Incident Dashboard
Welcome to the Incident Dashboard user guide. This dashboard is crucial for monitoring cyber security incidents and data breaches within your organisation. It offers a centralised area for IT and Data Protection teams, as well as Senior Leadership, to access vital metrics and data related to current and historic incidents. This enables effective management and facilitates prompt decision-making.
With detailed visualisations of incident trends and breach assessments, the dashboard provides a clear understanding of threat scopes and the efficacy of your response strategies. It is tailored to bolster your organisation's resilience by delivering insights that inform enhancements in security protocols and compliance practices.
Access to the Incident Dashboard is included with the Incident Management or Privacy Platform licence. For further information contact [email protected].
Accessing the Incident Dashboard
On purchasing Incident Management or 9ine’s Privacy Platform, all users automatically gain access to the Incident Dashboard, accessible via the left navigation menu. Initially, users might encounter limited data or No records available messages on dashboard cards until data is entered in the incident forms.

You can only view items to which you are assigned or have permissions. Incident permissions include: owner, member, screening reviewer, notified user, data protection (DP) lead, IT lead, attachment reviewer, and closure approver.
Adjusting data on the Incident Dashboard
How to adjust dashboard data
In the dashboard, you have access to several settings that help tailor the data d
In the dashboard, you have access to several settings that help tailor the data displayed to your needs, including a date range picker, a filter, and a setting to view your actions.
By default, the date range picker is set to display data from the Last 30 Days. You can adjust this by selecting from predefined ranges such as:
- Today
- Yesterday
- Last 7 Days
- Last 30 Days
- This Month
- Last Month
- Custom Range
- No Date Selection
Info:
For monthly selections, the 9ine Platform automatically determines the start and end dates by calendar month.

An orange dot appears next to the filter icon when a filter is active, making it easy to recognise. To quickly clear any filters and the selected date range, use the Clear Date Range or Reset Filters & Date Range options. If you want to focus solely on the items for which you are responsible, activate the My Actions toggle.
Info:
The My Action toggle displays only those items where you are the owner, member or notified user, across all cards displayed on the Dashboard.

To update the dashboard with the latest information, click the Refresh icon. This action will display the most recent changes and update the displayed date and time.

In the left-hand corner of each dashboard card, you have the option to assign a unique sequence number (e.g., 1, 2, 3, etc.). Upon assigning these numbers, the cards on the dashboard will automatically rearrange themselves to reflect your specified sequence order. Any changes are automatically saved and retained on the next login.

To remove individual dashboard cards, click View and deselect the cards you do not want to display. Note that at least one card must remain selected. After selecting your preferred cards, click Apply. You also have the option to Save View.

Info:
- The changes applied to the sequence order of the dashboard cards and in the View popup are user and dashboard specific and are only applied to your profile.
- The sequence order in the View popup does not update to reflect the sequence order added to the individual dashboard cards.
An overview of cards on the Incident Dashboard
The Incident Dashboard provides a set of cards, each representing different data points in relation to your organisation’s cyber security incidents and data breaches. You choose which cards are displayed, and in what order, using the View, and at least one card always remains visible. This dashboard offers a range of charts, including:
- Column
- Geo
- Donut
- Table
Column Charts
Column charts are crucial for visualising and comparing various datasets side by side. These charts provide a quick snapshot of vital information related to your organisation's incidents. For example, one of the charts illustrates the potential risks of damage to data subjects affected by an incident. Users can rapidly assess whether the risks involve loss of control over personal data, limitations of rights, discrimination, identity theft or fraud, financial loss, unauthorised reversal of pseudonymisation, reputational damage, loss of confidentiality, or any other significant social or economic disadvantages.

Geo Charts
The dashboard displays a geo-chart to visually depict incidents based on their countries of occurrence. This chart features an expansion option in the top right corner for an enlarged view. By hovering over the country markers, users can access detailed information about the status of each incident, whether open or closed. This feature effectively highlights the geographical distribution of incidents, providing valuable insights into the global impact and reach of your organisation’s cyber security incidents and data breaches.

Donut Charts
Donut charts provide a visual comparison between data points by displaying proportional data or percentages across different categories. For instance, the example below details the classification of open incidents, distinguishing between those deemed as near misses, non-reportable, or reportable. This chart also highlights any open incidents that have yet to be assessed to determine the most appropriate categorisation, offering a clear, visual breakdown of incident status and urgency.

Table Charts
The table charts on the dashboard are equipped with multiple columns and include a sorting function, enhancing data management capabilities. Clicking on any count within these charts directly navigates you to the incident management log, already filtered according to your selection. For instance, by clicking on a count of 8, you will be taken to the incident management log, where it displays a filtered view of the incidents in which your organisation was identified as the data controller.

Downloading the data displayed on the dashboard
Downloading the data displayed on the dashboard
To download a dashboard’s data, either click the options available in the ...
To download a dashboard’s data, either click the options available in the Download button (Preview/Download all Graphs (PDF) or Download all Tables (XLS)).

Or use the checkbox located in the top-right corner of an individual dashboard card. You can customise your download by applying the date range picker, filters, view options, or the My Actions function.

Note that it is not possible to download graphs and tables in one export, as they are provided in different file formats. If you select a graph using the checkbox, a toaster notification will inform you that:
- The selected card will be included in your download. You may continue to choose additional graph charts from the dashboard; however, it is not possible to select tables while graphs are selected. To include tables in your download, you must first deselect any graph charts. This measure ensures compatibility between different types of data representation for downloads. Graphs are exported in a PDF format, whereas tables are exported as XLS.

To download table-based dashboard data, select Download from the dashboard header. The export is processed in the background, and once complete, you will receive both an in-platform notification and an email notification. The exported Excel workbook includes a separate worksheet for each table card with available data. Cards that contain no records are not included in the export.
To download graph-based dashboard data, select Download to open the Preview screen, which displays the selected charts and the Total Cards count. After selecting Download, the export is processed in the background. Once the PDF is ready, you will receive an in-platform notification and an email notification.
The download link in the email notification is valid for 24 hours; after that, a new export must be generated.
