Data Compromise Assessment Form
Use this form to assess a suspected or confirmed data compromise by capturing incident details, affected systems and data, timeline, impact, response actions, and follow-up needs.
Incident Overview
Incident title or reference name
*
Date and time discovered
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Hour Minutes
AM
PM
AM/PM Option
Incident type
*
Suspected breach
Confirmed breach
Lost device
Unauthorized access
Malware/Ransomware
Phishing
Accidental disclosure
Third-party exposure
Other
Current status
*
Under review
Contained
Ongoing
Resolved
Reporting Contact
Full Name
*
First Name
Middle Name
Last Name
Job Title / Role
*
Organization / Department
*
Business Email
*
example@example.com
Phone Number
*
Please enter a valid phone number.
Format: (000) 000-0000.
Preferred Contact Method
*
Email
Phone
Either
Affected Data and Systems
System/Application Name
*
Data Category Affected
*
Please Select
Customer Records
Employee Records
Internal Documents
Credentials
Source Code
Financial Records
Other
Estimated Number of Records or Users Affected
Data Sensitivity Level
*
Public
Internal
Confidential
Highly Confidential
Credentials or Access Tokens May Have Been Exposed
*
Yes
No
Unknown
Compromise Timeline and Indicators
Approximate start of the issue
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Hour Minutes
AM
PM
AM/PM Option
Date and time detected
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Hour Minutes
AM
PM
AM/PM Option
How was the issue discovered?
*
Monitoring alert
User report
Vendor notice
Audit review
Unusual activity
Other
Indicators of compromise
*
Assessment of Impact
Business Impact Rating
*
1
2
3
4
5
Operational Impact Level
*
None
Minor
Moderate
Major
Critical
Severity Assessment
*
Rows
Low
Medium
High
Very High
Confidentiality
1
2
3
4
Integrity
5
6
7
8
Availability
9
10
11
12
Customer Impact
13
14
15
16
Regulatory/Reporting Concern
17
18
19
20
Containment and Response Actions
Response Actions Taken
*
Containment Status
*
Not Started
In Progress
Completed
Needs Review
Additional Response Notes / Escalation Details
Source and Scope Analysis
Likely Source or Cause of Compromise
*
Phishing
Malware
Unauthorized Access
Misconfiguration
Lost/Stolen Device
Third-Party Exposure
Accidental Sharing
Unknown
Other
Are Third Parties Involved?
*
Yes
No
Scope Analysis
*
Follow-Up and Reporting Needs
External notification may be needed?
*
Yes
No
Unsure
Internal teams to involve
*
Legal
IT/Security
Privacy
Compliance
HR
Management
Vendor Management
Preferred next action
*
Continue investigation
Begin containment
Request forensic review
Notify stakeholders
Other
Additional notes or evidence upload instructions
Submit Assessment
Should be Empty: