/// One channel · fully tracked
Report an incident.
If you think something is wrong, report it — an over-reported false alarm costs an hour, an unreported breach costs a semester. Do not wait until you have confirmed the details.
§ Include if you have it
Your institution and your role, plus a phone number we can reach today.
When you first noticed it, and what made you notice — in your own words.
Affected hosts, IPs, domains, or accounts — as text, not screenshots.
Relevant log excerpts with timestamps and the timezone they’re in.
Anything you have already changed: accounts disabled, hosts pulled, passwords reset.
§ Before you send
Don’t wipe or rebuild an affected host before we’ve agreed what to preserve.
Don’t send passwords or live credentials in plain email — encrypt to our PGP key.
Don’t contact a suspected attacker, or probe infrastructure you don’t operate.
Don’t discuss the incident on public channels until your institution has agreed a line.
§ Triage
How severity is decided
Severity sets the response clock. It’s assigned by the CSIRT, and revised as facts arrive.
incl. out of hours
§ After the report
What you get back
A reference of the form GH-CSIRT-2026-0148. Quote it on every follow-up.
One incident manager owns the case end to end, with a named deputy for cover.
A post-incident review: timeline, root cause where known, and recommendations you can act on.
§ Or use the form
Structured report
Prefer a form? This routes to the same tracked queue as email. For a live emergency, don’t wait on it — email csirt@garnet.edu.gh right away. Never include passwords; we’ll never ask for them.
✓ Report received
Thank you — your report has reached GARNET CSIRT. Please keep this reference for any follow-up:
If this keeps happening, email your report directly to csirt@garnet.edu.gh.