Operations1,500+ monthly searches

Cybersecurity Incident Report Form Template

Catch phishing, malware, and unauthorized access reports the moment they happen — one structured form your whole company can reach in 8 seconds.

A structured cybersecurity incident report form built for SOC, IT, and security teams. Anyone in the company can log a suspected phishing email, lost laptop, or strange account activity in under a minute, and the right responder gets pinged before the attacker moves.

#security#incident#cybersecurity#phishing#breach#soc#compliance#it
No signup required
AI customizable
✓ Free forever plan✓ Embed on any website✓ GDPR compliant✓ No code required

Why use a cybersecurity incident report form?

Most breaches don't start with a sophisticated zero-day. They start with a finance manager forwarding an invoice she wasn't sure about, or a sales rep who clicked a DocuSign link at 11pm and then thought "wait, that was weird." The window between that moment and the SOC finding out is where attackers actually win. A cybersecurity incident report form closes that gap. Instead of asking employees to remember a security@ inbox or dig up the SOC's Slack handle, you give them one link — bookmarked, in the intranet, pinned in the IT channel — that captures everything an analyst needs to triage in the first 90 seconds. Detection time, affected user, suspected vector, screenshots of the email, the URL they clicked. No back-and-forth, no missing context. It also gives you the paper trail regulators and cyber-insurance carriers ask for. SOC 2, ISO 27001, HIPAA and most cyber policies require a documented incident intake process with timestamps, severity classification, and evidence preservation. One form, filed automatically into your ticketing system, satisfies all three without anyone writing a Word doc at 2am.

What's included in this template

15 fields — customize any field or add new ones with AI.

Short textReporter Full Name✱
EmailReporter Email✱
Short textDepartment or Team✱
DateDate and Time Incident Was Detected✱
DropdownIncident Type✱
Long textAffected Systems, Accounts, or Devices✱
Long textIndicators of Compromise (URLs, IPs, file hashes, sender addresses)
Long textDescription of What Happened✱
Long textImmediate Actions Already Taken
Multiple choiceIs the Incident Still Active?✱
Multiple choiceEstimated Severity✱
NumberNumber of Users or Endpoints Affected
File uploadEvidence Files (screenshots, .eml, logs)
PhoneBest Contact Number for SOC Follow-Up
CheckboxesI confirm the information above is accurate to the best of my knowledge✱

Need different fields?

Tell the AI what to change — "add a budget dropdown" or "remove phone number" — and it edits the form instantly. Every field type above can be added, removed, or relabeled through the chat interface.

Key features of this cybersecurity incident report form template

Everything you need to launch this form in minutes, share it with your team, and collect submissions reliably.

1

Severity routing built in

Critical and High submissions trigger an immediate Slack ping to your SOC channel via webhook; Low and Informational go to a daily digest so analysts aren't paged for spam reports.

2

Evidence capture without email

Reporters drop .eml files, screenshots, and log snippets straight into the form — no more lost attachments or 12MB inbox limits stripping the headers you actually needed.

3

Structured IOC field

A dedicated indicators-of-compromise field keeps URLs, IPs, and hashes in one place, ready to paste into your SIEM or threat-intel platform without parsing free-form prose.

4

Anonymous reporting option

Toggle the reporter-name fields to optional so employees can flag suspected internal misuse without putting their name on the ticket — important for insider-threat programs.

5

Audit-friendly timestamps

Every submission is logged with detection time, submission time, and reporter identity, giving you the chain-of-custody record SOC 2 and cyber-insurance reviewers ask for.

6

Mobile-first reporting

A laptop is the worst place to report a lost laptop. The form works on any phone, so a sales rep at an airport can log a stolen device before they've even reached the gate.

Perfect for

Security operations centers, IT helpdesks, MSSPs running shared SOC services for SMB clients, compliance and GRC teams maintaining SOC 2 or ISO 27001 evidence, CISOs at companies without a 24/7 SOC, internal phishing-simulation teams collecting real-world reports, and any employee outside of IT who needs a one-click way to say "this email looks wrong."

How to use this template

1

Open the template

Click "Use this template free." Flexform loads the form instantly — no account needed to preview.

2

Customize with AI

Type what you want to change in the chat: fields to add or remove, rename labels, change field types, or rearrange pages.

3

Connect & publish

Link to Slack or Google Sheets with one click, then embed on your site or share the link.

Ways to use this template

Phishing report intake

Pin the form link in your "Report Phishing" Outlook button or Slack /phish command. Employees paste the suspicious email, attach the .eml, and the SOC has everything it needs to pull headers and block the sender — usually before a second user clicks the link.

Lost or stolen device reporting

A laptop goes missing on a business trip. The employee opens the form on their phone, marks "Lost/Stolen Device," and severity routes the report straight to IT so the device can be wiped via MDM and the corresponding accounts force-logged-out within the hour.

Suspicious account activity

When a user notices logins from a country they've never visited or an MFA prompt they didn't request, the form captures timestamp, location, and the account in question — exactly the inputs your IR runbook needs to start an investigation.

Third-party vendor breach notification

A SaaS vendor emails to say they've had a security event. Your vendor manager logs it on the same form with vendor name, affected data, and notification timestamps, giving compliance the audit trail required for breach-notification clocks.

Insider-threat tip line

Run a duplicate version of the form with reporter identity optional. HR and security share the inbox so concerns about data exfiltration or policy violations have a private, structured channel that isn't the CISO's personal email.

MSSP client reporting portal

Managed-security providers can spin up one form per client, embed it on the client portal, and route each submission to the right SOC queue based on which form was used — no shared inbox, no misrouted tickets.

Workflow integrations

Connect this form to your existing tools with no middleware. Every submission triggers your workflow automatically.

SlackGoogle SheetsWebhookEmail
⚡

Real-time sync

Data appears in your CRM or spreadsheet within 1–2 seconds of submission — no cron jobs, no delays.

🔀

Conditional routing

Route submissions to different Slack channels, HubSpot pipelines, or Airtable bases based on field values.

🔁

Two-way data flow

Pre-fill form fields with CRM data for returning visitors. Update existing records instead of creating duplicates.

Why choose Flexform?

Most incident-report tools are either a $40k-a-year SOAR module you can't reach without a license, or a generic Google Form that doesn't know what a hash looks like. FlexForm sits in the gap. The starting template covers the fields a Tier-1 analyst actually triages on — incident type, IOCs, affected systems, severity — and you can adjust any of it by describing what you want in plain English. "Add a field for the user's manager so we can notify them" or "split affected systems into prod and staging" — the AI rewrites the form, no JSON, no admin console. When a submission comes in, the Slack integration drops a formatted alert into your SOC channel with the severity, reporter, and a link to the full report, while Google Sheets keeps a running log your GRC team can hand to auditors. For deeper pipelines, the webhook hits TheHive, Jira, ServiceNow, or your SIEM directly — most teams have the routing wired up in an afternoon. Sensitive deployments can run the form behind SSO on your own domain via a shareable link, no employee account required, and the free plan covers it indefinitely if you're a small team or a single-client MSSP. For organizations with their own mobile apps — banks, hospitals, large retailers — the Kotlin Multiplatform mobile SDK lets you embed the same form natively inside your Android and iOS employee apps, so reporting a stolen device or suspicious push notification is one tap from the home screen instead of a hunt through the intranet.
One link, share anywhere
Native iOS & Android SDK
Free forever plan

Frequently asked questions

Is this form template free to use?

Yes. The cybersecurity incident report template, the share link, and the Slack and Google Sheets integrations are all on the free plan. You can run it indefinitely without entering a credit card — most small security teams never need to upgrade.

How do we route Critical incidents to our on-call analyst immediately?

Wire the form to your paging tool — PagerDuty, Opsgenie, or a Slack channel monitored by on-call — using the webhook integration. You can filter on the severity field so only High and Critical submissions trigger a page, and the rest land in a daily digest. Most teams have this set up in about 20 minutes.

Can employees submit reports anonymously?

Yes. Mark the reporter name and email fields as optional, or duplicate the form into a separate anonymous version for insider-threat use. The form still records submission timestamps and any IOCs, which is usually enough for the SOC to validate.

What file types can be attached as evidence?

The evidence field accepts screenshots (PNG, JPG), email source files (.eml, .msg), PDFs, and most log formats (.txt, .csv, .json). Individual files can be up to 25MB on the free plan, which covers full email headers and most log excerpts.

Does this meet SOC 2 or ISO 27001 incident-reporting requirements?

It captures the data points those frameworks expect: detection timestamp, reporter, affected systems, severity, and actions taken. Auditors generally want the form plus a documented response procedure, so pair it with your incident-response runbook. We've had customers use it as their primary intake mechanism through clean SOC 2 Type II audits.

Can we customize the incident-type dropdown for our environment?

Yes, and you don't need to touch JSON. Open the form in the editor, tell the AI "change the incident type options to Phishing, Malware, Unauthorized Access, Data Loss, Policy Violation, Physical Security, and Other," and it rewrites the field. You can do the same for severity tiers if you use Low/Medium/High/Critical instead of a numeric scale.

Can we embed the form inside our internal mobile app?

Yes. FlexForm ships a Kotlin Multiplatform SDK that renders the same form natively on Android and iOS, so you can put incident reporting one tap from the home screen of your employee app. Submissions flow through the same Slack and webhook routing you set up for the web version.

Where does the data live and who can see it?

Submissions are stored in your FlexForm workspace and accessible only to the team members you invite. You can also push them straight to your own systems via webhook and skip the FlexForm-stored copy if your security policy requires data minimization. Workspace access supports role-based permissions so SOC analysts and GRC reviewers can see different views.

Related templates

Use this cybersecurity incident report form template free

Open the template, customize with AI, connect your tools, and publish — in under 5 minutes.

No signup required · Free forever plan