Contenttrailcore

Field note · 7 April 2026

Choosing the incident window before you draw a single line

How security teams in the United Kingdom should pick the start and end of an incident trend picture so the charts stay honest.

Open notebook with handwritten planning notes on a wooden desk

A chart of security events is only as honest as the window it covers. If you start the picture on the Monday after a detector was switched off for a change, the quiet days that follow are not a success story. They are missing hours.

We ask clients to name three dates before we draw anything: the first hour the extracts can be trusted, the last hour they want in the pack, and any planned outages inside that span. The trusted start is often later than the calendar quarter. That is fine. A short, complete window reads better in a risk committee than a full quarter with a silent fortnight no one can explain.

UK organisations often inherit windows from finance: April to June, July to September. Those fiscal blocks are useful for comparing cost, not always for comparing detections. A phishing burst that begins on 28 June and ends on 3 July will be split across two packs if you obey the fiscal cut blindly. Name the burst as one incident window, then show the fiscal cut as a vertical mark if the committee still needs it.

Write the window on the first page of the pack, with timezone. British Summer Time still catches people out when logs are stored in UTC. A spike at 23:00 UTC is midnight in Ford in winter and 00:00 the next calendar day in summer. Put the rule in the caption once so the room does not spend ten minutes converting clocks.

Back to the journal