Organizations face cyber threats affecting the security of data, systems and business processes. Even a single event can lead to business disruption, data loss or legal problems. What do we mean by a security incident?
What is a security incident?
A security incident is an event that violates the confidentiality, availability or integrity of systems and data. Most often, it refers to situations related to cyberattacks, user errors or unauthorized access to organizational resources.
An information security incident may include, but is not limited to: data theft, information leakage, ransomware infection, phishing or theft of data media. Security incidents may result from the use of vulnerabilities in systems, employee errors, failures, unauthorized access or events affecting the continuity of services and business processes.
Under GDPR, concepts such as personal data breach incident are often used. These types of events may lead to the disclosure of private data and serious legal consequences.
Incident classification – ordinary, serious, significant, critical
The classification of incidents depends on the legal basis and context. The Act on the KSC uses, among others: concepts of ordinary, serious and critical incident:
- ordinary incident – an event that has an adverse impact on the security of information systems, but does not meet the criteria of a serious or critical incident;
- serious incident – an event that causes or may cause a serious decline in quality or interruption of the continuity of service provision.
- critical incident – an event resulting in significant damage to public security or order, international interests, economic interests, the operation of public institutions, civil rights and freedoms or human life and health.
NIS2, on the other hand, focuses primarily on the obligations to report significant incidents. The GDPR approaches the classification differently, where the basic concept remains a breach of personal data protection. The GDPR incident primarily concerns the risk to the rights and freedoms of persons whose data has been disclosed or lost. ISO/IEC 27001 standards focus on managing security incidents and protecting sensitive organizational resources.
How to respond to a security incident?
Responding to an incident should start with identifying the incident, assessing its scale, securing evidence and limiting the impact of the incident on systems, data and business processes.
Organizations should:
- isolate vulnerable systems,
- secure evidence,
- conduct an analysis of the incident,
- limit the effects of the event,
- start restoring systems,
- implement corrective and preventive actions.
It is also important to determine whether there has been a data leak or unauthorized access. Procedures describing what to do after a phishing attack and quick post-burglary support may be helpful in phishing limiting the effects of the incident.
After completing remedial actions, the organization should conduct a cybersecurity audit and verify whether the vulnerabilities in the systems have been effectively removed.
Incident management and reporting obligations
The NIS2 Directive provides for the obligation to promptly report significant incidents by key and important entities to the appropriate CSIRT or competent authority. In Poland, detailed obligations will depend on the regulations implementing NIS2 into the national legal order:
- Within 24 hours of detecting an incident, the organization should send an initial alert informing about the incident and the potential impact on services or information security.
- A more detailed report must be submitted within 72 hours, including: preliminary analysis of the incident, scale of the violation and actions taken to limit the effects of the event.
- Within 30 days, the organization should prepare a final report including a full analysis of the incident, the causes of the incident, corrective measures taken and actions to prevent similar incidents in the future.
This approach is intended to improve response to security incidents and enable faster exchange of information between organizations and CSIRTs.
FAQ – security incident
What is a security incident?
A security incident is an event that violates the confidentiality, integrity or availability of an organization’s data, systems or services.
What is the difference between a security incident and a cyberattack?
A cyberattack is an activity carried out by cybercriminals or other entities to violate the security of systems, data or services. A security incident, however, has a broader meaning and covers any event that affects the confidentiality, integrity or availability of information – including those resulting from employee errors, system failures or improper security configuration. This means that every cyberattack can be a security incident, but not every security incident is a cyberattack.