Why handoffs matter
Security operations are shift-based, while investigations rarely finish on schedule. If context lives only in a chat message or an analyst's memory, the next shift may lose the timeline, repeat containment work or overlook a related host. A handoff is the working state of an investigation, not a dramatic incident report.
Separate observed facts from hypotheses. 'EDR recorded a blocked process at 14:05 UTC on host FIN-WS-22' is an observation. 'The user may have opened a malicious attachment' is a hypothesis until evidence supports it. Labels stop assumptions spreading between analysts.
A seven-part handoff structure
Use a shared template in the case system so details stay findable during a busy shift.
Identify the case
Include case ID, alert name, current severity, detection source, status and latest update time. If priority changed, explain why.
Set the time window
Use explicit dates and a consistent timezone, preferably UTC for cross-team work. List key events in order and distinguish event time from alert-arrival time.
Name the known scope
List affected users, devices, IPs or applications, plus what has been checked. Say whether the scope is confirmed or still under investigation.
Point to evidence
Link the approved SIEM query, endpoint alert, identity event or evidence store. Include event IDs and a sentence about what each item shows. Follow evidence-handling procedure.
Record actions and outcomes
Note who did each action, when and what changed. Include containment steps, approvals, failed attempts and any service impact.
State uncertainty
List the leading explanation and alternatives, with confidence and missing evidence. Do not call a user or host compromised unless evidence supports it.
Make the next step unmistakable
Give the incoming analyst a specific task, expected result and owner or escalation path. Example: correlate this user's sign-ins from 13:30–15:00 UTC and escalate if an unfamiliar MFA approval is confirmed.
Before you hand over
Check that the next analyst can answer these questions:
- Can they locate the original alert and evidence from the case note?
- Are timestamps, time zone, asset names and case IDs unambiguous?
- Are facts, assumptions and open questions separated?
- Does the next action have an owner and a result to look for?
- Have secrets and unnecessary personal data been kept out of the note?
Keep the record proportionate
A handoff does not need every command or alert row. Summarize decision-relevant evidence and link to authorized details. Do not copy passwords, tokens or unrelated personal data into a ticket; follow your organization's retention and escalation procedures.
A reader should quickly see what is known, what has been done and what should happen next. If those three answers are clear, the investigation can move between shifts without losing its thread.
Write for the analyst who inherits the case
A strong handoff is factual, traceable and actionable. Mark uncertainty honestly and end with the first concrete step for the incoming shift.

