Security Incident Logbook: Free Excel Template

Free Excel template: an ongoing register for every security incident in a given year, including non-reportable ones, with automatic §32 BSIG deadline calculation.
Free download
Security incident logbook as an Excel template
A register for every security incident in a given year, including those that are not reportable, exactly what an audit asks for and what the BSI IT-Grundschutz module on incident handling requires as documentation.
- One row per incident: category, severity, affected assets and protection goals, cause
- Separate §32 BSIG and Art. 33 GDPR assessment columns, each with its own reporting status and timestamps
- Extra tabs: escalation and contact matrix, severity definitions
XLSX · 22 KB · no email required · updated September 2026
A security incident is rarely a single event that ends once you've reported it to the BSI. Over the course of a year, phishing attempts, minor access incidents, and occasionally significant incidents under §32 BSIG with running deadlines all add up (see NIS2 Reporting: When, What, and to Whom?). If an audit only finds the incidents you actually reported, that's a problem: the BSI IT-Grundschutz module DER.2.1 (handling security incidents) requires consistent documentation of every incident, not only the reportable ones.
The Security Incident Logbook is a free Excel template from NIS2Compass built for exactly that: an ongoing register for every security incident in a given year.
What's inside the logbook
The workbook has four sheets:
- Incident Register: 60 prepared rows with category, severity, affected assets and protection goals, cause, separate assessment columns for reportability under §32 BSIG and Art. 33 GDPR, reporting status with timestamps per stage, automatically calculated deadlines for the early warning (24 hours) and the notification (72 hours) from awareness, owner, immediate measures, and lessons learned
- Escalation & Contact Matrix: contact roles from the reporting owner to the BSI reporting portal, plus internal escalation levels by severity
- Severity Definitions: an internal classification scheme for prioritisation, explicitly separate from the statutory significance test
Why a separate register makes sense
Reportability under §32 BSIG and reportability under Art. 33 GDPR are two separate assessments with different deadlines and different recipients, even though the same incident can trigger both. The logbook tracks both assessments side by side instead of blending them into one field. The logbook doesn't itself perform the significance test: that's preparatory work, covered in detail in the article on significant security incidents and reporting obligations.
Who the template is for
The template is built for the ISB doing incident follow-up and audit preparation: documenting as you go means you don't have to reconstruct the timeline when it matters.
Does the logbook replace the significance test under §32 BSIG?
No. The logbook documents the result of the assessment, it doesn't perform it. The significance test under §2 no. 11 BSIG remains a separate step.
Do I have to document incidents that aren't reportable?
Yes. The IT-Grundschutz module DER.2.1 requires consistent documentation of every security incident, not only the ones reported to the BSI. That's exactly what the incident register is built for as an ongoing annual log.
For a structured path through the whole process, from awareness to the final report, see the NIS2 Guide.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.
Get startedRelated Articles
CRA Reporting: How Art. 14 Differs from Section 32 BSIG
Since 11 September 2026, manufacturers must report under Art. 14 CRA via the ENISA platform. Where it differs from § 32 BSIG, and why one incident can mean two reports.
10 min read
Cyber Resilience Act and NIS2: Do Both Apply to You?
Since 11 September 2026, manufacturers must report exploited vulnerabilities under the CRA. What this means for NIS2 entities, and why most IT managers are only indirectly affected.
8 min read
§65 BSIG: What Fine Tiers Apply to NIS2 Violations?
§65 BSIG tiers NIS2 fines into seven brackets, from EUR 100,000 to EUR 10 million or 2% of turnover. NIS2Compass explains the assessment criteria and real GDPR comparison cases.
12 min read