What is a cyber incident?¶
A cyber incident is an event, or series of events, involving digital systems, accounts, networks or data that may have caused unauthorised access, disruption, misuse, loss or harm.
Evidential caution: that a cyber incident always means a sophisticated external attack. It may instead involve a compromised account, accidental exposure, insider misuse, malicious software, unauthorised remote access, data theft, service disruption or abuse of legitimate administrative tools.
What this means¶
That definition is deliberately broad.
It is also important to distinguish an incident from an alert.
An incident normally requires some assessment of context. Investigators should ask what happened, which asset or account was affected, whether the activity was authorised, what the consequence was and what evidence supports the assessment.
The same technical event may have different meanings in different environments. A remote login may be routine for an administrator but suspicious for an ordinary user. A large data transfer may be an approved backup, an employee moving work files or deliberate exfiltration. A malware detection may represent blocked code, a quarantined file or successful execution.
For investigative purposes, the label matters less than the underlying facts.
A cyber incident can contribute evidence about method, access, sequence, impact and technical attribution. It will not necessarily establish who was personally responsible.
================================================================================
What to check or do next¶
- Record the observed activity, the affected systems, the time period, the source of the information and the claimed impact. Avoid repeating labels such as “breach”, “hack” or “compromise” unless the available evidence supports them.
Evidential limits¶
An alert is a notification generated by a security product, rule or analyst. It may indicate something worth investigating, but it does not automatically prove that malicious activity occurred.
Operational takeaway
Treat “cyber incident” as a starting classification and base your conclusions on the underlying events, records and context.