Last updated: January 21, 2026
A security incident report is a formal written record created by a security guard to document an event that affected (or threatened) people, property, or site safety. It matters because it preserves facts, timelines, and actions taken so supervisors, clients, and authorities can review what happened and decide next steps.
What To Do First (Scene Safety)
Before writing anything, handle the incident.
- Protect life and prevent escalation.
- Call for assistance/medical help if needed.
- Follow post orders and notify the proper contacts.
- When the scene is stable, start notes and preserve details.
When Should a Guard Write an Incident Report?
Write an incident report when something unusual, unsafe, or policy-relevant happens on post, including:
- Threats or violence (attempted or actual).
- Theft, vandalism, trespassing, or access-control issues.
- Accidents, injuries, hazards, or property damage.
- Any event requiring escalation to a supervisor, client contact, or law enforcement.
Best practice workflow:
- Handle the incident first.
- Capture preliminary notes immediately (times, names, descriptions).
- Complete the full report as soon as possible while the details are fresh.
What to Include (Minimum) — 5W/1H
At minimum, a security incident report should answer the 5W/1H so the reader can quickly understand the full context without guessing: who reported the incident and who was involved (including witnesses and responders such as guards, staff, EMS, or police), what happened and what was directly observed (facts only), and when it occurred (exact date/time, plus when it was discovered and when it was reported). It should also specify where it happened with an exact location (address and specific area, such as building/floor/door or gate number, and the camera zone if known). Finally, document why it may have happened only if supported by observed facts (otherwise note “Cause unknown—under review”) and how it unfolded, including the sequence of events, how it was detected, and how the response was carried out.
6-Step Process (Guard-Friendly)
- Take immediate notes safely. Write quick timestamps, descriptions, and names as soon as the situation allows.
- Record who/what/when/where. Lock down the basic facts first (it anchors the entire report).
- Write a chronological incident narrative. Create a clear timeline from first observation to the resolution.
- Document witness statements and suspect descriptions. Identify sources and what each person stated/observed.
- Log evidence and chain of custody. Note CCTV camera IDs, photos taken, and how evidence was handled/stored.
- Record actions, notifications, and follow-ups. Include escalation calls, report numbers, corrective actions, and next steps.
How to Write the Incident Narrative (Objective + Quotable)
Use an “incident narrative” style that reads like a timeline.
- Write in chronological order with clear timestamps (or “approx.” if needed).
- Use observed facts: what was seen/heard, what policies were triggered, what actions were taken.
- Avoid conclusions you cannot prove (no guessing motives, intoxication, intent, or identity).
- Use specific identifiers: clothing, height/build, direction of travel, vehicle plate/state, badge numbers, camera numbers.
- Keep pronouns clear (use names/roles instead of “he/they” when it could be confusing).

Include these Details When Relevant
- Witness statement: Who said what, when, and where they were standing/located.
- Suspect description: Sex/age range, height/build, clothing, distinguishing features, direction of travel, vehicle details.
- Evidence (CCTV/photos): Camera number, timestamp range, file name, where it’s stored, and who has access.
- Chain of custody: Who collected the item/media, where it was secured, and to whom it was transferred.
- Impact assessment: Injuries, damage, downtime, safety risk, or disruption to operations.
- Corrective actions: Immediate fixes taken (secured door, posted signage, escorted subject, hazard barricade).
- Notifications/escalation: Who was notified, when they were notified, and what instructions were received.
- Report number/case number: Internal report # and any law enforcement case # (if assigned).
Incident-Type Mini Examples (Quick Models)
Example 1: Trespassing (after-hours entry)
- What happened: An unknown male entered the restricted loading area after hours.
- Evidence: CCTV Camera 7 shows entry at 02:14 and exit at 02:18.
- Action taken: Guard approached, issued verbal directive to leave, subject exited without incident; supervisor notified.
Example 2: Theft (shoplifting/asset removal)
- What happened: The employee observed the suspect conceal merchandise and exit without payment.
- Evidence: CCTV coverage noted; witness statement obtained from cashier.
- Action taken: Guard followed post orders, maintained observation, contacted supervisor, and law enforcement as required.
Example 3: Accident/Injury (slip/trip)
- What happened: Visitor slipped near lobby entrance; complained of ankle pain.
- Evidence: Photos of floor condition and warning signage; witness statement from receptionist.
- Action taken: First aid offered per policy; EMS called; area secured with wet-floor signage; incident escalated to management.
Security Incident Report Template
Incident details
- Report number/case number:
- Date report written:
- Date/time incident occurred:
- Date/time discovered (if different):
- Exact location (address + area):
- Incident type (select one): [Theft / Trespassing / Vandalism / Assault / Injury / Access denial / Property damage / Other]
- Severity: [Low / Medium / High]
- Weather/lighting conditions (if relevant):
Reporting officer/post
- Guard/officer name:
- Post assignment/patrol area:
- Shift start/end time:
- Supervisor on duty:
Involved parties
- Victim(s) name/contact (if applicable):
- Witness(es) name/contact:
- Suspect(s) info (if applicable):
- Description (sex/age range/height/build):
- Clothing/identifiers:
- Direction of travel:
- Vehicle (plate/state/make/model):
Incident narrative (timeline + observed facts)
- 00:00 — (First observation/dispatch / call received)
- 00:00 — (Actions taken by guard)
- 00:00 — (Subject statements — quote if important)
- 00:00 — (Witness statements — source and location)
- 00:00 — (Resolution/scene stabilized)
Evidence and documentation
- CCTV: camera #/location + timestamp range:
- Photos taken: [Yes/No] (file names / where stored):
- Attachments: [Statements / Images / Logs / Access control records / Other]
- Chain of custody notes (if any physical items/media):
Impact + actions taken
- Injuries (describe):
- Property damage (describe/estimated):
- Immediate actions taken (first aid, escort, barricade, lock reset, etc.):
- Notifications/escalation (who + time + instruction):
- Law enforcement / EMS (agency + badge/unit + case #):
Follow-up / corrective actions
- Additional steps required:
- Recommended corrective actions:
- Lessons learned / prevention notes:
- Supervisor review required: [Yes/No]
Signature
- Guard/officer signature + date/time:
- Supervisor signature (if required) + date/time:

Bad vs Good Sentences (Micro Examples)
- Bad: “The suspect was acting suspicious and probably high.”
- Good: “The male subject had slurred speech, unsteady walking, and an odor of alcohol was observed at close range.”
- Bad: “He ran away, and we did everything.”
- Good: “At 21:43, the subject ran east toward Lot B. Guard A maintained visual for ~10 seconds and notified dispatch at 21:44.”
- Bad: “The door was broken.”
- Good: “Door 3’s strike plate was loose, and the latch did not seat; the door could be pulled open without a credential.”
Security Incident Handling and Response: Best Practices
Security guards and organizations can enhance their understanding of incident handling by consulting the comprehensive “Computer Security Incident Handling Guide” by the National Institute of Standards and Technology (NIST). This guide provides in-depth information on preparing for, detecting, analyzing, and responding to security incidents. It serves as an essential resource for developing a robust incident response strategy that minimizes damage and restores services efficiently.
Government-Supported Incident Reporting Systems
The Cybersecurity and Infrastructure Security Agency (CISA) operates a sophisticated Incident Reporting System that supports the timely handling and analysis of security incidents. This system allows security personnel to report incidents securely, contributing to national efforts to enhance cybersecurity resilience. The system also allows for improved analysis and response strategies, ensuring that each incident is handled with the appropriate urgency and attention to detail.
FAQs
What should a security incident report include?
- Date/time, exact location, incident type, and report number (if used).
- People involved (witnesses/victims/suspects) and contact info when permitted by policy.
- A chronological incident narrative with observed facts.
- Evidence (CCTV/photos/attachments), actions taken, notifications, and follow-up steps.
When should a guard write an incident report?
- After the incident is controlled and scene safety is addressed.
- After capturing preliminary notes (times, names, descriptions).
- As soon as practical, preferably on the same shift, to preserve accuracy.
How do you write an incident report narrative?
- Start with the first observable event and move forward in time.
- Use objective, specific details (who did what, where, and when).
- Document actions taken, who was notified, and the outcome.
Do you include opinions in an incident report?
- No—stick to observed facts and documented statements.
- If something is unknown, state it as unknown and avoid assumptions.
- If policy requires an assessment, label it clearly as an “assessment” and support it with observed facts.
Check other blogs
The Modern Approach: How Does Loss Prevention Work?
Cloud-Based Access Control: Is It Right for Your Business?
Guarding Green: The Crucial Shifts in Dispensary Security Needs
Community Security Guard Services: The Complete Protection Guide

