Incidents

When things go wrong,
everything on record

A structured register for security and data incidents, from detection through investigation, containment and closure. Each incident carries its severity, owner and timeline, links the assets, risks and vendors it touched, and if personal data is involved, the GDPR 72-hour notification clock is tracked from the moment you flag it.

Start for freeBook a conversation
++++
app.devguard.ch / incidents
1 open
By severity
Critical00
High01
Medium02
Low04
Linked to assets, risks & vendors
Phishing compromise · finance mailbox
INC-007High
Detected
Feb 4 · 09:10
Investigating
Root cause: missing MFA
Contained
Mailbox isolated
GDPR Art. 33 — 54h left on the 72-hour notification clock
Every framework
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
ISO/IEC 27001SOC 2GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018Swiss nFADP
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • Swiss nFADP
How it works

Logged, worked, closed

Log what happened, work the response through five statuses with the breach clock in view, and close with root cause and lessons learned.

01

Log what happened

Name, severity, owner, threat class, when it occurred and when you detected it — the incident is a structured record from the first minute, owned by a business role so responsibility survives shift changes.

02

Work it through to closure

Open, investigating, contained, resolved, closed — the status reflects where the response stands, and resolution and closure timestamps are captured as they happen, so the timeline is a record rather than a reconstruction.

The 72-hour clock, tracked

Flag a personal-data breach and devguard tracks the GDPR Article 33 notification deadline from detection. The remaining time is on the incident and the date lands on your Deadlines calendar — no side-channel countdown in someone’s notes.

03

Link everything it touched

Attach the assets, risks, vendors, controls and treatment actions involved. The incident becomes part of the register: an asset shows its incident history, a vendor reassessment sees what went wrong, and the lessons learned feed the risks you score next.

Why it’s built this way

A register, not a ticket queue

Four choices behind how incidents work here — each one something you can check, not an adjective.

01

The breach clock is tracked, not remembered

Flag an incident as a personal-data breach and the GDPR Article 33 notification deadline is computed and tracked from the moment of detection — the 72-hour clock is never in someone’s head.

02

Linked to the register, not a standalone log

An incident links the assets, risks, vendors, controls and treatment actions it touched, so the record shows what was hit and what was done — not just what happened.

03

Timestamps that survive an audit

Occurred, detected, resolved and closed are captured as the response progresses, so the timeline you show an auditor or a regulator is the one that actually happened.

04

Closure means lessons learned

Root cause and lessons learned are fields on the incident, not a meeting that never happens — what you’d do differently is written down where the next responder finds it.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

What an incident connects to

An incident is never just its own story — it touches the assets, risks and vendors you already track, and its deadlines land on the same calendar.

2.0SCORE

Risks

An incident’s lessons feed the risks you score and treat.

1,284
assets tracked
+12 today

Assets

Link the systems an incident touched, from one inventory.

AWAWSReviewed
CFCloudflareReviewed
StStripe

Vendors

When a third party is involved, the incident says so.

JUN
ISO review
in 3 days

Deadlines

Breach-notification deadlines land on the same calendar.

FAQ

The questions evaluators ask.

Does devguard detect incidents for me?

No — devguard is the incident register and response record, not a monitoring tool. You log an incident when you become aware of it; devguard then structures the response: severity, status, timeline, linked assets and vendors, root cause and lessons learned. Your detection stack stays whatever it is today.

How does the GDPR breach deadline work?

Flag an incident as a personal-data breach and devguard tracks the Article 33 notification deadline — 72 hours from detection. The remaining time is visible on the incident and the deadline surfaces on the Deadlines calendar, so the clock is never missed because nobody was counting.

What can I link to an incident?

The assets, risks, vendors, controls and treatment actions involved. The links work both ways: the incident shows everything it touched, and an asset or vendor shows the incidents it was part of — useful in reviews and reassessments.

How is this different from a spreadsheet or a ticket?

A ticket closes and disappears into the queue; a spreadsheet row has no timeline, no severity model and no links. A structured register gives you lifecycle timestamps, the breach clock, and the connections to assets, risks and vendors — the things ISO 27001 and GDPR actually ask you to demonstrate.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Your incident register is yours and exportable in full at any time, with no lock-in.

Respond with a record, not a reconstruction

Log incidents with severity, owner and timeline, keep the GDPR notification clock in view, and close each one with the root cause and lessons the next response will need.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free