If anyone is in immediate danger, call 911 first. If the threat has passed, secure the scene, keep people away from evidence, and notify your on-site security lead or manager right away. Start capturing timestamped notes within minutes, then move into the formal incident report. That sequence, in that order, is the entire foundation of a defensible security incident reporting procedure.
TL;DR:
- Staff must distinguish between emergencies and non-emergencies to ensure the correct reporting channel is used, affecting response timing and actions.
- Incident reports need detailed, objective information, including location specifics, witness statements, evidence logs, and proof of submission to remain legally valid.
- Escalation should follow a three-tier severity system, with high-severity incidents requiring immediate notification of multiple stakeholders and law enforcement.
- Prompt evidence collection, including exporting video footage and labeling physical items, is critical to maintain chain of custody and support future investigations.
- Regular drills, audits, and staff training are essential to ensure the incident response process remains effective and is properly followed under pressure.
Table of Contents
- What Are Security Incident Reporting Procedures for On-Site Threats?
- What Should Staff Do in the First Minutes of an Incident?
- What Belongs on a Security Incident Report Form?
- When Should You Escalate and Who Needs to Know?
- How Do You Preserve Evidence and Chain of Custody?
- Who Owns the Post-Incident Review and When Is It Due?
- How Often Should You Drill and Audit Reporting Procedures?
- What Do Most Facilities Get Wrong About Incident Reporting?
- How Hub Investigative Group Helps You Build These Procedures
- Where Can You Find Reporting Templates and Guidance?
- Sources
What Are Security Incident Reporting Procedures for On-Site Threats?
Security incident reporting procedures are the defined steps staff and security officers follow from the moment an incident is discovered through final documentation and review. They exist because the first five minutes after a theft, assault, or trespass determine whether you have a clean record or a mess of conflicting memories weeks later.
Government guidance is unambiguous on the first decision point: call 911 for any threat to life or safety, and use your local police department’s non-emergency line or reporting portal for incidents like theft or vandalism. That distinction sounds obvious until you are standing in a loading dock at 2 a.m. deciding whether a broken window justifies an emergency call. It usually does not, unless someone is still on the property or hurt.
This framework is built around a phased structure most physical security programs recognize: detection, containment, communication, evidence preservation, and post-incident review. Each phase has an owner, a deadline, and a specific output. Facility managers who treat these as five separate checklists, rather than one blurry event, close incidents faster and with fewer disputes over what actually happened.

What Should Staff Do in the First Minutes of an Incident?
Safety comes before documentation, and documentation comes before anything else. The order below reflects how most facility incident response plans are structured, whether you manage a commercial building, a residential property, or an event venue.
- Assess and protect. Determine if anyone is in danger. If yes, call 911 immediately and initiate lockdown, shelter-in-place, or area isolation depending on the threat type.
- Designate the caller and the notifier. One person calls 911 or the non-emergency line; a second person notifies the on-site security lead, facility manager, or HR, depending on incident type (a workplace altercation routes to HR faster than a break-in does).
- Secure the scene. Rope off or physically block the area. Do not let anyone touch, move, or “clean up” anything, even with good intentions.
- Capture real-time notes. Write down the time you discovered the incident, what you saw, and who was present, before your memory smooths over the details. Notes taken close to real time hold up far better under later questioning than notes reconstructed hours later.
- Use the designated channel. Radio, an emergency call button, or a specific non-emergency phone line, whatever your site has documented. If that channel fails, have a fallback (a second radio frequency, a supervisor’s cell number) written down in advance, not improvised in the moment.
Pro Tip: Keep a laminated card at every guard post and reception desk listing the exact escalation order, phone numbers, and radio channel. When adrenaline is high, people forget names they know perfectly well.
Our alarm response procedures guide breaks this sequence down further for teams building formal SOPs.
What Belongs on a Security Incident Report Form?
A report that gets thrown together after the fact rarely survives a legal challenge or an insurance dispute. A thorough incident report needs specific structural elements: an administrative header, precise location data, a severity classification, an objective narrative, witness details, and a full evidence inventory.
- Administrative header: reporter name, date and time of both the incident and the report, and a unique incident number for tracking.
- Precise location: not “the parking garage” but “Level 2, Bay 14, near the east stairwell camera.”
- Classification and severity: flag it as theft, assault, trespass, vandalism, or suspicious activity, and assign a severity tier (covered in the next section).
- Objective narrative: facts only, in chronological order. “The subject appeared intoxicated” is an assumption; “the subject slurred speech and stumbled twice” is a fact.
- Witness information: full name, contact information, and a brief statement, even if they saw only part of the event.
- Evidence inventory: camera IDs, access log entries, photos, and physical items collected.
One structural detail catches even experienced supervisors off guard: reports need documented submission confirmation, meaning a timestamp or receipt proving the report reached the right recipient. Without that, you have no way to prove the report was filed on time if it becomes relevant to a claim later. Downloadable templates with these fields pre-built save new hires from missing something under pressure.
When Should You Escalate and Who Needs to Know?
Not every incident needs the same people notified at the same speed. A three-tier severity model keeps escalation proportional and consistent across shifts.
- Tier 1, low severity (minor trespass, a lost item, a policy violation): the on-site security lead documents and closes it within the shift, notifying the facility manager by end of day.
- Tier 2, moderate severity (theft, vandalism, a verbal altercation): notify the security manager and facilities director within one hour, and HR if the incident involves an employee or contractor.
- Tier 3, high severity (assault, active threat, weapon involvement): notify the security manager, facilities director, HR, legal counsel, and communications immediately, and involve law enforcement on scene.
For any incident involving police, record the responding officer’s name, badge number, and the case or report number they assign, since that documentation matters if a claim or prosecution follows later. Insurer notification is triggered by dollar-loss thresholds or bodily injury, not by how dramatic the incident felt in the moment. When in doubt about whether a regulator needs notice, treat it as a legal question rather than a judgment call for on-site staff.
How Do You Preserve Evidence and Chain of Custody?
Evidence has a shelf life, and most facility managers only learn that the hard way. Video management systems and access-control logs cycle on overwrite schedules, so pulling and exporting relevant footage the same day, not “sometime this week,” is the difference between having proof and having an apology.
- Export the full time range around the incident, not just the moment itself, and note every camera ID used.
- Photograph the scene twice: one wide shot for context, one close-up for detail, with a consistent labeling convention (incident number plus sequence number).
- Log environmental conditions (lighting, weather, crowd density) since they affect how footage or witness accounts get interpreted later.
- Assign one person as evidence custodian and record every transfer in a written log: timestamp, who handed off, who received, and where it’s stored.
- Use tamper-evident bags for physical items and preserve digital files as read-only copies rather than working files.
Pro Tip: Store exported video and access logs in a separate, dated folder outside your main server the same day, before the overwrite window closes. A recovered file is never as clean as one you saved on purpose.
Who Owns the Post-Incident Review and When Is It Due?
Every incident needs a named review owner, not a vague sense that “someone should look into this.” For guidance on incident logging and ensuring system reliability during these reviews, see Security & Reliability. The industry-standard target is a completed review within five business days of the incident closing.
- Owner assigned: typically the security manager or Incident Response Lead, named at the start, not after the fact.
- Required outputs: a summary of what happened, root cause, and specific corrective actions.
- Prioritized remediation: rank fixes by risk and assign a deadline and an owner to each one, not just a general “we’ll address it.”
- Retention check: security incident records and supporting evidence should generally be kept at least seven years to support potential claims or litigation, and legal counsel should weigh in before anything gets disposed of early.
- Feedback loop: findings should update training content and, where relevant, physical changes like lighting or camera placement.
How Often Should You Drill and Audit Reporting Procedures?
Procedures that only exist on paper fail exactly when you need them most. Facility security programs benefit from annual audits paired with layered protection strategies like Crime Prevention Through Environmental Design (CPTED), which focuses on lighting, sightlines, and access design to prevent incidents before they start.
- Run a formal audit annually, plus an additional review any time a significant incident exposes a gap.
- Schedule tabletop exercises quarterly that walk staff through a mock incident from discovery to final report.
- Add live drills twice a year that test actual radio channels, evidence photography, and the escalation chain under time pressure.
- Set onboarding and refresher training so every new hire completes reporting training within their first two weeks, with a refresher annually.
- Review centralized incident logs quarterly to spot patterns, like a location that keeps generating the same complaint or a shift where response times consistently lag.
Our physical security risk assessment guide and security assessment checklist both give facility teams a structured way to run these audits without reinventing the process each year.
What Do Most Facilities Get Wrong About Incident Reporting?

Most reporting failures aren’t dramatic. They’re small, and they compound. The biggest one is delay: a guard who means to write up an incident “after their shift” almost always loses detail that mattered. Notes taken in the first few minutes hold up far better than a tidy narrative reconstructed the next morning.
The second failure is speculation dressed up as fact. Witnesses change their story, sometimes innocently, sometimes not, and a report built on assumption instead of observation collapses under scrutiny. Keep a standing photo checklist and a simple witness statement form at every post; they cost nothing and save hours during a real event. We’ve built training around exactly these failure points because they show up in nearly every incident file we’ve reviewed, not just the complicated ones.
— Derek
How Hub Investigative Group Helps You Build These Procedures
Writing a solid incident reporting procedure once is one thing. Keeping it current, trained, and actually followed under pressure is a different job, and it’s the one most facility teams run out of time for. Security firms can work directly with facility managers and security supervisors to close that gap, starting with a practical gap analysis of current reporting flow, then drafting clear SOPs, training staff on evidence handling and escalation, and following up with an audit to confirm the procedures actually hold up.

A typical engagement moves through four stages: assessment of your current process, a written SOP tailored to your site, hands-on staff training, and a follow-up review to catch what needs adjusting. Whether you’re managing a commercial property, a residential building, or a construction site with its own security demands, the goal is the same: procedures your team can execute without hesitation. If you want a second set of eyes on your current reporting process, request a consultation through our security services page and we’ll walk through where the gaps are.
Where Can You Find Reporting Templates and Guidance?
For emergency versus non-emergency reporting decisions, USA.gov’s crime reporting guidance is the definitive starting point. For layered facility protection strategies including CPTED, see Buildings’ action-step guide. Ready-to-use forms are available through Document.com’s incident report templates.
Sources
- Usa
- 5 key action steps facility management professionals should take to ensure an effective physical security program | Buildings
- How to Fill Out and Submit a Security Incident Report Form – LegalClarity
- Document