Insights on Crypto Payments, Infrastructure, and Operations

Major Incident

Pronunciation: MAY-jur IHN-suh-dunt

Definition

A major incident is a high-impact disruption requiring urgent cross-functional coordination, elevated authority, communication, and prioritized service restoration. Major Incident should distinguish an alert, suspected event, confirmed incident, material impact, and restored service because each state requires different decisions and notifications. Major Incident must define the affected service or asset, event severity, business and customer impact, evidence, responsible roles, containment priority, recovery objective, and reporting obligations.

Overview

A major incident exceeds routine operational handling because its impact, urgency, complexity, customer reach, legal significance, or dependency spread is substantial. Examples include prolonged payment outages, widespread account compromise, key exposure, or large data loss.

Classification criteria should reflect critical services, affected customers, financial harm, safety, compliance duties, and recovery time. Teams may declare a major incident before every fact is known because delayed coordination can increase damage.

Response requires an incident commander, clear workstreams, secure communications, decision records, stakeholder updates, containment, recovery, and post-incident review. Authority and escalation paths should be tested through exercises rather than invented during the crisis. Regular status cadence should distinguish verified facts, hypotheses, decisions, and outstanding risks.

A major incident is a high-impact disruption requiring urgent cross-functional coordination, elevated authority, communication, and prioritized service restoration. Major Incident should distinguish an alert, suspected event, confirmed incident, material impact, and restored service because each state requires different decisions and notifications. Major Incident must define the affected service or asset, event severity, business and customer impact, evidence, responsible roles, containment priority, recovery objective, and reporting obligations. Major incidents need rapid centralized coordination while technical, customer, legal, financial, and continuity decisions proceed in parallel.

A production treatment of Major Incident should test a high-impact disruption requiring urgent cross-functional coordination, elevated authority, communication, and prioritized service restoration within the relevant asset, decision, or service state. The Major Incident context record for high-impact disruption requiring urgent cross-functional coordination, elevated authority, and communication should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Major Incident should determine whether safeguards addressing high-impact disruption requiring urgent cross-functional coordination, elevated authority, and communication changed exposure in practice, not merely whether a document or setting existed.

Key Takeaway

Major incidents need rapid centralized coordination while technical, customer, legal, financial, and continuity decisions proceed in parallel.

Sources

  1. NIST Documentation: Cyberframework — NIST (2026-07-30)
  2. FATF Documentation: Virtual Assets — FATF (2026-07-30)