CySA+ v4 · Objective 4.2
Incident reporting and handover
Communicate an incident clearly across audiences and shifts, preserving operational security, decision ownership, and measurable lessons.
What you will be able to do
- Write an incident update that separates facts, uncertainty, impact, and the next decision.
- Select stakeholders and approved communication paths for sensitive incident information.
- Produce an actionable handover with accepted ownership and pending tasks.
- Define operational metrics and convert post-incident findings into validated improvements.
Learn the concepts
- Lesson 1
Tell the right people what they need to decide
Communication is part of response, not a report written after the technical work finishes. A good update gives its audience enough reliable information to make the next decision without exposing unnecessary incident detail.
Open lesson → - Lesson 2
Carry the incident across shifts and into improvement
An incident can lose momentum when people change shifts or when service restoration removes the immediate pressure. Structured handover and carefully defined measures keep unfinished work visible and make learning actionable.
Open lesson →
Apply your judgement · Synthetic scenario
The shift change before service release
A fictional housing association is responding to unauthorised access to its repair scheduling service. The evening team is about to leave, and a director wants a concise update. Technical restoration is ready, but an identity review and release approval remain open.
- Confirmed scope
- Two staff accounts used without authorisation; one scheduling service affected.
- Uncertainty
- Resident-record access review incomplete; no supported conclusion about disclosure yet.
- Current controls
- Affected accounts suspended and sessions revoked; replacement service remains restricted.
- Pending work
- Identity permission review due 19:00; service-owner release approval pending; next executive update 19:30.
- Metric proposal
- Analyst proposes reporting the incident resolved because the replacement server started successfully.
Your task
- Write a concise executive update with a clear uncertainty statement.
- Produce the three most important handover items and ownership acknowledgements.
- Explain why the proposed resolution metric is premature.
Compare your response
Two staff accounts accessed the scheduling service without authorisation and have been contained. The service remains restricted while access review and release checks finish; resident-data disclosure is still being assessed. Confirm support for continued restricted operation and provide the next update at 19:30.
The incoming lead accepts incident ownership; the identity analyst accepts the permission review and 19:00 check; the service owner and response lead retain the documented release decision. Link the evidence record, existing controls, pending impact assessment, and escalation path if either checkpoint slips.
Starting the replacement is an operational milestone, not verified remediation, authorised release, or administrative closure. Record the actual milestone and leave the incident open. Report each interval using its agreed boundaries and retain the unresolved identity and impact tasks.
Check your understanding
Source reading: supplied book, chapters 12. Lessons, scenarios, and questions are original CyberCorps course material.