What this is
What is a security incident investigation?
What is a security incident investigation?
A record of a theft, break-in, unauthorised access, tampering or threat, capturing what was found, what was done immediately, what evidence was preserved, and why it happened, so a similar event is either prevented or handled better next time. It sits apart from the general safety incident stream because it usually involves named individuals and evidence that may become a police matter.
How is a security incident different from a safety incident?
A safety incident is investigated to find out what failed in a process or control. A security incident starts from the presumption that somebody did something deliberately, which changes the first response: preserve the scene rather than make it safe for work to resume, and restrict who can see the record rather than share it for lessons learned.
Who should complete it?
Whoever discovered the incident, as close to the moment as possible. The record is not written by security staff after the fact from a verbal account; the discoverer's own factual description is the version least altered by hindsight or hearsay from others on site.
Scope
When is a security incident investigation required?
This record is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use this template when
- Theft, break-in, unauthorised access, tampering or a threat has occurred, or was attempted
- The workspace is being set up, or the singleton register needs establishing for the site
- You are running the Lone Working and Security programme and this is its incident stream
- A linked record needs this one to exist: RCA for a full investigation, Security Assessment for a review of controls
- Product integrity may have been affected and a hold needs to be raised against it
Do not use it for
- Security Risk Assessment, which assesses the site before an incident, not what happened during one.
- Violence and Aggression Assessment, which assesses roles exposed to aggression generally, rather than recording a specific event.
- CCTV and Monitoring Review, which periodically reviews coverage and system health, not a single incident's footage.
- Site Security Audit, which periodically audits the whole security posture, not one occurrence.
- The Root Cause Analysis or CAPA record itself once one is raised, which is a linked but separate record with its own investigation content.
Compliance mapping
Which ISO 45001 cl.10.2 requirements does this satisfy?
ISO 45001 treats a security incident as a work-related incident like any other once it has, or could have, resulted in harm, which is why this record sits inside the same clause as any safety investigation. What differs is the handling of evidence and personal data, which falls outside the standard entirely.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.10.2 | Incidents reacted to in a timely way and investigated with the involvement of relevant workers to determine what happened | What happened |
| ISO 45001 cl.8.1.2 | Operational controls applied to eliminate or reduce risk during the immediate response, not just afterwards in the write-up | Immediate response |
| ISO 45001 cl.7.5.3 | Documented information, including evidence such as footage and records, protected and controlled before it is lost or altered | Evidence |
| ISO 45001 cl.5.4 | Consultation and participation of workers, applied here as statements taken from witnesses and the discoverer | Evidence |
| ISO 45001 cl.10.2 | Root cause determined and reviewed against whether similar incidents exist or could occur elsewhere on site | Cause and prevention |
| ISO 45001 cl.6.1.2.1 | Hazard identification proactive and ongoing, extended here to insider involvement and control failure rather than assumed absent | Cause and prevention |
| ISO 45001 cl.7.5.3 | Access to documented information restricted where its content, such as named individuals and allegations, requires it | Cause and prevention |
What it does not cover
- Security Risk Assessment, which assesses the site's exposure to theft, unauthorised access, sabotage and tampering before an event, not after one.
- Root Cause Analysis, which this record can trigger but does not itself perform once Investigation Level is set above a quick debrief.
- CAPA record, which tracks the corrective action to a verified close once Action Required is set, separate from the investigation itself.
- Employee disciplinary process, which follows from a finding of insider involvement but is run through HR, not through this record.
- Police investigation, which this record supports with a crime reference and preserved evidence but does not substitute for.
Global
Security Incident Investigation requirements by country
No jurisdiction regulates a 'security incident' as a named category. What applies instead is the general duty to investigate work-related harm, and separately, the rules governing personal data and evidence gathered along the way.
OSHA recordkeeping (29 CFR 1904); General Duty Clause
No federal duty to investigate theft or break-in as such, but an incident involving injury, including one arising from a confrontation, falls under standard recordkeeping and the General Duty Clause.
The security content of the record is voluntary good practice; the moment it produces an injury, it becomes a recordable event like any other.
RIDDOR 2013; Data Protection Act 2018 / UK GDPR
Work-related violence causing a reportable injury falls under RIDDOR. Separately, CCTV footage and named individuals in the record are personal data subject to lawful basis and retention limits.
Restricting access to the record is not just good discipline, it is close to a data protection requirement once allegations against named people are involved.
ISO 45001
A management system requirement to investigate incidents, determine root cause, and take corrective action, applied here to a security event with the potential for harm.
Certification auditors will ask why a security incident with a plausible harm outcome was, or was not, investigated to the same standard as a safety one.
How to complete it
How to complete a security incident investigation, step by step
The form prompts for the facts. Whether the record ends up defensible depends on judgement calls it cannot make for the person completing it.
The help text is explicit: set by potential outcome, not by what actually happened. A break-in discovered empty-handed with nobody present still deserves the same rigour as one that ends in confrontation, because the difference between the two is often timing rather than intent.
Most systems overwrite CCTV on a rolling cycle measured in days, sometimes hours on busy cameras. If the record is opened, description written and CCTV review deferred to later in the shift, the footage that would have settled 'Time Of Occurrence Known' as anything but unknown may already be gone.
The help text asks for what was seen and found, not who or why. An account that names a suspect on first write becomes the frame every subsequent question is answered inside, and it is very hard to walk back once statements start referencing it.
Access Restricted To This Record exists because most records in the library are not restricted, and this one usually should be. Leaving it at No because nobody thought to change it is a different failure from deciding restriction is not warranted and being able to say why.
What auditors find
Most common security incident investigation findings
The record usually exists after the fact; findings concern whether it was completed while the evidence still could be, and whether it stayed factual.
| Finding | Clause | What fixes it |
|---|---|---|
| CCTV footage not exported before the retention cycle overwrote it. | ISO 45001 cl.7.5.3 | Export footage on discovery, before the description is written, regardless of how minor the incident appears. |
| Scene not preserved or only partly secured before staff resumed normal work in the area. | ISO 45001 cl.8.1.2 | Cordon the area on discovery and hold it until evidence has been reviewed, even where the loss looks minor. |
| Investigation Level set to reflect the outcome that occurred rather than what could have occurred. | ISO 45001 cl.10.2 | Reassess level against the worst plausible outcome of the same event, not the actual one. |
| Record left unrestricted despite naming an individual or containing an unresolved allegation. | ISO 45001 cl.7.5.3 | Restrict access at the point a name or allegation enters the record, not after the fact. |
| Control failure identified with no corresponding Security Assessment review triggered. | ISO 45001 cl.6.1.2.1 | Trigger the assessment review whenever a specific control is named as having failed, not only for repeat incidents. |
| Discoverer confronted the individual involved before reporting. | ISO 45001 cl.8.1.2 | Reinforce observe-and-report through conflict and aggression training, and treat confrontation as a training gap, not a one-off lapse. |
Case in point
Case in point: the footage that was already gone
A cold store site found a padlock cut and a pallet of high-value stock missing on a Monday morning. The discoverer, a warehouse supervisor, wrote a thorough factual description, correctly did not confront anyone since nobody was present, and secured the area. CCTV Reviewed was marked yes later that day. Footage Retained was left at no, because the reviewer watched the relevant hour on screen, confirmed a vehicle had reversed up to the yard gate overnight, and moved on to the next task assuming the recording would still be there when needed.
The system's retention cycle was four days. By the time police asked for the footage to support a crime reference, it had been overwritten twice over. The description, the crime reference and the insurer notification were all in order; the one piece of evidence that could have identified a vehicle was gone because reviewing it on screen was treated as equivalent to keeping it.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- SAF-146
- Archetype
- Record
- Record ID
- CASE-2026-000
- Scoring
- Open cases
- Direction
- Low is good
- Singleton
- Yes
- Basis
- ISO 45001 cl.10.2
- Links
- Links RCA, Security assessment
- Tags
- Security
- Sections
- 5
- Fields
- 48
- Follow up fields
- 6
- Repeating sections
- 0
- Links out
- 5
Header
12 fieldsCase ID*
Auto sequence. Format CASE-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Area
The area within the site.
Exact Location
Drop a pin for anything hard to find.
Handled Separately And Carefully
Security incidents often involve named individuals, allegations and evidence that may become a police matter. Restrict access to this record and keep the account factual.
Incident Type*
Time Discovered*
Discovered By*
What happened
7 fieldsFactual Description*
What was seen and found. No conclusions about who or why.
Property Or Product Involved
Estimated Value
Product Integrity Affected*
- No3 pts
- Possibly1 pt
- Yes0 pts
Hold ID
Links to QUA-003 Hold ID
Time Of Occurrence Known
Repeat Of Previous Incident*
- No3 pts
- Yes0 pts
Immediate response
6 fieldsScene Preserved*
- Yes3 pts
- Partly1 pt
- No0 pts
Area Secured*
- Yes3 pts
- Partly1 pt
- No0 pts
Anybody Confronted*
Confronting a thief has produced more injuries than it has recovered stock. Observe and report.
- No3 pts
- Yes0 pts
Police Notified*
- Yes3 pts
- Not appropriate3 pts
- No0 pts
Crime Reference
Insurer Notified
Evidence
6 fieldsCCTV Reviewed*
- Yes3 pts
- No coverage1 pt
- No0 pts
Footage Retained*
Systems overwrite quickly. Export the footage before it is lost.
- Yes3 pts
- No1 pt
Access Records Reviewed*
- Yes3 pts
- No0 pts
Witnesses Identified
Statements Taken
- Yes3 pts
- No0 pts
Photographs Taken*
- Yes3 pts
- No0 pts
Cause and prevention
17 fieldsControl Failure Identified*
- No2 pts
- Yes0 pts
Which Control
Insider Involvement Suspected*
- No3 pts
- Possible1 pt
- Yes0 pts
Investigation Required*
Set by potential outcome, not by what actually happened.
- No3 pts
- Yes0 pts
Investigation Level
RCA ID
Format RCA-2026-00000.
Links to FDN-013 RCA ID
Security Assessment Review Triggered*
- Yes3 pts
- Not needed3 pts
- No0 pts
Assessment ID
Links to SAF-142 Assessment ID
Access Restricted To This Record*
- Yes3 pts
- No0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Site Manager*
Signature*
Security*
Second Signature*
SAF-146 · record IDs look like CASE-2026-000 · Links RCA, Security assessment
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The record is the easy part once someone is on scene. What fails is the minutes before it is opened and the evidence trail that runs cold once the record is filed and forgotten.
Holds the incident register against site and area, flags when a control failure has not triggered a Security Assessment review, and tracks restricted access on named records.
Picks up product integrity findings and turns them into a hold record automatically, rather than leaving the link to be made by hand.
Connects a confrontation finding to conflict and aggression training due dates, so the response to a lapse is retraining, not a note in a file.

Nudges CCTV export within the retention window rather than after it, and holds every write to a restricted record for explicit approval.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Security Incident Investigation definitions and key terms
- Scene preservation
- Keeping an area untouched after discovery so evidence is not disturbed, distinct from making an area safe, which can involve moving or cleaning things.
- Crime reference
- The number issued by police once a report is logged, used to link this record, the insurer notification and any later correspondence to the same reported event.
- Insider involvement
- A finding that someone with legitimate access, rather than an external party, is suspected of causing or enabling the incident, which changes who the investigation can safely involve.
- Investigation level
- The depth of follow-up required, from a quick debrief through to a cross-functional root cause analysis, set by potential severity rather than actual outcome.
- Product integrity affected
- A finding that the incident may have compromised product, which routes the record to a hold rather than leaving contamination or tampering risk unaddressed.
FAQ
Frequently asked questions about security incident investigation
Should we wait for security or the police before completing the record?+
No. Discovery, immediate response and evidence preservation happen in the minutes after the event, and the record should be opened then, by whoever found it. Security and police involvement layer on top; they do not gate the first entry.
What if we don't know whether it's a security incident or a safety incident yet?+
Start here if there is any suggestion of a deliberate act: theft, unauthorised access, tampering or a threat. If the investigation later shows it was accidental, the record still stands as the accurate account of what was found; it does not need to be recreated in the safety stream.
Why does the form penalise confronting someone, even if the item was recovered?+
Because the scoring is about risk to the person, not the outcome of the recovery. A confrontation that goes well this time sets no precedent for the next one, and the form is written to discourage the behaviour regardless of how it turns out.
When should product integrity be marked as possibly affected rather than no?+
Whenever the incident occurred in or near a product area and there is no positive evidence the product was untouched. 'No' should reflect confirmation, not absence of a reason to suspect otherwise.
Does every security incident need a full RCA?+
No. Investigation Level scales from none required through to cross-functional RCA, set against potential outcome. A minor unauthorised access with no loss and full CCTV coverage may only need a quick debrief; a break-in with insider suspicion should not.
Who should see a restricted record?+
The investigator, the site manager and security, and no one else by default. Widening access should be a deliberate decision tied to a specific need, such as HR involvement once insider involvement is confirmed rather than merely suspected.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Lone Working and Security
Food Defense Plan
Assesses where product could be deliberately contaminated and sets out how that is prevented
Security Risk Assessment
Assesses the site against theft, unauthorised access, sabotage and product tampering
Violence and Aggression Assessment
Assesses roles exposed to aggression from the public, hauliers or colleagues, and the controls in place
Lone Working Risk Assessment
Assesses tasks done alone, out of hours or out of sight, and how the person would raise an alarm
Lone Worker Check In Record
Records the agreed contact points during a period of lone working, and that each one happened
Access Control Review
Reviews who holds access to which areas and whether that is still justified
More in Security and Lone Working
Security Risk Assessment
Assesses the site against theft, unauthorised access, sabotage and product tampering
Violence and Aggression Assessment
Assesses roles exposed to aggression from the public, hauliers or colleagues, and the controls in place
Lone Working Risk Assessment
Assesses tasks done alone, out of hours or out of sight, and how the person would raise an alarm
Lone Worker Check In Record
Records the agreed contact points during a period of lone working, and that each one happened
Access Control Review
Reviews who holds access to which areas and whether that is still justified
CCTV and Monitoring Review
Reviews camera coverage, recording retention, image quality and who can view footage

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018 clauses 10.2, 8.1.2, 7.5.3 and 5.4
- RIDDOR 2013, reporting duty for work-related violence causing a reportable injury (UK)
- Data Protection Act 2018 / UK GDPR, lawful basis and retention for CCTV and personal data
- 29 CFR 1904, OSHA recordkeeping requirements (US)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.