Instructor Sele
Operations Commander | SafeHaven Strategies

"Your team performs at the level you set — not the level you hope for."

Module 7

Incident Management and Reporting

Instructor Sele: Every incident is a test of your management capability — and a source of intelligence for the next operation. How you manage incidents, document them, and report them is what separates a professional operation from a reactive one.

Section 1 — Incident Classification

Not all incidents require the same response. The SOC classifies incidents immediately on notification:

ClassificationDescriptionSOC Response
RoutineMinor deviation from normal — no injury, no significant disruptionShift supervisor manages; SOC notified; standard log entry
SignificantInjury, property damage, or reputational risk — but containedSOC takes command; client notified; full incident report within 4 hours
CriticalThreat to life, major property loss, external agency involvement, or legal/reputational implicationsSOC activates ICS; immediate client and SafeHaven Command notification; full documentation throughout

Section 2 — The Critical Incident

A critical incident is any event that significantly disrupts operations, threatens life, requires senior management involvement, and/or has legal or reputational implications. Examples: armed robbery, assault causing injury, fire, active threat, serious data breach, media involvement.

When a critical incident is declared, the SOC assumes command as Incident Commander, SafeHaven Operations Command is notified immediately, client senior management is notified within 15 minutes, LNP is contacted if required, the incident log is opened and maintained continuously, and no public or media communication occurs without explicit authorisation.

Section 3 — Incident Reporting Standards

Every significant and critical incident requires a full written incident report covering: date, time, and precise location; what happened (factual, chronological account); who was involved; what actions were taken and by whom; the outcome; evidence preserved; and further action required.

The report is written in the first person by the guard(s) involved. The SOC reviews, countersigns, and files within 4 hours of resolution for significant incidents and within 24 hours for critical incidents.

Section 4 — Key Performance Indicators

KPIs are measurable values that demonstrate how effectively the security team is achieving operational objectives. Common KPIs include incident response time, post coverage rate, guard punctuality and attendance, patrol completion rate, training compliance, incident report accuracy and timeliness, and client satisfaction.

KPIs must be reviewed monthly by the SOC and reported to both SafeHaven management and the client. Declining KPIs are early warning indicators of operational degradation.

KPIWhat It Measures
Incident response timeTime from report to SOC response
Post coverage rate% of contracted posts covered without gaps
Guard attendance rate% punctuality and attendance compliance
Patrol completion rate% of scheduled patrols completed and logged
Training compliance rate% of guards current on mandatory training
Client satisfactionMeasured at contract review meetings
Key Points
  • Classify every incident immediately: Routine / Significant / Critical — response escalates accordingly
  • Critical incidents: SOC assumes command, notify SafeHaven Command and client within 15 minutes
  • Incident reports are factual, chronological, first-person accounts — filed within 4 hours (significant) or 24 hours (critical)
  • KPIs provide measurable evidence of operational performance — review monthly
  • Declining KPIs are early warning signs — act on them before they become incidents
Field Note · Instructor Sele

"I reviewed a client's incident reports from the previous SOC's tenure and found that 80% were filed more than 24 hours after the incident. Some were filed three days later. By the time they were written, details had changed, memories had been contaminated by conversation, and the guard who wrote the report had discussed it with colleagues who weren't even there. Write the report while the memory is fresh. Every hour of delay is an hour of degrading accuracy — and degrading legal protection."

Knowledge Check

Which of the following best describes a Key Performance Indicator (KPI) in security management?