ICT-Related Incident
Abbreviation: ICT
Pronunciation: I-C-T ree-LAY-tid IN-sih-dent
Also known as: Technology incident, ICT incident, ICT
Definition
An ICT-related incident is an unplanned event or linked series of events that compromises, or may compromise, the security, availability, authenticity, integrity, or confidentiality of technology services or data. The term is broader than a confirmed cyberattack because operational failures, processing errors, infrastructure outages, and third-party disruptions can qualify even when malicious activity is not established. Operationally, teams should record detection time, affected services, data impact, and customers.
Overview
An ICT-related incident is an unplanned event or linked series of events that compromises, or may compromise, the security, availability, authenticity, integrity, or confidentiality of technology services or data.
ICT-Related Incident is closely connected to Major ICT-Related Incident, Incident Classification, and Incident Severity. The term is broader than a confirmed cyberattack because operational failures, processing errors, infrastructure outages, and third-party disruptions can qualify even when malicious activity is not established.
Operational implementation should record detection time, affected services, data impact, customers, duration, root cause, dependencies, containment, recovery evidence, and reporting decisions using a consistent incident process.
The principal failure modes include under-classification, fragmented records, delayed escalation, missing customer impact data, unresolved root causes, and treating recurring operational failures as unrelated events.
Useful measures include incident count by class, detection time, containment time, service impact, recurrence rate, and reporting timeliness.
Operationally, teams should record detection time, affected services, data impact, and customers. Key risks include under-classification, fragmented records, delayed escalation, and missing customer impact data.
A production treatment of ICT-Related Incident should test an unplanned event or linked series of events that compromises, or may compromise, the security, availability, authenticity, integrity, or confidentiality of technology services or data within the relevant asset, decision, or service state. The ICT-Related Incident context record for unplanned event, linked series of events that compromises, and may compromise should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of ICT-Related Incident should determine whether safeguards addressing unplanned event, linked series of events that compromises, and may compromise changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
An ICT-related incident is an unplanned event or linked series of events that compromises, or may compromise, the security, availability, authenticity, integrity, or confidentiality of technology services or data.
Sources
- Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector — European Union (2026-08-03)
- Commission Delegated Regulation (EU) 2024/1772 on ICT Incident Classification — European Union (2026-08-03)
- Incident Response Recommendations and Considerations, NIST SP 800-61 Rev. 3 — NIST (2026-08-03)