Security Incident Reports: What to Record and Why It Matters Later

September 23, 2026

blog post

A security incident report is written the night of an incident and read months afterward, usually by someone deciding whether your property handled it reasonably. That person might be an insurance adjuster, a prosecutor, an attorney taking a deposition, or a judge. None of them were there, and none of them will accept a vague account written by someone tired.

Most reports fail in predictable ways. They record conclusions instead of observations, leave out timing, or describe what an officer assumed rather than what they saw. This guide covers what belongs in a report, what does not, and how the documentation gets used once the incident is no longer recent.

What a Weak Report Costs You Later

Reports are written under time pressure and read under scrutiny, which is a bad combination when the writing was rushed.

Gap in the report What it costs you
No specific time, only a shift or a rough hour Footage cannot be matched to the event, and the timeline breaks under questioning.
Conclusions with no observations behind them The account reads as opinion, and an attorney will treat it that way.
Vague location, such as "the parking lot" Nobody can determine sightlines, camera coverage, or which entrance was involved.
No record of who was notified and when Your response time becomes unprovable, whatever it actually was.
Missing witness names and contact details Statements become unobtainable once staff turn over.

The pattern holds across all five. A report fails not because it says something wrong but because it leaves someone else unable to reconstruct what happened. Consistent daily reporting from staffed assignments is the practical fix, since a report written to a standard format every shift is far harder to rush than one written only when something happens.

What Belongs in a Security Incident Report

The test for every line is whether a stranger reading it in a year could reconstruct the event without asking questions.

1. The Fixed Facts

Date, exact time, and precise location, written as specifically as the property allows. Not the parking lot but the northeast corner near the loading dock. Not late evening but 10:47 p.m. Include the reporting officer's name, the weather and lighting conditions if they are relevant to what could be seen, and the time the report itself was written.

2. Observations, Not Conclusions

This is the distinction that separates useful reports from liabilities. Write what you saw, heard, and did. "The subject appeared intoxicated" is a conclusion. "The subject was unsteady on his feet and his speech was slurred" is an observation, and it supports the same inference without the writer having claimed it.

The same applies to intent. An officer cannot know that someone was attempting to break in. They can record that a person was pulling on a door handle at 2:15 a.m. and left when the officer approached.

3. Descriptions That Hold Up

Physical descriptions, clothing, vehicles, and plates where visible. Direction of travel matters more than most people record, because it is frequently what connects one incident to another across a property or across weeks.

4. Actions and Notifications

What the officer did, in order, with times attached. Who was notified, when, and by what method. Whether law enforcement was called, when they arrived, and any case or reference number they provided. This section is what establishes that your property responded rather than simply noticed.

5. Evidence Preserved

Which cameras cover the location, whether footage was pulled and saved, and where it is stored. This matters more than it appears, and the next section explains why.

What Not to Write in a Security Incident Report 

Three things weaken a report reliably, and all three are easier to avoid than to fix afterward.

1. Speculation

 Guesses about motive, identity, or what might have happened invite cross-examination and add nothing a reader can use. An officer who suspects a vehicle was casing the lot should record the vehicle, the time, and the behavior, and stop there.

2. Editorializing 

Characterizations of people, sarcasm, and visible frustration read badly in a deposition and reflect on your organization rather than on the person described. The report is a record, and anything in it that sounds like an opinion will be treated as one.

3. Overstated authority

Security officers are private personnel, not law enforcement, so language like "apprehended," "detained the suspect," or "placed under arrest" describes powers they do not hold. Record that the officer observed, documented, and called police. That version is both accurate and defensible.

Why Timing and Preservation Decide the Value

Details degrade fast. A report written at the end of a shift is more accurate than one written the next day, and both are more accurate than one reconstructed from memory a week later when someone requests it.

Footage decays on a different clock. Recording systems overwrite on a fixed cycle, which means the clip supporting your report can disappear while the report itself sits in a file. Pull and store the relevant segment the same day, and note in the report that you did. Once litigation is anticipated, preservation stops being good practice and becomes an obligation: the Federal Rules of Civil Procedure allow courts to impose sanctions when electronically stored information that should have been preserved is lost because a party failed to take reasonable steps.

Injuries add a separate track. If an incident involves an employee injury, recording it in your security file does not satisfy workplace requirements, since OSHA's injury and illness recordkeeping rules operate independently of whatever security documentation you keep.

How Reports Get Used Once the Incident Is Old

Insurance and Claims

Adjusters work from documentation. A contemporaneous report with times, names, and preserved footage moves a claim. A thin report invites questions your property will answer from memory, which is the weakest position available.

Litigation

The report becomes a discovery document, read alongside every other report your property filed that year. Consistency across them matters as much as the content of any single one, because a file where the format changes shift to shift suggests nobody was supervising the process.

Pattern Recognition

Individual reports document losses. Read together, they tell you which entrance, which hours, and which category of incident is recurring, which is the only way documentation turns into prevention. This is where mobile patrol logs and camera coverage records earn their cost, and it works only if the reports are comparable to each other.

Justifying Your Coverage

When you ask for budget, a year of consistent reports is the argument. Without them, a request for additional coverage is a preference. With them, it is a documented pattern with dates attached.

Making Reporting Consistent Across a Property

A standard format is what makes the difference, because it removes the judgment call about what to include from a person writing at the end of a long shift. Post orders should specify the fields, the deadline for filing, and who reviews them.

Review is the step most properties skip. Reports that nobody reads accumulate without improving, and errors repeat because nobody corrects them. A supervisor reading reports weekly catches the vague location and the missing notification time while the officer still remembers the answer.

If your current reporting is inconsistent or arrives only when something goes badly wrong, Stonewall Security staffs assignments with site-specific post orders, supervisor review, and daily reporting as standard. Request a security consultation when you want a look at how your documentation would hold up, and we'll actually respond.

Are you looking to hire security guards? Let's chat - we'll actually respond back.
Close Pop-up icon