Preparing your learning space...
55% through Projects tutorials
In this project, you will learn how to write a professional cybersecurity incident report. You'll analyze a simulated security incident, document findings, create a timeline, assess impact, and provide remediation recommendations. Incident reporting is a critical skill for any security professional.
The Incident: On June 15, 2026, at approximately 2:30 PM, the BrightPath Education IT team detected unusual network activity. Investigation revealed that an employee's credentials were compromised through a phishing email, leading to unauthorized access to the student database containing 5,000+ records.
Your task is to write a comprehensive incident report documenting this incident.
š” Free Lab Setup: Incident reporting requires no special software ā just documentation tools you already have:
- Google Docs / LibreOffice ā Report writing (free)
- Google Sheets / LibreOffice Calc ā Evidence logs, timelines (free)
- draw.io ā Network/attack flow diagrams (free)
- All templates and checklists are included in this tutorial ā just copy and fill in!
- No paid tools required.
š Your Step-by-Step Task:
- Read the incident scenario ā BrightPath Education data breach (below)
- Study the incident response lifecycle framework
- Review the chain of custody and evidence collection procedures
- Create an incident timeline using the template provided
- Write a technical analysis of the phishing attack
- Perform a "5 Whys" root cause analysis
- Calculate business impact using the cost estimate template
- Write an executive summary (1 page, plain language)
- Complete the full incident report using the sample as a guide
- Complete the deliverables checklist and take the quiz
After completing this project, you will be able to:
Incident Response (IR) is the systematic approach to managing and responding to security incidents. The goal is to handle the situation in a way that limits damage, reduces recovery time and costs, and helps prevent future incidents.
PURPOSE OF INCIDENT REPORTS:
1. Documentation: Record what happened for legal and compliance
2. Analysis: Understand how and why the incident occurred
3. Improvement: Identify gaps and improve defenses
4. Communication: Inform stakeholders at all levels
5. Compliance: Meet regulatory reporting requirements
6. Lessons Learned: Share knowledge to prevent recurrence
7. Legal Protection: Demonstrate due diligence
| Regulation | Reporting Requirement | Deadline |
|---|---|---|
| GDPR | Notify data protection authority | 72 hours |
| HIPAA | Notify affected individuals and HHS | 60 days |
| PCI DSS | Notify card brands | Varies |
| CCPA | Notify affected California residents | Without reasonable delay |
| SEC (public companies) | Report material incidents | 4 business days |
1. EXECUTIVE SUMMARY
āā Brief overview for management (1 page maximum)
2. INCIDENT DETAILS
āā Classification, severity, status, timeline
3. CHRONOLOGY / TIMELINE
āā What happened, when, and in what order
4. TECHNICAL ANALYSIS
āā Detailed technical findings
5. BUSINESS IMPACT
āā Data, financial, operational, reputational impact
6. ROOT CAUSE ANALYSIS
āā Why the incident happened
7. EVIDENCE COLLECTED
āā Chain of custody, evidence types
8. RECOMMENDATIONS
āā Short-term and long-term remediation
9. LESSONS LEARNED
āā What went well, what could improve
10. APPENDICES
āā Logs, screenshots, raw data, references
| Principle | Description | Example |
|---|---|---|
| Factual | State facts, not opinions | "Logs show 15 failed login attempts" not "Attacker tried many times" |
| Objective | Avoid blame language | "The account was compromised" not "The user was careless" |
| Clear | Use plain language, define acronyms | Define "SIEM" on first use |
| Timely | Document as events happen | Record timestamps immediately |
| Complete | Cover all relevant aspects | Don't leave questions unanswered |
| Confidential | Mark appropriately | Include confidentiality notice |
| Verifiable | Include evidence references | Reference log file names and locations |
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
ā PREPARATION ā
ā (Policies, tools, training) ā
āāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāā
ā
āāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāā
ā DETECTION & ANALYSIS ā
ā (Monitor, detect, triage) ā
āāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāā
ā
āāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāā
ā CONTAINMENT, ERADICATION ā
ā & RECOVERY ā
āāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāā
ā
āāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāā
ā POST-INCIDENT ACTIVITY ā
ā (Lessons learned, reporting) ā
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
1. PREPARATION
- IR policy and procedures
- IR team roles defined
- Tools and technologies in place
- Communication plans established
- Training conducted
2. DETECTION & ANALYSIS
- Alert triggered / incident reported
- Initial triage and assessment
- Evidence collection begins
- Scope determination
- Severity classification
3. CONTAINMENT, ERADICATION & RECOVERY
- Short-term containment (isolate affected systems)
- Long-term containment (apply patches, change passwords)
- Eradication (remove malware, close backdoors)
- Recovery (restore from backups, return to production)
4. POST-INCIDENT
- Investigation complete
- Report written
- Lessons learned meeting
- Remediation plan implemented
- Report filed for compliance
| Level | Name | Description | Response Time |
|---|---|---|---|
| 4 | Informational | No impact, potential concern | Report only |
| 3 | Low | Minor impact, single user | 24 hours |
| 2 | Medium | Department-level impact, data exposure risk | 4 hours |
| 1 | High | Organization-wide impact, data breach | 1 hour |
| 0 | Critical | Life safety, existential threat | Immediate |
| Type | Description | Example |
|---|---|---|
| Phishing | Deceptive email to obtain credentials | Fake login page |
| Malware | Malicious software installation | Ransomware |
| Unauthorized Access | Improper system access | Stolen credentials |
| Data Breach | Unauthorized data exfiltration | Customer data stolen |
| DDoS | Service disruption | Site taken offline |
| Insider Threat | Malicious or negligent employee | Data theft |
| Physical Security | Physical access compromise | Server room breach |
| Policy Violation | Violation of security policy | Unauthorized software |
Incident: BrightPath Education Data Breach
Classification: Data Breach / Unauthorized Access
Severity: HIGH (Level 1)
Status: Contained / Under Investigation
Confidentiality: CONFIDENTIAL ā DO NOT DISTRIBUTE
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
CHAIN OF CUSTODY FORM
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
Case Number: IR-2026-001
Incident: Student Database Unauthorized Access
ITEM #1
āāāāāāāā
Description: Export of authentication logs (auth.log)
Source System: DC01.domain.local (Domain Controller)
Date/Time Collected: 2026-06-15 16:45 EDT
Collected By: Jordan Chen (Security Analyst)
Collection Method: Secure copy via winrm ā sha256 verified
Hash (SHA256): a1b2c3d4e5f6...
Storage Location: \\forensic\cases\IR-2026-001\evidence\
Media Type: Network share (encrypted volume)
Transfer History:
āāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāā¬āāāāāāāāāāāāāāāāāāāāāāāāā
ā Date/Time ā From ā To ā
āāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāāāāāāāāā¤
ā 2026-06-15 ā Jordan Chen ā Evidence Locker ā
ā 16:45 ā (Collector) ā (Encrypted Share) ā
āāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāāāāāāāāā¤
ā 2026-06-16 ā Evidence Locker ā Dr. Sarah Williams ā
ā 09:30 ā ā (Lead Investigator) ā
āāāāāāāāāāāāāāāā“āāāāāāāāāāāāāāāāāā“āāāāāāāāāāāāāāāāāāāāāāāāā
Purpose: Analysis of login events during incident timeframe
Intact upon receipt? Yes ā / No ā (If no, explain)
DIGITAL EVIDENCE:
⢠System logs (Windows Event Log, syslog)
⢠Network logs (firewall, proxy, DNS)
⢠Email headers and content
⢠File system artifacts
⢠Memory dumps
⢠Disk images (forensic copies)
⢠Database transaction logs
⢠Application logs
⢠SIEM alerts and correlation data
⢠Packet captures (PCAP)
PHYSICAL EVIDENCE:
⢠Hardware (if seized)
⢠Written notes and documentation
⢠Photographs of physical configuration
DOCUMENTARY EVIDENCE:
⢠Access control lists
⢠User account information
⢠Policy documents
⢠Previous security assessments
⢠Employee records
DO'S:
ā Work from copies, never originals
ā Document every action taken
ā Use write blockers when acquiring drives
ā Verify integrity with hashes (SHA256)
ā Store evidence in secure, access-controlled location
ā Maintain detailed chain of custody
DON'TS:
ā Don't modify original evidence
ā Don't use the suspect system for analysis
ā Don't discuss case details unnecessarily
ā Don't store evidence on unencrypted media
ā Don't let evidence leave custody unattended
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
INCIDENT TIMELINE ā IR-2026-001
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
Date: June 15, 2026
TIME (EDT) | EVENT | SOURCE
āāāāāāāāāāāāāā¼āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā¼āāāāāāāāāāāāā
08:45 ā Phishing email sent to employee jdoe@... ā Email logs
09:12 ā Employee clicked link in phishing email ā Proxy logs
09:13 ā Credentials phished via fake login page ā Web logs
09:15 ā Attacker authenticated as jdoe (first login) ā AD logs
09:15 ā GeoIP: Login from unusual location (RU) ā GeoIP alert
09:30-11:45 ā Attacker enumerated AD, mapped network ā Event logs
11:50 ā Attacker accessed student database (SELECT) ā DB logs
11:50-12:30 ā Data exfiltration: 5,000+ records exported ā FW logs (outbound)
12:35 ā Attacker established persistence (scheduled task)ā Sysmon
13:00 ā Employee reported suspicious email to IT ā Email
13:15 ā IT security team starts investigation ā Log
14:30 ā Alert triggered: Unusual outbound traffic ā SIEM
14:35 ā Incident declared (Level 1 - High) ā IR team
15:00 ā Affected account disabled ā AD logs
15:15 ā Database server isolated from network ā Network team
15:30 ā Containment verified ā Security team
16:00 ā Executive notified ā Email
16:30 ā Evidence collection begins ā Forensics
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
1. Use a SINGLE timezone throughout (EDT/EST or UTC)
2. Include "unknown period" notations where gaps exist
3. Source each event (how do you know this happened)
4. Note confidence level (Confirmed / Likely / Possible)
5. Include both attacker and defender actions
6. Add time between events (dwell time, response time)
7. Reference evidence items in brackets [E-001, E-002]
8. Keep updating as investigation progresses
1. EMAIL ANALYSIS
- Original phishing email headers and body
- Sender domain analysis (SPF, DKIM, DMARC)
- Link destinations (URL analysis)
- Attachment analysis (if any)
2. NETWORK ANALYSIS
- Source IPs and geolocation
- C2 server communications
- Data exfiltration patterns
- Protocols and ports used
- DNS queries made
3. ENDPOINT ANALYSIS
- Compromised user account activity
- Processes executed
- Files created/modified
- Registry changes
- Scheduled tasks/jobs
4. DATABASE ANALYSIS
- Queries executed
- Data accessed
- Export operations
- Authentication attempts
TECHNICAL ANALYSIS REPORT
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
1. PHISHING EMAIL ANALYSIS
āāāāāāāāāāāāāāāāāāāāāāā
Original email received: jdoe@brightpath.edu
From: "IT Support" <support@brightpath-verify.com>
Subject: "Action Required: Verify Your Account"
SPF: Fail (sending IP not authorized)
DKIM: Not signed
DMARC: No policy (p=none)
Sending IP: 203.0.113.45 (hosted in Bulgaria)
Link: https://brightpath-verify.com/login (Typosquatting)
Link domain registered: June 10, 2026 (5 days before attack)
Link domain registrar: GoDaddy (anonymous WHOIS)
2. ATTACKER ACCESS ANALYSIS
āāāāāāāāāāāāāāāāāāāāāāāāā
Initial access: 2026-06-15 09:15 via VPN (203.0.113.50)
VPN IP geolocation: Russia (Moscow)
Protocols used: RDP via jump host
Accounts used: jdoe (compromised), then escalated to svc_admin
Lateral movement: 3 systems accessed between 09:30-11:45
3. DATA ACCESS
āāāāāāāāāāāā
Database: StudentRecords (SQL Server)
Queries: SELECT * FROM Students WHERE GraduationYear >= 2024
Records accessed: 5,247 student records
Data exfiltrated: Confirmed via outbound traffic analysis
Exfiltration method: HTTPS POST to 203.0.113.60
Data size: ~45 MB
4. PERSISTENCE
āāāāāāāāāāāā
Method: Scheduled task created (TaskName: "SystemUpdate")
Runs as: SYSTEM
Interval: Daily at 3:00 AM
Action: PowerShell reverse shell
Artifact: C:\Windows\Tasks\SystemUpdate.ps1 (deleted on containment)
š Educational example ā The dollar figures below are scenario-based estimates for practicing impact assessment. No real costs involved.
| Category | Impact Description | Quantification |
|---|---|---|
| Data Impact | Student PII exposed | 5,247 records |
| Financial Impact | Breach response costs | $180,000 estimated |
| Operational Impact | Database offline for 48 hours | Extended recovery |
| Reputational Impact | Parent/student trust affected | High |
| Legal Impact | Potential FERPA/HIPAA violations | Investigation ongoing |
| Regulatory Impact | State breach notification laws | 60-day notification window |
š” Educational example only ā These are industry-average breach costs used to practice impact assessment. No actual spending is involved.
BREACH COST ESTIMATE
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
Direct Costs:
Incident response team (200 hours @ $150/hr) $30,000
Forensic investigation (external) $25,000
Legal counsel $20,000
Notification costs (5,247 recipients) $15,000
Credit monitoring (12 months) $40,000
Public relations support $15,000
System restoration and hardening $20,000
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
Total Direct Costs $165,000
Indirect Costs:
Productivity loss $25,000
Increased insurance premiums $10,000
Potential regulatory fines $50,000+
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
Total Indirect Costs $85,000+
TOTAL ESTIMATED COST: $250,000+
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
AFFECTED DATA:
āāāāāāāāāāāāāāāāāāāāāāāā¬āāāāāāāāā¬āāāāāāāāāāā
ā Data Field ā Type ā Sensitivity ā
āāāāāāāāāāāāāāāāāāāāāāāā¼āāāāāāāāā¼āāāāāāāāāāā¤
ā Student Name ā PII ā High ā
ā Date of Birth ā PII ā High ā
ā Social Security # ā PII ā Critical ā
ā Home Address ā PII ā High ā
ā Parent/Guardian Name ā PII ā High ā
ā Grade Level ā Educational ā Low ā
ā Enrollment Status ā Educational ā Low ā
ā Medical Info ā PHI ā Critical ā
āāāāāāāāāāāāāāāāāāāāāāāā“āāāāāāāāā“āāāāāāāāāāā
PROBLEM: Student database accessed by unauthorized attacker
WHY 1: Why was the attacker able to access the database?
ā Because the attacker had valid credentials (jdoe's account).
WHY 2: Why did the attacker have jdoe's credentials?
ā Because jdoe entered them on a fake login page.
WHY 3: Why did jdoe fall for the phishing page?
ā Because the email looked legitimate and bypassed spam filter.
WHY 4: Why did the email bypass the spam filter?
ā Because SPF/DMARC wasn't properly configured to reject spoofed emails.
WHY 5: Why wasn't SPF/DMARC properly configured?
ā Because email security configuration wasn't prioritized
during the last infrastructure review.
ROOT CAUSE: Inadequate email security controls (SPF/DMARC)
and lack of MFA allowed a successful phishing attack to
compromise credentials and lead to data breach.
SECURITY GAPS IDENTIFIED:
1. No MFA on user accounts (allows credential-only access)
2. SPF/DMARC not configured for email domain
3. Database accessible from user workstations (no network segmentation)
4. No data exfiltration detection (outbound data monitoring)
5. Insufficient user security awareness (fall victim to sophisticated phishing)
6. No privileged access management (PAM) for database access
7. No alert for unusual geo-location logins
8. Delayed detection (dwell time: ~5 hours before alert)
| # | Action | Priority | Owner | Status |
|---|---|---|---|---|
| 1 | Reset ALL user passwords | Critical | IT Team | ā Complete |
| 2 | Enable MFA for all accounts | Critical | IT Team | ā³ In Progress |
| 3 | Remove persistence mechanisms | Critical | IR Team | ā Complete |
| 4 | Review and revoke unauthorized access | Critical | Security Team | ā Complete |
| 5 | Notify affected individuals (FERPA) | High | Legal | š Planned |
| 6 | Implement geo-blocking for known malicious regions | High | Network Team | ā³ In Progress |
| 7 | Scan entire environment for IOCs | High | IR Team | ā³ In Progress |
| # | Action | Priority | Owner |
|---|---|---|---|
| 1 | Configure SPF, DKIM, and DMARC with reject policy | High | IT Team |
| 2 | Implement network segmentation (database VLAN) | High | Network Team |
| 3 | Deploy DLP solution for data exfiltration detection | High | Security Team |
| 4 | Enhance SIEM rules for geo-anomaly detection | Medium | SOC Team |
| 5 | Conduct organization-wide security awareness training | High | HR/Security |
| 6 | Implement Privileged Access Management (PAM) | Medium | IT Team |
| 7 | Deploy endpoint detection and response (EDR) | High | IT Team |
| # | Action | Priority | Owner |
|---|---|---|---|
| 1 | Adopt Zero Trust architecture | High | Security |
| 2 | Implement SOAR for automated response | Medium | Security |
| 3 | Regular penetration testing (quarterly) | High | External |
| 4 | Bug bounty program | Medium | Security |
| 5 | Cyber insurance review | Medium | Risk/Legal |
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
INCIDENT RESPONSE REPORT ā IR-2026-001
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
CLASSIFICATION: CONFIDENTIAL ā PRIVILEGED
TO: Board of Directors, BrightPath Education
FROM: Security Incident Response Team
DATE: June 22, 2026
SUBJECT: Student Database Unauthorized Access Incident
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
EXECUTIVE SUMMARY
āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
On June 15, 2026, BrightPath Education experienced a security
incident involving unauthorized access to the student database.
The incident was the result of a successful phishing attack that
compromised an employee's credentials.
TIMELINE OVERVIEW:
⢠08:45 ā Phishing email sent
⢠09:15 ā Credentials compromised, attacker gains access
⢠14:30 ā Anomalous activity detected by SIEM
⢠14:35 ā Incident declared
⢠15:30 ā Containment achieved
IMPACT:
⢠5,247 student records accessed (PII including SSN)
⢠Estimated financial impact: $250,000+
⢠No evidence of lateral movement to other systems
⢠No ransomware or malware deployed
ROOT CAUSE:
⢠Inadequate email security (SPF/DMARC not configured)
⢠No multi-factor authentication (MFA)
⢠Lack of network segmentation (database accessible from user LAN)
STATUS: CONTAINED ā All active threats neutralized
REMEDIATION (COMPLETED):
ā All passwords forcibly reset
ā Compromised account disabled
ā Database server isolated and secured
ā Backup verified and clean
ā IOCs shared with threat intelligence partners
RECOMMENDATIONS (PRIORITY):
1. Enable MFA for all accounts ā IMMEDIATE
2. Implement network segmentation ā 30 DAYS
3. Deploy DLP solution ā 60 DAYS
4. Conduct security awareness training ā 30 DAYS
[COMPLETE REPORT ā TABLE OF CONTENTS]
1. Executive Summary ................................... 1
2. Incident Classification ............................ 2
3. Detailed Timeline .................................. 3
4. Technical Analysis ................................. 5
4.1 Phishing Email Analysis
4.2 Network Traffic Analysis
4.3 Endpoint Analysis
4.4 Database Access Analysis
5. Evidence Inventory ................................. 9
6. Chain of Custody .................................. 10
7. Business Impact Assessment ........................ 12
8. Root Cause Analysis ............................... 14
9. Containment Actions ............................... 15
10. Remediation Plan .................................. 16
11. Lessons Learned ................................... 18
12. Recommendations ................................... 19
13. Appendices ........................................ 20
A. Raw Log Data
B. Phishing Email (Full Headers)
C. IOC List (Indicators of Compromise)
D. Regulatory Notification Requirements
E. Communications Log
# INCIDENT REPORT ā QUICK REFERENCE
**Case ID**: IR-YYYY-###
**Date Reported**:
**Reported By**:
**Incident Type**:
**Severity**: Critical / High / Medium / Low
**SUMMARY**:
[2-3 sentences describing the incident]
**AFFECTED SYSTEMS**:
- System 1 (IP, Role)
- System 2 (IP, Role)
**IMPACT**:
- Data:
- Systems:
- Users:
**TIMELINE**:
- Detection:
- Containment:
- Eradication:
- Recovery:
**ROOT CAUSE**:
[Brief explanation]
**ACTIONS TAKEN**:
- [ ] Action 1
- [ ] Action 2
- [ ] Action 3
**NEXT STEPS**:
- [ ] Step 1
- [ ] Step 2
## EVIDENCE LOG
| Item # | Description | Source | Collector | Date/Time | Hash (SHA256) | Location |
|--------|-------------|--------|-----------|-----------|---------------|----------|
| E-001 | | | | | | |
| E-002 | | | | | | |
| E-003 | | | | | | |
| Mistake | Why It's a Problem | Better Approach |
|---|---|---|
| Blaming individuals | Creates fear, discourages reporting | Focus on processes, not people |
| Incomplete timelines | Gaps in timeline mean missed evidence | Document in real-time, fill gaps ASAP |
| Jargon overload | Management can't understand | Executive summary in plain language |
| No evidence references | Claims without proof are worthless | "As shown in E-001, log X shows..." |
| Speculation as fact | Misleads investigation | Label speculation as "Likely," "Possible" |
| Poor chain of custody | Evidence inadmissible | Document every transfer |
| No lessons learned | Same mistake repeats | Include improvement section |
| Delayed reporting | Regulatory/compliance failure | Report on timeline |
| Over-classification | Hinders information sharing | Classify appropriately, share need-to-know |
| Missing recommendations | Report ends without action plan | Always include actionable remediation |
Before marking this project complete:
Save your progress and earn XP for completing tutorials.
Keep learning
Technology
Cyber Security & Networking
Lesson group
Projects
Progress
55% complete