Security Incident Responses
Initial response templates for security-related IT issues.
Updated Summary
Hi {{cursor}},
Thank you for reaching out regarding updated summary.
Here are the key details:
- [Detail 1]: [Specific information]
- [Detail 2]: [Specific information]
- [Detail 3]: [Specific information]
Please review the above and let me know if you have any questions or need additional information.
I look forward to hearing from you. Feel free to reply to this message or schedule a call.
Best regardsRevised Alert
Revised Alert
Date: {{date}}
Prepared by: {{cursor}}
Summary:
[Brief overview of revised alert]
Details:
1. [Key point or finding]
2. [Key point or finding]
3. [Key point or finding]
Action Items:
- [Action item 1] - Due: [Date]
- [Action item 2] - Due: [Date]
- [Action item 3] - Due: [Date]
Next Steps:
[Description of what happens next]
Notes:
[Additional context or considerations]Initial Note
Hi {{cursor}},
Quick update on initial note:
[Key information]
Let me know if you have any questions.
BestFollow-Up Memo
Follow-Up Memo
Date: {{date}}
Status: [Active/Pending/Complete]
Owner: {{cursor}}
Description:
[Detailed description of follow-up memo]
Key Points:
- [Point 1]
- [Point 2]
- [Point 3]
Timeline:
- Start: [Date]
- Milestone 1: [Date]
- Completion: [Date]
Notes:
[Additional information]Standard Version
Hi {{cursor}},
Thank you for your patience while we reviewed standard version.
Here are the key details:
- [Detail 1]: [Specific information]
- [Detail 2]: [Specific information]
- [Detail 3]: [Specific information]
Please review the above and let me know if you have any questions or need additional information.
If you need any clarification, I am available to chat anytime this week.
Best regardsFormal Response
Formal Response
Date: {{date}}
Prepared by: {{cursor}}
Summary:
[Brief overview of formal response]
Details:
1. [Key point or finding]
2. [Key point or finding]
3. [Key point or finding]
Action Items:
- [Action item 1] - Due: [Date]
- [Action item 2] - Due: [Date]
- [Action item 3] - Due: [Date]
Next Steps:
[Description of what happens next]
Notes:
[Additional context or considerations]Friendly Update
Hi {{cursor}},
Quick update on friendly update:
[Key information]
Let me know if you have any questions.
BestBrief Template
Brief Template
Date: {{date}}
Status: [Active/Pending/Complete]
Owner: {{cursor}}
Description:
[Detailed description of brief template]
Key Points:
- [Point 1]
- [Point 2]
- [Point 3]
Timeline:
- Start: [Date]
- Milestone 1: [Date]
- Completion: [Date]
Notes:
[Additional information]Detailed Notification
Hi {{cursor}},
Following up on our recent conversation about detailed notification.
Here are the key details:
- [Detail 1]: [Specific information]
- [Detail 2]: [Specific information]
- [Detail 3]: [Specific information]
Please review the above and let me know if you have any questions or need additional information.
I am happy to discuss this further at your convenience. Please do not hesitate to reach out if you need anything else.
Best regardsWhen to use this template
- Suspected phishing email reported by a user. Acknowledge fast, ask them not to click anything, kick off the investigation.
- Suspected compromised account. Lock first, ask questions later — template confirms the lock and the path to recovery.
- Lost or stolen device report. Triggers immediate remote-wipe / MDM lockout plus the formal report-filing instructions.
Customize for your workflow
- Don't use the same template for low-severity vs high-severity incidents. A misdirected email is different from a credential leak; the response should reflect that.
- Include the security team's pager / on-call contact for high-severity incidents. Email-only response paths are too slow at 2am.
Common questions
Should I tell the user the suspected attacker's identity if known?
Not in initial templates. Investigation isolation is part of incident response — what's known to security shouldn't be in the user-facing reply.
How fast must I respond to a security report?
Acknowledge within 15 minutes for any potentially active threat. Containment within 1 hour. Slower than that and the threat actor has a head start.
Related reading
More IT Support & Helpdesk Templates
Password Reset Instructions
Step-by-step password reset guides for various systems.
8 snippetsVPN Setup Guides
VPN configuration instructions for different platforms.
9 snippetsHardware Request Responses
Equipment request processing and fulfillment templates.
8 snippetsSoftware Installation Guides
Common software setup and configuration instructions.
10 snippetsNetwork Troubleshooting
Common network issue diagnosis and resolution guides.
11 snippetsAccount Provisioning
New account setup confirmations and access instructions.
8 snippetsUse these snippets in TypeFire
Download the template pack, drop the .md files into your TypeFire snippets folder, and start expanding with abbreviations instantly.