What is in a PatientZero malware report?
A PatientZero malware report explains a compromise at two levels. The executive summary tells owners what happened and whether data or customers were affected. The technical section lists every finding, the incident timeline, the evidence kept and the verification that shows the clean-up worked. Remaining risks are stated plainly rather than hidden.
| Section | For | Contents |
|---|---|---|
| Executive summary | Owners, managers | Impact, actions taken, remaining risks |
| Technical findings | Developers, hosts | Paths, rules, severity, affected sites |
| Timeline | Everyone | Entry point, persistence, clean-up, verification |
| Evidence vault | Insurers, legal | Quarantined files, SHA-256 hashes |
| Verification | Everyone | Before and after scan results |
Can the report support an ICO breach report or insurance claim?
Yes. The report records when the compromise began, what was accessed or changed, what was removed and how the fix was verified. That is the factual basis the ICO, insurers and clients ask for. It does not replace legal advice, but it saves you piecing events together from memory under pressure.
Under UK GDPR, a personal data breach that is likely to result in a risk to people's rights and freedoms must be reported to the ICO within 72 hours of becoming aware of it, according to ICO guidance. Card skimmers and database access on shops are typical cases. A timeline with hashes and timestamps helps you decide quickly and report accurately. Read more in website hacks and GDPR breach reporting.
Tip: keep the ZIP package somewhere separate from the affected server. It is your record if questions come later.
Why does evidence matter after a website hack?
Evidence lets you prove what happened instead of guessing. Deleting infected files straight away destroys the timestamps and code that show how the attacker got in and what they could reach. PatientZero quarantines files with hashes and records every step, so the clean-up is reversible, explainable and defensible if anyone asks later.
- Clients see exactly what was affected and what was done
- Insurers get a dated timeline and a record of remediation
- Developers can confirm the entry point and patch it
- If the same malware returns, its hash links it to the original incident
Evidence starts with the Forensic scan, which captures persistence and access indicators before anything is changed.
What does the Activity log record?
The Activity log records every action taken in the platform: servers added or removed, connection tests, scan engine deployments, scans started and finished, fixes applied and playbooks run, each with a timestamp and the user responsible. It is the audit trail that shows your security work was actually done.
# Activity (fictional)
2026-09-14 09:02 Test connection acme-prod-01 ok
2026-09-14 09:04 Deploy scan engine acme-prod-01 /opt/patient-zero/scan-engine
2026-09-14 09:21 malware-intelligence acme-prod-01 38 findings
2026-09-14 10:10 Fix acme-prod-01 38 quarantined, hashes stored
2026-09-14 11:45 Verification scan acme-prod-01 0 findings
Agencies can share reports with clients under their own brand; see PatientZero for agencies.