# What is a Security Incident?

> A security incident is an occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of information or systems and meets the organization’s threshold for coordinated handling.

- Canonical URL: https://yellowcube.eu/glossary/security-incident/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Not every security event is an incident. Events are observable occurrences — a failed login, a blocked connection — while an incident is an event, or a correlated set of events, assessed as harmful or potentially harmful enough to require response. The declaration boundary is an organizational decision that should be defined in advance.

Declaring an incident starts a governed process: triage, evidence preservation, containment, eradication, recovery, and review. Some incidents also trigger legal and regulatory duties — personal-data breach notification under GDPR, sector reporting under NIS2 or DORA, or sectoral rules elsewhere — each with its own definitions and deadlines that do not wait for technical certainty.

### Key points

- **Declaration criteria:** Define which observations, severities, affected assets, and impacts move an event or alert to declared-incident status, and who has authority to declare.
- **Thresholds to map:** Legal, regulatory, contractual, and insurer notification definitions may each draw the incident line differently from internal criteria.
- **Evidence from the start:** Treat declaration as the beginning of a record — timestamps, actions, approvals, and preserved evidence shape later legal, disciplinary, and recovery options.
- **Important limitation:** A declared incident is a determination for handling, not proof that a compromise occurred. Premature declaration can divert resources, while reluctance to declare delays response and can breach notification deadlines.

### Related terms

[Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Digital forensics and incident response (DFIR)](<https://yellowcube.eu/glossary/digital-forensics-and-incident-response/>) · [Data breach](<https://yellowcube.eu/glossary/data-breach/>) · [Crisis management](<https://yellowcube.eu/glossary/crisis-management/>) · [Chain of custody](<https://yellowcube.eu/glossary/chain-of-custody/>)

### Sources

[NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [NIST glossary: Incident](https://csrc.nist.gov/glossary/term/incident)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

