Not every security event is an incident. Events are observable occurrences — a failed login, a blocked connection — while an incident is an event, or a correlated set of events, assessed as harmful or potentially harmful enough to require response. The declaration boundary is an organizational decision that should be defined in advance.
Declaring an incident starts a governed process: triage, evidence preservation, containment, eradication, recovery, and review. Some incidents also trigger legal and regulatory duties — personal-data breach notification under GDPR, sector reporting under NIS2 or DORA, or sectoral rules elsewhere — each with its own definitions and deadlines that do not wait for technical certainty.
Key points
Declaration criteriaDefine which observations, severities, affected assets, and impacts move an event or alert to declared-incident status, and who has authority to declare.
Thresholds to mapLegal, regulatory, contractual, and insurer notification definitions may each draw the incident line differently from internal criteria.
Evidence from the startTreat declaration as the beginning of a record — timestamps, actions, approvals, and preserved evidence shape later legal, disciplinary, and recovery options.
Important limitationA declared incident is a determination for handling, not proof that a compromise occurred. Premature declaration can divert resources, while reluctance to declare delays response and can breach notification deadlines.