Glossary · Term

Incident explained

An incident is a security event that affects data, systems or services.

At a glance
Meaning
Security incident
Effect
Impact on data, systems or services
Important
Only significant incidents are notifiable
Related
Incident response, reporting obligations
Updated
June 2026
Editorial team
Compliance Compass

What is an incident?

An Incident is any event that actually affects the availability, confidentiality, integrity or authenticity of data, systems or services. The spectrum ranges from a malware infection through a data leak and ransomware to a complete system outage. Unlike a mere suspicion or a technical alert, an incident is an event with a demonstrable effect – it has breached a protection objective or disrupted operations. This definition is the basis for whether and how quickly an organisation has to react and report.

Telling incident, event and near miss apart

Not every event is an incident. A harmless “event” – a single failed login, say – only becomes an incident once security is actually affected. Its counterpart is the Near miss – a near-incident in which the damage did not materialise. That clean distinction matters, because it governs which resources are mobilised and whether reporting obligations bite. Treat every event as an incident and you overload the team; play real incidents down and you risk missing deadlines.

From incident to response

The structured way of dealing with incidents is called Incident response or Incident handling – from detection through containment and eradication to Recovery. The more clearly an event is classified as an incident, the faster these processes start. Incidents are often detected from technical traces, so-called Indicators of Compromise.

Incidents and the NIS2 reporting obligations

If an incident is “significant”, it triggers the NIS2 Reporting obligations – an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Smaller incidents should still be documented internally, because they are often the forerunners of bigger problems. A typical case: If a ransomware attack encrypts the production database of an energy supplier and brings operations to a standstill, that is a significant incident – the 24-hour early warning to the national CSIRT or competent authority goes out immediately, in parallel with technical containment.

Further reading: Directive (EU) 2022/2555 (NIS2), full text on EUR-Lex

Frequently asked questions

What is an incident?

An incident is a security event that actually affects the availability, confidentiality, integrity or authenticity of data, systems or services – through malware, a data leak, ransomware or a complete system outage, for example. Unlike a mere suspicion or a technical alert, an incident is an event with a demonstrable effect: it has breached a protection objective or disrupted operations. This definition decides whether and how quickly an organisation has to react and report.

Does every incident have to be reported?

No, not every incident is notifiable. Only significant incidents trigger the reporting obligations under NIS2. For a significant incident the staggered reporting chain applies: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. The deadlines come from the directive; the body you report to is national, normally the CSIRT or the competent authority of the Member State in which you are established. Smaller incidents should still be documented internally, because they are often the forerunners of bigger problems and remain relevant for later analysis.

What is the difference to a near miss?

A near miss is a near-incident in which the damage was only just avoided, whereas an incident has actually affected security. In a near miss an attack or an error was detected or fended off in time, so no protection objective was breached. Both matter: near misses give valuable pointers to weaknesses before they turn into a real incident with a possible reporting duty under NIS2, and should therefore be documented as well.

Incident management

Incidents under control

Compliance Compass records, assesses and documents incidents – from detection through to notification.