"Your team performs at the level you set — not the level you hope for."
Incident Management and Reporting
Instructor Sele: Every incident is a test of your management capability — and a source of intelligence for the next operation. How you manage incidents, document them, and report them is what separates a professional operation from a reactive one.
Section 1 — Incident Classification
Not all incidents require the same response. The SOC classifies incidents immediately on notification:
| Classification | Description | SOC Response |
|---|---|---|
| Routine | Minor deviation from normal — no injury, no significant disruption | Shift supervisor manages; SOC notified; standard log entry |
| Significant | Injury, property damage, or reputational risk — but contained | SOC takes command; client notified; full incident report within 4 hours |
| Critical | Threat to life, major property loss, external agency involvement, or legal/reputational implications | SOC activates ICS; immediate client and SafeHaven Command notification; full documentation throughout |
Section 2 — The Critical Incident
A critical incident is any event that significantly disrupts operations, threatens life, requires senior management involvement, and/or has legal or reputational implications. Examples: armed robbery, assault causing injury, fire, active threat, serious data breach, media involvement.
When a critical incident is declared, the SOC assumes command as Incident Commander, SafeHaven Operations Command is notified immediately, client senior management is notified within 15 minutes, LNP is contacted if required, the incident log is opened and maintained continuously, and no public or media communication occurs without explicit authorisation.
Section 3 — Incident Reporting Standards
Every significant and critical incident requires a full written incident report covering: date, time, and precise location; what happened (factual, chronological account); who was involved; what actions were taken and by whom; the outcome; evidence preserved; and further action required.
The report is written in the first person by the guard(s) involved. The SOC reviews, countersigns, and files within 4 hours of resolution for significant incidents and within 24 hours for critical incidents.
Section 4 — Key Performance Indicators
KPIs are measurable values that demonstrate how effectively the security team is achieving operational objectives. Common KPIs include incident response time, post coverage rate, guard punctuality and attendance, patrol completion rate, training compliance, incident report accuracy and timeliness, and client satisfaction.
KPIs must be reviewed monthly by the SOC and reported to both SafeHaven management and the client. Declining KPIs are early warning indicators of operational degradation.
| KPI | What It Measures |
|---|---|
| Incident response time | Time from report to SOC response |
| Post coverage rate | % of contracted posts covered without gaps |
| Guard attendance rate | % punctuality and attendance compliance |
| Patrol completion rate | % of scheduled patrols completed and logged |
| Training compliance rate | % of guards current on mandatory training |
| Client satisfaction | Measured at contract review meetings |
- •Classify every incident immediately: Routine / Significant / Critical — response escalates accordingly
- •Critical incidents: SOC assumes command, notify SafeHaven Command and client within 15 minutes
- •Incident reports are factual, chronological, first-person accounts — filed within 4 hours (significant) or 24 hours (critical)
- •KPIs provide measurable evidence of operational performance — review monthly
- •Declining KPIs are early warning signs — act on them before they become incidents
"I reviewed a client's incident reports from the previous SOC's tenure and found that 80% were filed more than 24 hours after the incident. Some were filed three days later. By the time they were written, details had changed, memories had been contaminated by conversation, and the guard who wrote the report had discussed it with colleagues who weren't even there. Write the report while the memory is fresh. Every hour of delay is an hour of degrading accuracy — and degrading legal protection."
Which of the following best describes a Key Performance Indicator (KPI) in security management?