Evidence to capture during the incident
- Original alert, user report, vendor notice, or customer message.
- Time detected, time reported, and detection source.
- Affected assets, users, services, suppliers, or customers.
- Indicators observed, including domains, IPs, hashes, accounts, devices, or log patterns where relevant.
- Screenshots or configuration exports where appropriate and safe.
- Actions taken, including containment, access changes, rollback, blocking, or recovery.
- Decision notes showing who approved important actions and why.
Evidence to capture after containment
- Validated service recovery or restoration evidence.
- Final impact assessment and affected population where known.
- Root cause and contributing factors.
- Supplier RCA or customer-facing statements where applicable.
- Reporting and notification decisions.
- Corrective actions with owners and due dates.
- Post-incident review notes and management follow-up.
What good incident evidence looks like
| Quality | Practical meaning |
|---|---|
| Traceable | A reviewer can see where the information came from. |
| Time-bound | Important events have dates and times. |
| Owned | Each action or decision has an accountable person or role. |
| Relevant | The evidence supports impact, cause, action, or decision. |
| Reviewable | A manager, auditor, customer, or adviser can understand the record without reading every chat message. |
| Protected | Sensitive evidence is stored with appropriate access control and retention. |
Avoid evidence chaos
Evidence chaos happens when logs are in one tool, screenshots are in chat, decisions are in email, supplier updates are in a shared drive, and the RCA is written from memory. That makes reporting and review harder than the incident itself.
A better approach is to keep the incident ticket as the index. It does not need to store every artifact directly, but it should point to where each artifact lives and why it matters.
Where IncidentAI helps
IncidentAI can help keep incident evidence organized by linking context to the ticket, summarizing thread updates, maintaining a timeline, highlighting missing information, and preparing RCA notes for review.
Evidence still needs human validation. AI can organize and summarize, but people decide what is accurate, sensitive, reportable, and appropriate to retain.
Quick FAQ
What evidence should be kept for a NIS2 incident?
Keep detection details, timelines, affected assets, impact assessment, logs, alerts, actions, decisions, communications, RCA, corrective actions, owners, and review notes.
Should all evidence be attached to the ticket?
Not always. The ticket should at least index the evidence and link to controlled storage where sensitive artifacts are retained.
Why is a decision log important?
A decision log explains what the team knew, who approved actions, and why choices were made when facts were still developing.
Can AI validate incident evidence?
AI can help organize and summarize evidence, but accountable humans should validate accuracy, relevance, sensitivity, and reporting implications.
Official sources used
These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.
