Security Incident Logbook: Free Excel Template
Free Excel template: an ongoing register for every security incident in a given year, including non-reportable ones, with automatic §32 BSIG deadline calculation.
Free download
Security incident logbook as an Excel template
A register for every security incident in a given year, including those that are not reportable, exactly what an audit asks for and what the BSI IT-Grundschutz module on incident handling requires as documentation.
- One row per incident: category, severity, affected assets and protection goals, cause
- Separate §32 BSIG and Art. 33 GDPR assessment columns, each with its own reporting status and timestamps
- Extra tabs: escalation and contact matrix, severity definitions
XLSX · 18 KB · no email required · updated August 2026
A security incident is rarely a single event that ends once you've reported it to the BSI. Over the course of a year, phishing attempts, minor access incidents, and occasionally significant incidents under §32 BSIG with running deadlines all add up (see NIS2 Reporting: When, What, and to Whom?). If an audit only finds the incidents you actually reported, that's a problem: the BSI IT-Grundschutz module DER.2.1 (handling security incidents) requires consistent documentation of every incident, not only the reportable ones.
The Security Incident Logbook is a free Excel template from NIS2Compass built for exactly that: an ongoing register for every security incident in a given year.
What's inside the logbook
The workbook has four sheets:
- Incident Register: 60 prepared rows with category, severity, affected assets and protection goals, cause, separate assessment columns for reportability under §32 BSIG and Art. 33 GDPR, reporting status with timestamps per stage, automatically calculated deadlines for the early warning (24 hours) and the notification (72 hours) from awareness, owner, immediate measures, and lessons learned
- Escalation & Contact Matrix: contact roles from the reporting owner to the BSI reporting portal, plus internal escalation levels by severity
- Severity Definitions: an internal classification scheme for prioritisation, explicitly separate from the statutory significance test
Why a separate register makes sense
Reportability under §32 BSIG and reportability under Art. 33 GDPR are two separate assessments with different deadlines and different recipients, even though the same incident can trigger both. The logbook tracks both assessments side by side instead of blending them into one field. The logbook doesn't itself perform the significance test: that's preparatory work, covered in detail in the article on significant security incidents and reporting obligations.
Who the template is for
The template is built for the ISB doing incident follow-up and audit preparation: documenting as you go means you don't have to reconstruct the timeline when it matters.
Does the logbook replace the significance test under §32 BSIG?
No. The logbook documents the result of the assessment, it doesn't perform it. The significance test under §2 no. 11 BSIG remains a separate step.
Do I have to document incidents that aren't reportable?
Yes. The IT-Grundschutz module DER.2.1 requires consistent documentation of every security incident, not only the ones reported to the BSI. That's exactly what the incident register is built for as an ongoing annual log.
For a structured path through the whole process, from awareness to the final report, see the NIS2 Guide.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with an Implementation Guide, templates and Knowledge Hub.
Get startedÄhnliche Artikel
What Happens After You Report to the BSI?
What happens after a BSI report: acknowledgment of receipt, possible audit, customer notification duty — and why you can't withdraw it.
7 Min. Lesezeit
NIS2 Reporting Templates: §32 BSIG Notification Stages
The three §32 BSIG notification stages (early warning, initial notification, final report) with fully worded sample texts for ransomware, data exfiltration, and DDoS, ready to adapt.
12 Min. Lesezeit
When Is a Security Incident Reportable? (§ 32 BSIG)
A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.
9 Min. Lesezeit