Skip to content
Checklist20 review points9 minreviewed 10/08/2026

Managing IT security incidents organizationally

First organizational steps for roles, situation report, communication, evidence and restart in the event of a suspected IT security incident.

For whom
Management, IT, information security, data protection and communication in small and medium-sized companies.
When to use it
Immediately upon a suspected incident and in parallel with expert technical analysis.
THE SHORT ANSWER

In the event of a suspected IT security incident, what counts is calm, a named operations management, a secure situation report, coordinated technical measures, documented decisions and timely checked reporting and communication obligations.

Download PDF
01

Leadership and accessibility

A small group capable of acting is better than many parallel individual decisions.

02

Situation report and evidence

Early observations and timing are crucial later for technology, duties and communication.

03

Coordinate containment

Emergency technical measures must limit damage without unnecessarily jeopardizing evidence or recovery.

04

Reporting and communication

Unverified statements create additional harm. However, deadlines should not be overlooked.

05

Restart and follow-up

A system is not trustworthy simply because it can be accessed again.

Result of the joint review

  • A named operational management and clear roles
  • A continuous situation report with a timeline
  • Coordinated technical and communication decisions
  • A tested restart with follow-up

Sources and professional basis

This working aid translates general recommendations into a compact initial review. The primary sources and your specific context remain decisive.

Frequently asked questions

Should an affected system be switched off immediately?

Not across the board. A shutdown can limit damage, but it can also affect evidence, availability or recovery. The decision should be made based on the specific situation and, if possible, with expert incident response support.

Does this list replace an incident response plan?

No. She helps with the initial organization. Responsibilities, contacts, technical measures and reporting channels should be planned and practiced before an incident.

Browser checkmarks are not stored or transmitted to sudo/PORT.

Nächster Schritt

Turn open points into a next step

We help prioritise risks and define an appropriate scope for analysis, a project or an immediate measure.

Discuss the checklist