Skip to content

Client Data Breach Incident Response Worksheet

Client Data Breach Incident Response Worksheet

Section titled “Client Data Breach Incident Response Worksheet”

Name:

Role:

Organizational Unit (e.g., agency, department, division, team) and Affiliation:

E-mail Address:

Phone Number:

Contact Information for alternate Law Enforcement Officer/Regulator (if appropriate)

Section titled “Contact Information for alternate Law Enforcement Officer/Regulator (if appropriate)”

Name:

Role:

Organizational Unit (e.g., agency, department, division, team) and Affiliation:

E-mail Address:

Phone Number:

Contact Information for the Incident Reporter

Section titled “Contact Information for the Incident Reporter”

Name:

Role:

Organizational Unit (e.g., agency, department, division, team) and Affiliation:

E-mail Address:

Phone Number:

Contact Information for the Incident Response Coordinator

Section titled “Contact Information for the Incident Response Coordinator”

Name: Name:

Role:

Organizational Unit (e.g., agency, department, division, team) and Affiliation:

E-mail Address:

Phone Number:

Contact Information for the Incident Response Lead

Section titled “Contact Information for the Incident Response Lead”

Name:

Role:

Organizational Unit (e.g., agency, department, division, team) and Affiliation:

E-mail Address:

Phone Number:

Name:

Role:

Organizational Unit (e.g., agency, department, division, team) and Affiliation:

E-mail Address:

Phone Number:

Name:

Role:

Organizational Unit (e.g., agency, department, division, team) and Affiliation:

E-mail Address:

Phone Number:

(add other team member contact information on additional pages as necessary)

Current status of the Incident (updated as appropriate, choose all that apply):

Ongoing Attack Contained Eradicated Recovery
Investigating Impact Evaluated Formal Incident Declared Incident Closed
US Department of Defense Notified Other Federal Regulators Notified State/Local Regulators Notified International Regulators Notified

Status change date/timestamps (including time zone) when:

Incident Started:

Incident First Discovered:

Incident Reported:

Incident Declared:

Incident Resolved/Ended:

Physical location at which the:

Incident Started:

Incident First Discovered:

Incident Reported:

Information Types Impacted (check all that apply)

Section titled “Information Types Impacted (check all that apply)”
Government Information Customer/Partner Information Customer/Partner Information Internal Information Internal Information
Controlled Technical Information Personal Health Information (“PHI”) Employee Financial/Personal Health Info.
Covered Defense Information Personally Identifiable Information (“PII”) Employee Personally Identifiable Information
Controlled Unclassified Information Customer Privileged Information (Case Histories/Legal Documents) Legal (privileged) Information
Federal Contract Information Customer Confidential Information Organization Financial Information
Other Government Information Partner Confidential Information Organization Confidential Information

From what jurisdiction(s) is/are the information (e.g., PII from Guam, California, and New York; Financial Information from Florida and Alabama; CUI from DoD and DHS):

Source/cause of the incident (if known):

IP/Physical Address(es) Individual/Equipment Name(s) Notes

Incident Description (how was the incident detected, what occurred, etc.):

(Continue the description on one or more separate pages as necessary)

Affected Resources (e.g., networks, subnets, hosts, applications, data), including hostnames, IP addresses, and function:

(Continue the description on one or more separate pages as necessary)

Vectors of Attack and Indicators of Compromise (e.g., equipment not showing up in inventory, traffic patterns, registry keys, MD5/SHA256 hashes, etc.):

(Continue the description on one or more separate pages as necessary)

Information Attributes (e.g., what kind of information (including healthcare information, banking information, PII, client information, and partner information) and from what jurisdiction(s)):

(Continue the description on one or more separate pages as necessary)

Impact Quantification Factors (functional impact, information impact, recoverability, etc.)

Section titled “Impact Quantification Factors (functional impact, information impact, recoverability, etc.)”
Factor Description Individual Factor Severity Score Individual Factor Severity Score Individual Factor Severity Score Individual Factor Severity Score Individual Factor Severity Score Total
Business Impact (check the appropraite box and enter corresponding score in the Total column) None (0) Few/ Limited (2) Many/ Moderate (5) Most/ Severe (8) All/ Critical (10)
To what extent will the Incident or the response to the Incident impact the organization’s ability to continue day- to-day operations?
To what extent will the Incident impact one or more Clients’ ability to continue day-to-day operations?
To what extent is the Incident spreading to other equipment/information?
Government Information (check the appropriate box and enter corresponding score in the Total column) FCI (10) CUI (55) CDI (55) CTI (55) Total
Is any government information (FCI, CUI, CDI, CTI, etc.) potentially involved in the incident?
Non-Government Information (check the appropraite box and enter corresponding score in the Total column) None (0) Few/ Limited (5) Many/ Moderate (8) Most/ Severe (10) All/ Critical (15) Total
How many client-related health records may have been exposed in the Incident?
How many client-related financial records may have been exposed in the Incident?
How many client-related records containing Personally Identifiable Information (PII) may have been exposed in the Incident?
How many employee financial or personal records, including PII, may have been exposed in the Incident?
To what extent is/are the organization’s bank account(s) impacted by the Incident?
To what extent is the organization’s confidential information impacted by the Incident?
How much of the information impacted by the Incident is likely to be subject to additional legal or regulatory restrictions (e.g., GDPR, CCPA, 23 NYCRR 500, etc.)?
Recoverability Effort (check the appropriate box and enter corresponding score in the Total column) None (0) Few/ Limited (5) Many/ Moderate (8) Most/ Severe (10) All/ Critical (15) Total
What is the expected level of effort needed to recover from the Incident?
Potentially Mitigating Factors (check the appropriate box and enter corresponding score in the Total column) None (0) Few/ Limited (-5) Many/ Moderate (-8) Most/ Severe (-10) All/ Critical (-15) Total
To what extent is the information impacted by the Incident encrypted where the encryption key was not also exposed?
Other Severity Factors (assign a score to each factor) None Few/ Limited Many/ Moderate Severe/ Most All/ Critical Total
Total Score

Assign an overall Severity Score to the Incident based on the Total Score from the table above:

Low Moderate High Critical
0- 10 11-25 26- 50 51+

Response Actions Performed (e.g., disconnected device from the network, shut down host/device, etc.)

Section titled “Response Actions Performed (e.g., disconnected device from the network, shut down host/device, etc.)”

a. Log of Actions Taken by Incident Responders

Section titled “a. Log of Actions Taken by Incident Responders”
Date Time Incident Responder Action Taken

(Copy sheet or add notes on back/separate page(s) as necessary)

  • a. List of Evidence Gathered:
  • b. Incident Handler/Involved Party Comments and Notes:
  • c. Incident Cause (e.g., unpatched equipment, misconfigured application, zeroday, SQL injection, etc.):
  • d. Incident Business Impact:
    1. Lessons Learned
  • a. What went well?

Document the actions taken or other attributes of the response that went well. This is important because any issues/improvements that may be listed below can be modeled after the successful attributes of the response.

What attributes of the organization’s response could use additional attention?

c. How can we improve the Incident Response Plan for next time?

Section titled “c. How can we improve the Incident Response Plan for next time?”
Section titled “Related Standards, Policies, Plans, and Procedures”

Incident Response Policy

Client Data Breach Incident Response Plan

Referenced Terms

CUI
Information that requires safeguarding or dissemination controls pursuant to and consistent with applicable law, regulations, and government-wide policies.

Revision History

2026-08-20 — Darren Rush
Merge pull request #2 from safire-dev/dev (16cb681)
Edit this Page