GlossarySOC and monitoring

Security incident

Short answer

A security incident is an event, or series of events, that compromises or is likely to compromise the confidentiality, integrity or availability of information or systems, such as a ransomware infection, an account takeover or a data leak. Not every security event is an incident, and not every incident is a data breach.

Event, incident and breach

A security event is anything observable that may be relevant to security, such as a failed login or a blocked malware download. Most events are harmless. An incident is an event, or a series of events, that actually threatens information or operations. A personal data breach is a specific type of incident affecting personal data, with its own legal obligations.

Classifying incidents

Organisations classify incidents by type (malware, unauthorised access, denial of service, data leak, fraud) and by severity, based on the systems, data and people affected and the impact on operations. The classification decides who must be involved, how fast and whether a notification is required.

Notification obligations

Under the GDPR, personal data breaches that pose a risk must be notified to the AEPD within 72 hours. NIS2 requires significant incidents to be reported with an early warning within 24 hours, a notification within 72 hours and a final report within a month. DORA sets its own process for major ICT related incidents in the financial sector. Our article on NIS2 and DORA reporting deadlines compares them.

Handling them well

A documented incident response plan, clear criteria for what counts as an incident, a register of all incidents and lessons learned after each one are expected by ISO 27001 (Annex A 5.24 to 5.28), the ENS and SOC 2. Employees also need to know how to report anything suspicious quickly.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub