- Meaning
- Near-incident without damage
- Benefit
- Early warning signal for vulnerabilities
- Response
- Evaluate it, close the gap
- Related
- Incident, vulnerabilities
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is a near miss?
A Near miss (a near-incident) is an event in which an Incident almost occurred, but the damage did not materialise – whether because a protective measure was in place or simply through luck. A typical example is an opened phishing mail whose attachment happened not to be executed, or an attacker who failed against a firewall kept up to date. The decisive difference from an incident: there was no actual impairment of security – and therefore no NIS2 reporting obligation either.
Why near misses are valuable
Near-incidents are free early warning signals: evaluating them reveals Vulnerabilities and process gaps before real damage occurs. In safety-critical industries such as aviation, consistent reporting of near-incidents has been standard for decades, because they occur far more often than actual losses and therefore offer a much denser field to learn from. Applied to cybersecurity, every documented near miss gives concrete pointers to where controls need sharpening.
How to deal with them
What matters is an open reporting culture in which near-incidents are reported rather than kept quiet out of fear of consequences. Every near miss is recorded through a simple reporting channel, documented, evaluated and leads – where necessary – to a concrete improvement, such as a technical measure or Awareness-based training. Assigning blame is counterproductive, because it stifles exactly the openness the system needs.
Near misses and NIS2
Evaluating near misses systematically is part of the continual improvement that an ISMS and Risk management aim at under NIS2. Even though near misses are not themselves notifiable, dealing with them consistently lowers the likelihood of notifiable incidents. In practice: an employee clicks a phishing link, but multi-factor authentication prevents the account takeover. Instead of ticking the event off, the team records it as a near miss, discovers that a whole department fell for the campaign – and follows up with targeted training and stricter mail filters.
Further reading: ISO/IEC 27001 – information security management systems (ISO)
Frequently asked questions
What is a near miss?
A near miss is a near-incident that almost became a security incident but caused no damage – because a protective measure worked, or simply through luck. A typical example is an opened phishing mail whose attachment was never executed. Unlike a real incident, a near miss triggers no NIS2 reporting obligation, because there was no actual impairment of security.
Why should you record near misses?
Near misses are free early warning signals: recording and evaluating them systematically reveals vulnerabilities and process gaps before they turn into a real incident with damage and a reporting duty. In aviation, reporting near-incidents has been standard for decades, because they occur far more often than actual losses and therefore offer a denser field to learn from. That lowers overall risk noticeably.
What does that take?
Above all it takes an open reporting culture without blame, in which near-incidents are reported rather than kept quiet out of fear, plus a simple reporting channel and a process that documents every near miss, evaluates it and turns it into concrete improvements – a technical measure or an awareness training session, for example. Assigning blame is counterproductive, because it stifles exactly the openness the system needs.