Skip to content
Cyberbezpieczeństwo

Security Incident

A security incident is an event that violates an organization's security policy, threatening the confidentiality, integrity, or availability of systems and data.

What is Security Incident?

Security Incident — A security incident is an event that violates an organization’s security policy, threatening the confidentiality, integrity, or availability of systems and data.

Learn more

Explore our services

Frequently asked questions

+ What is the difference between an event and a security incident?

An event is any observed change of state in a system — e.g. a user logging in or an alert from a system. A security incident is an event (or a series of them) that actually violates or genuinely threatens the confidentiality, integrity or availability of data and systems. In other words: every incident is an event, but it is only the negative impact on security that turns an event into an incident requiring a response.

+ What are the stages of responding to a security incident?

According to the response cycle (NIST SP 800-61) the stages are: preparation (procedures, team, tools), detection and analysis (identifying and classifying the incident), containment (cutting off the threat), eradication (removing the cause), recovery (restoring systems) and post-incident lessons learned. A well-functioning SOC shortens the time to detect (MTTD) and respond (MTTR).

+ Do security incidents have to be reported?

Yes — depending on their nature. Entities covered by the Act on the National Cybersecurity System and the NIS2 Directive are obliged to report serious incidents to the relevant CSIRT (CSIRT NASK, GOV or MON) within defined deadlines. Personal data breaches must be reported to the data protection authority (UODO) within 72 hours (GDPR), and in the financial sector additional DORA regulations and supervisory requirements apply.

+ What are examples of security incidents?

Typical incidents are: a ransomware attack encrypting data, a data leak or theft (data breach), a successful credential phishing attempt, a DDoS attack taking services offline, unauthorized access to systems, a malware infection and abuse of privileges by an employee (insider threat). Each of these requires classification by severity and an appropriate response procedure.

Tags:

security incident

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist