possible impacts, urgency, and escalation level | Structured incident record | Initial report, system owner, business context | May change as evidence develops |
| Evidence register and timeline | Track logs, versions, changes, communications, decisions, and gaps | Controlled working register | Access to technical and operational evidence | Not a substitute for formal forensic chain of custody |
| Containment and decision plan | Compare immediate actions, dependencies, reversibility, and residual exposure | Action plan and decision log | Accountable decision-makers and fallback options | Client approves operational actions |
| Investigation findings | Explain observed failure, affected pathways, contributing factors, and uncertainty | Findings report and technical appendix | SMEs, vendors, architecture, test evidence | Conclusions depend on evidence quality |
| Impact and risk assessment | Assess affected people, services, data, obligations, and business consequences | Impact matrix and executive summary | Legal, privacy, security, risk, and business input | Does not provide legal advice |
| Remediation and recovery plan | Define corrective actions, owners, validation, recovery gates, and residual risks | Prioritised backlog and recovery checklist | Technical feasibility, budgets, owners | Implementation may require separate scope |
| Lessons-learned and control-improvement pack | Strengthen playbooks, monitoring, testing, governance, training, and reporting | Workshop pack and improvement roadmap | Stakeholder participation and policy context | Benefits depend on adoption and ownership |