PV
PilotVantage

Incidents

Log security incidents and drive them through a clear, repeatable lifecycle so nothing slips through the cracks.

When something goes wrong — a phishing email, a lost laptop, a suspected breach — you raise an incident in PilotVantage and work it to a close. Every incident gets an automatic reference like INC-2026-0001, a running timeline, and a status that reflects exactly where it stands.

The incident lifecycle

Each incident moves through a defined set of statuses. You advance it one step at a time as the situation develops, and you can Reopen a closed incident if new information comes to light.

  • ReportedTriagedInvestigatingContainedResolvedClosed
One step at a time
Status changes follow the lifecycle order, so your records stay consistent and audit-ready. Each transition is stamped on the timeline automatically.

Reporting an incident — step by step

n
The numbered red callouts in each screenshot mark exactly where to click or type. Screenshots are from our demo workspace.

1. Open Incidents and click Report Incident

Click Incidents in the sidebar, then Report Incident in the top-right corner of the register.

PilotVantage sidebar with Incidents highlighted
Incident register with the Report Incident button highlighted

2. Describe and classify it

Capture a clear title and a factual description — updates come later on the timeline. Pick a category and set the severity.

Incident form with title, description, category and severity annotated

3. Assign an owner and add context

Give the incident an owner, record when it occurred, list the affected systems, and tick personal data involved if applicable — it flags your GDPR notification duties.

Incident form with owner, occurred time, affected systems and personal data flag annotated

4. Report it

Click Report Incident. The incident is created in Reported status with an automatic reference.

Report Incident submit button highlighted
Created incident page showing the reference, Reported status and Triage button

5. Drive it through the lifecycle

Advance the incident one step at a time — Triage, then investigation onwards. Every transition updates the status and is stamped on the activity log, and the next step is always one click away.

Incident after triage showing the Triaged status and Start Investigation button

6. Work it to a close

Record updates on the timeline as you go, attach evidence, raise remediation actions, and link related risks. Once contained and remediated, move it to Resolved and then Closed.

Incident Response Playbooks

Alongside your incidents, PilotVantage gives you Incident Response Playbooks — step-by-step response guides for scenarios such as phishing, ransomware and data breach. Create a playbook from a built-in template, keep it beside your live incidents, and tag it to the relevant ISO controls so your response process is demonstrably in place.

Ready when you need it
Prepared playbooks mean your team responds calmly and consistently under pressure, instead of improvising.

Works with

  • Evidence — attach proof to any incident.
  • Actions — track remediation to closure.
  • Controls — tag playbooks to the ISO controls they support.
  • Reports — surface incident activity for management review.