Guides · Privacy & compliance

Incident documentation: what to record if something goes wrong

Good documentation supports regulators, insurers, and your own learning.

Start simple: an incident log row

  • Detected when / how
  • Contained when
  • Notified whom (internal, host, counsel, individuals)
  • Root cause category (credential leak, plugin, phishing, etc.)

Evidence handling

Preserve logs carefully; avoid tipping attackers by noisy mass password resets before containment if guidance says otherwise—sequence matters.

Post-incident improvements

Track remediation tickets: MFA gaps closed, backup test passed, monitoring alert added. Close the loop so the same hole does not reopen.

Frequently asked questions

How long to keep incident notes?

Follow legal and insurance guidance; often longer than ordinary operational logs.

Should customers know about every small phishing attempt?

Not necessarily—assess impact and get advice; transparency is important when personal data is at risk.

Putting this into practice on your NZ website

This guide sits in our Privacy & compliance collection. The goal is practical advice you can act on without a computer science degree. Start with one change, measure whether enquiries or usability improve, then tackle the next item. Small businesses across Auckland, Wellington, Hamilton, Christchurch, and regional New Zealand face the same constraints: limited time, real customers, and a website that must earn its keep.

For Incident documentation: what to record if something goes wrong, the highest-leverage move is usually to align your live site with what the guide recommends, then fix anything that blocks Google from crawling pages or stops visitors from contacting you. If your site runs on WordPress, many of these tasks are configuration and content work rather than custom development.

Document your starting point: note current enquiry volume, average page speed from PageSpeed Insights, and any errors showing in Google Search Console. Without a baseline, improvements are guesswork. Revisit the same metrics after 90 days—SEO and UX changes rarely produce overnight miracles, but sustained progress should be visible in leads and user behaviour.

Share this guide with whoever maintains your site—an employee, a contractor, or your hosting support desk—so terminology and priorities align. The FAQ section on our main site answers common project questions if you are weighing a rebuild versus incremental fixes.

When to involve a web partner

Some tasks—migrations, checkout changes, security incidents, or a full redesign—benefit from experienced help. If you are comparing providers, look for clear scoping, realistic timelines, and measurement tied to business outcomes rather than vanity metrics. Our team builds and maintains business websites nationwide; explore relevant services below or request a quote when you are ready.

A good partner will ask about your customers, geography, and capacity to publish content—not only colour preferences. Review our recent website projects for examples of brochure, WordPress, and ecommerce work across New Zealand.

Related NZDH services

More guides in this topic

Browse the full Privacy & compliance guide hub or return to the guides home.

Explore on NZDH.co.nz

Authoritative further reading

These independent resources complement this guide. Search engines and customers both reward accurate, helpful information—we link out where official documentation or regulators explain the topic better than a generic blog post could.