Security operations

What Good Security Incident Reporting Should Tell the Customer

A practical guide to security incident, patrol and occurrence reporting for customers managing commercial premises.

Tornado FM Ltd Editorial Team5 min readPublished 14 July 2026
Security officer completing a digital incident report at commercial premises

A security report should enable the customer to understand what happened, what the security operative observed, what action was taken and what remains unresolved. A list of vague statements or ticked boxes does not provide effective operational control.

Good reporting supports immediate decisions, investigations, insurance enquiries, health and safety reviews, contract management and longer-term risk reduction. HSE guidance on investigating incidents emphasises gathering information, analysing it, identifying controls and implementing an action plan.

Different reports serve different purposes

The reporting structure should distinguish routine activity from exceptions and urgent incidents.

  • Shift or occurrence log – a chronological record of relevant activity during a guarding shift.
  • Patrol or inspection report – evidence that agreed locations and conditions were checked.
  • Incident report – a structured account of an event requiring action, escalation or investigation.
  • Alarm response report – details of the activation, attendance, findings, contacts and site condition.
  • Action log – outstanding issues, responsible persons, target dates and closure evidence.

Using the wrong report type can bury a serious issue in routine information or generate unnecessary incident reports for ordinary activity.

Record the essential facts

A useful incident report should normally include:

  • Date, time and precise location.
  • The reporting person and other people directly involved or present.
  • How the incident was discovered or reported.
  • What was seen, heard or found.
  • Immediate risks and any continuing hazard.
  • Actions taken and the authority for those actions.
  • People contacted, instructions received and reference numbers.
  • Evidence secured or preserved.
  • Outstanding actions and the person responsible for follow-up.

The report should be completed promptly while the details are fresh, but urgent safety and escalation actions take priority over writing.

Separate observation from assumption

Security personnel should record what they directly observed and identify information received from somebody else. They should not present an opinion as established fact.

Where an inference is operationally relevant, label it clearly and state the evidence supporting it. Accurate language protects the customer, the officer and any later investigation.

Create a reliable timeline

Time information helps the customer reconstruct an incident and assess response. Record times consistently and identify whether they come from personal observation, a system record, CCTV, an alarm receiving centre or another person.

  • Time the incident occurred, if known.
  • Time it was discovered or reported.
  • Time security attended or took control.
  • Time the customer or emergency service was contacted.
  • Time instructions were received and actions completed.
  • Time responsibility was transferred or the incident was closed.

Use photographs and video carefully

Images can show damage, position, condition and change over time. They can also contain personal data, confidential information or material relevant to a criminal investigation.

The customer and provider should define when images are appropriate, where they are stored, who can access them and how long they are retained. The ICO’s data-minimisation principle requires organisations to collect and hold personal data that is adequate, relevant and limited to what is necessary for the purpose.

Escalation is part of the report

A report should not be the first time the customer learns of a serious incident. The assignment instructions should identify immediate notification thresholds and the approved communication method.

  • Threat to life, violence or medical emergency.
  • Fire, smoke, flooding or a serious safety hazard.
  • Confirmed or suspected intrusion.
  • Loss of keys, access credentials or confidential material.
  • Major building damage or failure of a critical security system.
  • A person refusing to leave or comply where the situation is escalating.

The report should record the escalation without replacing it. It should show who was contacted, when, what information was given and what instruction followed.

Track actions to closure

A recurring weakness in operational reporting is the failure to close actions. The same broken gate, failed light or access-control fault may appear in several reports without a named owner or completion date.

  • Give each action a unique reference.
  • Assign an owner with authority to complete or commission the work.
  • Set a target date based on risk.
  • Record temporary controls while the permanent action is outstanding.
  • Require closure evidence and verify it where necessary.

Use reporting to identify patterns

Individual reports explain individual events. Management information should also show repeated issues by location, time, incident type or cause. HSE guidance on work-related violence recommends recording and reviewing incidents to determine whether further controls are needed.

  • Repeated alarm activations from the same zone.
  • Doors or gates regularly found unsecured.
  • Unauthorised access attempts during the same operating period.
  • Contractors failing to follow access or lock-up procedures.
  • Areas where lighting, fencing or visibility repeatedly contributes to concern.

Trend information should lead to decisions. A dashboard that does not trigger ownership or action has limited value.

Protect personal and sensitive information

Security reports may contain names, contact details, vehicle registrations, images, allegations or information about health and behaviour. The customer and provider should identify their respective data-protection roles, lawful basis, access controls and retention requirements.

Collect enough information to fulfil the reporting purpose, but avoid irrelevant personal detail or speculative commentary. Where information may be shared with the police or another authority, record the decision and share only what is necessary and proportionate.

What customers should agree during mobilisation

1. The report types required for each service and incident category.

2. Immediate escalation thresholds and authorised contacts.

3. Mandatory fields and terminology.

4. Rules for photographs, attachments and personal data.

5. Delivery method, recipients and expected timescales.

6. Action ownership and closure procedure.

7. Monthly or quarterly trend and performance information.

8. Quality checks and correction of inaccurate reports.

Reporting demonstrates service control

Professional reporting is not an administrative extra. It is evidence that the service was delivered, risks were identified and decisions were communicated. It also gives the customer information needed to improve the premises and hold the right people accountable.

Tornado FM Ltd provides manned guarding, mobile patrols, keyholding, alarm response, lock and unlock services, vacant-property inspections, security assessments and concierge or reception security. Reporting requirements should be specified for each assignment and agreed before mobilisation.

Ask Tornado FM Ltd how security activity, incidents and outstanding actions would be reported for your site.

Related Tornado FM Ltd pages

Sources and further reading

  • Health and Safety Executive, Investigating accidents and incidents: HSG245, guidance page updated 4 January 2022.
  • Health and Safety Executive, Reporting and learning from incidents of work-related violence, guidance accessed 14 July 2026.
  • Health and Safety Executive, RIDDOR - Reporting of Injuries, Diseases and Dangerous Occurrences Regulations, guidance accessed 14 July 2026.
  • Information Commissioner’s Office, Data minimisation, guidance accessed 14 July 2026.
  • Information Commissioner’s Office, Storage limitation, guidance accessed 14 July 2026.
  • Information Commissioner’s Office, Sharing personal data with law enforcement authorities, published 29 September 2023.

Source access date: 14 July 2026.

Chat with us on WhatsApp