Incident
Pronunciation: IHN-suh-dunt
Definition
An incident is an event or series of events that disrupts operations, causes harm, or violates defined security, compliance, or service expectations. Incident must define the affected service or asset, event severity, business and customer impact, evidence, responsible roles, containment priority, recovery objective, and reporting obligations. Effective handling of Incident connects detection, triage, preservation, containment, eradication, recovery, communication, regulatory assessment, and lessons learned through one auditable timeline.
Overview
An incident is a situation requiring coordinated management beyond normal operating activity. It may involve security compromise, fraud, service outage, data loss, financial error, safety concerns, compliance failure, or a third-party disruption.
Not every alert becomes an incident, and classification can change as evidence develops. Severity typically reflects impact, urgency, affected parties, spread, legal duties, service dependency, financial loss, and the possibility that the condition remains active.
Organizations should define reporting paths, triage criteria, ownership, escalation, communication, evidence handling, containment, recovery, and review. Teams need flexibility because waiting for complete certainty before opening an incident can allow preventable harm to continue. A named incident commander helps coordinate decisions and accountability.
For Incident, contracts and operating procedures should define control responsibilities, evidence access, incident notice, audit rights, subcontractors, service levels, data handling, termination, and continuity when a provider becomes unavailable.
An incident is an event or series of events that disrupts operations, causes harm, or violates defined security, compliance, or service expectations. Incident must define the affected service or asset, event severity, business and customer impact, evidence, responsible roles, containment priority, recovery objective, and reporting obligations. Effective handling of Incident connects detection, triage, preservation, containment, eradication, recovery, communication, regulatory assessment, and lessons learned through one auditable timeline. An incident is managed uncertainty requiring timely ownership, evidence, containment, communication, recovery, and learning beyond routine ticket handling.
A production treatment of Incident should test the use of harm, or violates defined security, compliance, or service expectations within the relevant asset, decision, or service state. The Incident context record for harm, violates defined security, and compliance should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Incident should determine whether safeguards addressing harm, violates defined security, and compliance changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
An incident is managed uncertainty requiring timely ownership, evidence, containment, communication, recovery, and learning beyond routine ticket handling.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)