Incident Response Messages
Security incident communication templates for various severity levels.
Updated Request
Hi {{cursor}},
Following up on our recent conversation about updated request.
Here are the key details:
- [Detail 1]: [Specific information]
- [Detail 2]: [Specific information]
- [Detail 3]: [Specific information]
Please review the above and let me know if you have any questions or need additional information.
I look forward to hearing from you. Feel free to reply to this message or schedule a call.
Best regardsRevised Summary
Revised Summary
Date: {{date}}
Prepared by: {{cursor}}
Summary:
[Brief overview of revised summary]
Details:
1. [Key point or finding]
2. [Key point or finding]
3. [Key point or finding]
Action Items:
- [Action item 1] - Due: [Date]
- [Action item 2] - Due: [Date]
- [Action item 3] - Due: [Date]
Next Steps:
[Description of what happens next]
Notes:
[Additional context or considerations]Initial Alert
Hi {{cursor}},
Quick update on initial alert:
[Key information]
Let me know if you have any questions.
BestFollow-Up Note
Follow-Up Note
Date: {{date}}
Status: [Active/Pending/Complete]
Owner: {{cursor}}
Description:
[Detailed description of follow-up note]
Key Points:
- [Point 1]
- [Point 2]
- [Point 3]
Timeline:
- Start: [Date]
- Milestone 1: [Date]
- Completion: [Date]
Notes:
[Additional information]Standard Memo
Hi {{cursor}},
I wanted to follow up with you about standard memo.
Here are the key details:
- [Detail 1]: [Specific information]
- [Detail 2]: [Specific information]
- [Detail 3]: [Specific information]
Please review the above and let me know if you have any questions or need additional information.
I look forward to hearing from you. Feel free to reply to this message or schedule a call.
Best regardsFormal Version
Formal Version
Date: {{date}}
Prepared by: {{cursor}}
Summary:
[Brief overview of formal version]
Details:
1. [Key point or finding]
2. [Key point or finding]
3. [Key point or finding]
Action Items:
- [Action item 1] - Due: [Date]
- [Action item 2] - Due: [Date]
- [Action item 3] - Due: [Date]
Next Steps:
[Description of what happens next]
Notes:
[Additional context or considerations]Friendly Response
Hi {{cursor}},
Quick update on friendly response:
[Key information]
Let me know if you have any questions.
BestBrief Update
Brief Update
Date: {{date}}
Status: [Active/Pending/Complete]
Owner: {{cursor}}
Description:
[Detailed description of brief update]
Key Points:
- [Point 1]
- [Point 2]
- [Point 3]
Timeline:
- Start: [Date]
- Milestone 1: [Date]
- Completion: [Date]
Notes:
[Additional information]Detailed Template
Hi {{cursor}},
Thank you for reaching out regarding detailed template.
Here are the key details:
- [Detail 1]: [Specific information]
- [Detail 2]: [Specific information]
- [Detail 3]: [Specific information]
Please review the above and let me know if you have any questions or need additional information.
Please let me know if you have any questions or if there is anything else I can help with.
Best regardsWhen to use this template
- Internal incident declaration with severity, scope, who's responding, and where to follow updates.
- Mid-incident communication update — what's been confirmed, what's still investigating, and any user actions required.
- Post-incident customer notification when the incident affected user data or service.
Customize for your workflow
- Match communication breadth to severity. P0 reaches everyone affected; P3 stays in the security team channel.
- Don't speculate in early communications. 'We're investigating X' is fine; 'we believe attackers did Y' before you've confirmed creates legal and PR exposure.
Common questions
When do I notify regulators or customers about a breach?
Per applicable regulations (GDPR is 72 hours; varies elsewhere). Get legal involved early; the notification timeline is often the most important compliance question.
Public statement before or after notifying affected users?
Affected users first when possible. They shouldn't learn from press. Coordinate timing with legal and comms — sometimes simultaneous is the only option.
Related reading
More Cybersecurity Templates
Security Alert Templates
Threat detection notifications and vulnerability disclosure formats.
10 snippetsPhishing Awareness
Employee phishing education and simulated phishing test templates.
8 snippetsAccess Review Templates
Periodic access certification and privilege review communications.
8 snippetsSecurity Policy Updates
Security policy change announcements and compliance reminders.
9 snippetsPenetration Test Reports
Penetration testing summary and finding report templates.
8 snippetsSecurity Training Reminders
Mandatory security training notifications and completion tracking.
8 snippetsUse these snippets in TypeFire
Download the template pack, drop the .md files into your TypeFire snippets folder, and start expanding with abbreviations instantly.