Knowella

Security Incident Investigation

A security incident investigation records theft, break-in, unauthorised access, tampering or threat once the situation is safe. Its recurring failure is speed working against evidence: CCTV overwrites itself in days, a confronted intruder produces an injury nobody assessed, and by the time the form is opened the scene has already been tidied by someone trying to help.

KnowSafeRecordSAF-146Pinned in navigation48 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 45001 cl.10.2
Workspace
KnowSafe
Form type
Record
Completed by
Whoever discovered it, at the moment it is safe to do so
Raised
Immediately, not reconstructed from memory the next day

The short version

  • This record deliberately keeps facts and conclusions apart. The description field asks for what was seen and found, with no conclusions about who or why, because an investigation that starts with a suspect stops looking at anything else.
  • Confronting is not investigating. The form scores 'Anybody Confronted' at zero for yes and three for no, because a recovered item is worth less than an avoidable injury, and confrontation has produced more injuries than recoveries.
  • Evidence has a shelf life the paperwork does not respect. CCTV systems overwrite footage on a cycle measured in days, so 'Footage Retained' asks whether it was exported, not whether it exists, and a record completed a week late can find nothing left to retain.
  • Investigation level is set by what could have happened, not what did. A near-miss break-in with nobody present still needs the same rigour as one with a confrontation, because the next attempt might not be so quiet.

What this is

What is a security incident investigation?

What is a security incident investigation?

A record of a theft, break-in, unauthorised access, tampering or threat, capturing what was found, what was done immediately, what evidence was preserved, and why it happened, so a similar event is either prevented or handled better next time. It sits apart from the general safety incident stream because it usually involves named individuals and evidence that may become a police matter.

How is a security incident different from a safety incident?

A safety incident is investigated to find out what failed in a process or control. A security incident starts from the presumption that somebody did something deliberately, which changes the first response: preserve the scene rather than make it safe for work to resume, and restrict who can see the record rather than share it for lessons learned.

Who should complete it?

Whoever discovered the incident, as close to the moment as possible. The record is not written by security staff after the fact from a verbal account; the discoverer's own factual description is the version least altered by hindsight or hearsay from others on site.

Scope

When is a security incident investigation required?

This record is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use this template when

  • Theft, break-in, unauthorised access, tampering or a threat has occurred, or was attempted
  • The workspace is being set up, or the singleton register needs establishing for the site
  • You are running the Lone Working and Security programme and this is its incident stream
  • A linked record needs this one to exist: RCA for a full investigation, Security Assessment for a review of controls
  • Product integrity may have been affected and a hold needs to be raised against it

Do not use it for

  • Security Risk Assessment, which assesses the site before an incident, not what happened during one.
  • Violence and Aggression Assessment, which assesses roles exposed to aggression generally, rather than recording a specific event.
  • CCTV and Monitoring Review, which periodically reviews coverage and system health, not a single incident's footage.
  • Site Security Audit, which periodically audits the whole security posture, not one occurrence.
  • The Root Cause Analysis or CAPA record itself once one is raised, which is a linked but separate record with its own investigation content.

Compliance mapping

Which ISO 45001 cl.10.2 requirements does this satisfy?

ISO 45001 treats a security incident as a work-related incident like any other once it has, or could have, resulted in harm, which is why this record sits inside the same clause as any safety investigation. What differs is the handling of evidence and personal data, which falls outside the standard entirely.

ClauseRequirementWhere it lands
ISO 45001 cl.10.2Incidents reacted to in a timely way and investigated with the involvement of relevant workers to determine what happenedWhat happened
ISO 45001 cl.8.1.2Operational controls applied to eliminate or reduce risk during the immediate response, not just afterwards in the write-upImmediate response
ISO 45001 cl.7.5.3Documented information, including evidence such as footage and records, protected and controlled before it is lost or alteredEvidence
ISO 45001 cl.5.4Consultation and participation of workers, applied here as statements taken from witnesses and the discovererEvidence
ISO 45001 cl.10.2Root cause determined and reviewed against whether similar incidents exist or could occur elsewhere on siteCause and prevention
ISO 45001 cl.6.1.2.1Hazard identification proactive and ongoing, extended here to insider involvement and control failure rather than assumed absentCause and prevention
ISO 45001 cl.7.5.3Access to documented information restricted where its content, such as named individuals and allegations, requires itCause and prevention

What it does not cover

  • Security Risk Assessment, which assesses the site's exposure to theft, unauthorised access, sabotage and tampering before an event, not after one.
  • Root Cause Analysis, which this record can trigger but does not itself perform once Investigation Level is set above a quick debrief.
  • CAPA record, which tracks the corrective action to a verified close once Action Required is set, separate from the investigation itself.
  • Employee disciplinary process, which follows from a finding of insider involvement but is run through HR, not through this record.
  • Police investigation, which this record supports with a crime reference and preserved evidence but does not substitute for.

Global

Security Incident Investigation requirements by country

No jurisdiction regulates a 'security incident' as a named category. What applies instead is the general duty to investigate work-related harm, and separately, the rules governing personal data and evidence gathered along the way.

United States

OSHA recordkeeping (29 CFR 1904); General Duty Clause

No federal duty to investigate theft or break-in as such, but an incident involving injury, including one arising from a confrontation, falls under standard recordkeeping and the General Duty Clause.

The security content of the record is voluntary good practice; the moment it produces an injury, it becomes a recordable event like any other.

United Kingdom

RIDDOR 2013; Data Protection Act 2018 / UK GDPR

Work-related violence causing a reportable injury falls under RIDDOR. Separately, CCTV footage and named individuals in the record are personal data subject to lawful basis and retention limits.

Restricting access to the record is not just good discipline, it is close to a data protection requirement once allegations against named people are involved.

International

ISO 45001

A management system requirement to investigate incidents, determine root cause, and take corrective action, applied here to a security event with the potential for harm.

Certification auditors will ask why a security incident with a plausible harm outcome was, or was not, investigated to the same standard as a safety one.

How to complete it

How to complete a security incident investigation, step by step

The form prompts for the facts. Whether the record ends up defensible depends on judgement calls it cannot make for the person completing it.

Set investigation level by what could have happened

The help text is explicit: set by potential outcome, not by what actually happened. A break-in discovered empty-handed with nobody present still deserves the same rigour as one that ends in confrontation, because the difference between the two is often timing rather than intent.

Export the footage before writing the description

Most systems overwrite CCTV on a rolling cycle measured in days, sometimes hours on busy cameras. If the record is opened, description written and CCTV review deferred to later in the shift, the footage that would have settled 'Time Of Occurrence Known' as anything but unknown may already be gone.

Keep the factual description free of conclusions

The help text asks for what was seen and found, not who or why. An account that names a suspect on first write becomes the frame every subsequent question is answered inside, and it is very hard to walk back once statements start referencing it.

Restrict access as a decision, not a default

Access Restricted To This Record exists because most records in the library are not restricted, and this one usually should be. Leaving it at No because nobody thought to change it is a different failure from deciding restriction is not warranted and being able to say why.

What auditors find

Most common security incident investigation findings

The record usually exists after the fact; findings concern whether it was completed while the evidence still could be, and whether it stayed factual.

FindingClauseWhat fixes it
CCTV footage not exported before the retention cycle overwrote it.ISO 45001 cl.7.5.3Export footage on discovery, before the description is written, regardless of how minor the incident appears.
Scene not preserved or only partly secured before staff resumed normal work in the area.ISO 45001 cl.8.1.2Cordon the area on discovery and hold it until evidence has been reviewed, even where the loss looks minor.
Investigation Level set to reflect the outcome that occurred rather than what could have occurred.ISO 45001 cl.10.2Reassess level against the worst plausible outcome of the same event, not the actual one.
Record left unrestricted despite naming an individual or containing an unresolved allegation.ISO 45001 cl.7.5.3Restrict access at the point a name or allegation enters the record, not after the fact.
Control failure identified with no corresponding Security Assessment review triggered.ISO 45001 cl.6.1.2.1Trigger the assessment review whenever a specific control is named as having failed, not only for repeat incidents.
Discoverer confronted the individual involved before reporting.ISO 45001 cl.8.1.2Reinforce observe-and-report through conflict and aggression training, and treat confrontation as a training gap, not a one-off lapse.

Case in point

Case in point: the footage that was already gone

A cold store site found a padlock cut and a pallet of high-value stock missing on a Monday morning. The discoverer, a warehouse supervisor, wrote a thorough factual description, correctly did not confront anyone since nobody was present, and secured the area. CCTV Reviewed was marked yes later that day. Footage Retained was left at no, because the reviewer watched the relevant hour on screen, confirmed a vehicle had reversed up to the yard gate overnight, and moved on to the next task assuming the recording would still be there when needed.

The system's retention cycle was four days. By the time police asked for the footage to support a crime reference, it had been overwritten twice over. The description, the crime reference and the insurer notification were all in order; the one piece of evidence that could have identified a vehicle was gone because reviewing it on screen was treated as equivalent to keeping it.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

48fields
5 sections
Reference
SAF-146
Archetype
Record
Record ID
CASE-2026-000
Scoring
Open cases
Direction
Low is good
Singleton
Yes
Basis
ISO 45001 cl.10.2
Links
Links RCA, Security assessment
Tags
Security
Sections
5
Fields
48
Follow up fields
6
Repeating sections
0
Links out
5
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

12 fields
Text

Case ID*

Generated on save

Auto sequence. Format CASE-2026-00000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Single Choice

Area

Optional

The area within the site.

Cutting roomBoning hallPackingChill storeFreezerPasteurisingFillingCulture roomDespatchYardWorkshopPlant roomOffices
Location

Exact Location

Optional

Drop a pin for anything hard to find.

Info

Handled Separately And Carefully

Security incidents often involve named individuals, allegations and evidence that may become a police matter. Restrict access to this record and keep the account factual.

Single Choice

Incident Type*

RansomwarePhishingUnauthorised accessDenial of serviceMalwareData loss
Date & Time

Time Discovered*

Users

Discovered By*

What happened

7 fields
Text

Factual Description*

What was seen and found. No conclusions about who or why.

Text

Property Or Product Involved

Optional
Numeric Answer

Estimated Value

OptionalScored
Single Choice

Product Integrity Affected*

Scored
  • No3 pts
  • Possibly1 pt
  • Yes0 pts
Text

Hold ID

OptionalLinkedShows if Product Integrity Affected equals Yes

Links to QUA-003 Hold ID

Single Choice

Time Of Occurrence Known

Optional
YesApproximateUnknown
Single Choice

Repeat Of Previous Incident*

Scored
  • No3 pts
  • Yes0 pts

Immediate response

6 fields
Single Choice

Scene Preserved*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Area Secured*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Anybody Confronted*

Scored

Confronting a thief has produced more injuries than it has recovered stock. Observe and report.

  • No3 pts
  • Yes0 pts
Single Choice

Police Notified*

Scored
  • Yes3 pts
  • Not appropriate3 pts
  • No0 pts
Text

Crime Reference

Optional
Single Choice

Insurer Notified

Optional
YesNot neededNo

Evidence

6 fields
Single Choice

CCTV Reviewed*

Scored
  • Yes3 pts
  • No coverage1 pt
  • No0 pts
Single Choice

Footage Retained*

Scored

Systems overwrite quickly. Export the footage before it is lost.

  • Yes3 pts
  • No1 pt
Single Choice

Access Records Reviewed*

Scored
  • Yes3 pts
  • No0 pts
Numeric Answer

Witnesses Identified

Optional
Single Choice

Statements Taken

OptionalScored
  • Yes3 pts
  • No0 pts
Single Choice

Photographs Taken*

Scored
  • Yes3 pts
  • No0 pts

Cause and prevention

17 fields
Single Choice

Control Failure Identified*

Scored
  • No2 pts
  • Yes0 pts
Single Choice

Which Control

Optional
PerimeterAccess controlCCTVKey controlSupervisionScreening
Single Choice

Insider Involvement Suspected*

Scored
  • No3 pts
  • Possible1 pt
  • Yes0 pts
Single Choice

Investigation Required*

Scored

Set by potential outcome, not by what actually happened.

  • No3 pts
  • Yes0 pts
Single Choice

Investigation Level

OptionalShows if Investigation Required equals Yes
None requiredQuick debrief5 WhyFull RCACross functional RCA
Text

RCA ID

OptionalLinkedShows if Investigation Required equals Yes

Format RCA-2026-00000.

Links to FDN-013 RCA ID

Single Choice

Security Assessment Review Triggered*

Scored
  • Yes3 pts
  • Not needed3 pts
  • No0 pts
Text

Assessment ID

OptionalLinked

Links to SAF-142 Assessment ID

Single Choice

Access Restricted To This Record*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Site Manager*

Signature

Signature*

Users

Security*

Signature

Second Signature*

SAF-146 · record IDs look like CASE-2026-000 · Links RCA, Security assessment

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The record is the easy part once someone is on scene. What fails is the minutes before it is opened and the evidence trail that runs cold once the record is filed and forgotten.

KnowSafe

Holds the incident register against site and area, flags when a control failure has not triggered a Security Assessment review, and tracks restricted access on named records.

KnowQuality

Picks up product integrity findings and turns them into a hold record automatically, rather than leaving the link to be made by hand.

KnowTrain

Connects a confrontation finding to conflict and aggression training due dates, so the response to a lapse is retraining, not a note in a file.

Ella
Ella

Nudges CCTV export within the retention window rather than after it, and holds every write to a restricted record for explicit approval.

This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.

Meet KnowSafe→

Glossary

Security Incident Investigation definitions and key terms

Scene preservation
Keeping an area untouched after discovery so evidence is not disturbed, distinct from making an area safe, which can involve moving or cleaning things.
Crime reference
The number issued by police once a report is logged, used to link this record, the insurer notification and any later correspondence to the same reported event.
Insider involvement
A finding that someone with legitimate access, rather than an external party, is suspected of causing or enabling the incident, which changes who the investigation can safely involve.
Investigation level
The depth of follow-up required, from a quick debrief through to a cross-functional root cause analysis, set by potential severity rather than actual outcome.
Product integrity affected
A finding that the incident may have compromised product, which routes the record to a hold rather than leaving contamination or tampering risk unaddressed.

FAQ

Frequently asked questions about security incident investigation

Should we wait for security or the police before completing the record?+

No. Discovery, immediate response and evidence preservation happen in the minutes after the event, and the record should be opened then, by whoever found it. Security and police involvement layer on top; they do not gate the first entry.

What if we don't know whether it's a security incident or a safety incident yet?+

Start here if there is any suggestion of a deliberate act: theft, unauthorised access, tampering or a threat. If the investigation later shows it was accidental, the record still stands as the accurate account of what was found; it does not need to be recreated in the safety stream.

Why does the form penalise confronting someone, even if the item was recovered?+

Because the scoring is about risk to the person, not the outcome of the recovery. A confrontation that goes well this time sets no precedent for the next one, and the form is written to discourage the behaviour regardless of how it turns out.

When should product integrity be marked as possibly affected rather than no?+

Whenever the incident occurred in or near a product area and there is no positive evidence the product was untouched. 'No' should reflect confirmation, not absence of a reason to suspect otherwise.

Does every security incident need a full RCA?+

No. Investigation Level scales from none required through to cross-functional RCA, set against potential outcome. A minor unauthorised access with no loss and full CCTV coverage may only need a quick debrief; a break-in with insider suspicion should not.

Who should see a restricted record?+

The investigator, the site manager and security, and no one else by default. Widening access should be a deliberate decision tied to a specific need, such as HR involvement once insider involvement is confirmed rather than merely suspected.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 45001:2018 clauses 10.2, 8.1.2, 7.5.3 and 5.4
  • RIDDOR 2013, reporting duty for work-related violence causing a reportable injury (UK)
  • Data Protection Act 2018 / UK GDPR, lawful basis and retention for CCTV and personal data
  • 29 CFR 1904, OSHA recordkeeping requirements (US)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.