Glossary · OT cybersecurity
Security incident
Also known as: Cybersecurity incident, Incident (security)
German: Sicherheitsvorfall
In cybersecurity, a security incident is an event that actually or potentially compromises the availability, integrity or confidentiality of systems, data or services, or violates security policies. NIS 2 defines an incident as an event compromising the availability, authenticity, integrity or confidentiality of data or services of network and information systems.
- OT security
In one sentence
A security incident is an event that compromises or threatens the availability, integrity or confidentiality of systems, data or services.
Example
Malware found on an engineering workstation that had been connected to several PLCs is treated as a security incident, even though no controller shows abnormal behavior yet.
How it applies
- Operation: Not every security event is an incident. A failed login is an event; repeated failed logins followed by a successful one from an unusual source may be an incident. Clear criteria help staff decide when to start Incident response.
- Compliance: Under NIS 2, significant incidents must be reported to authorities; under the CRA, manufacturers report severe incidents affecting the security of their products.
- Safety: In OT, an incident can affect physical processes. Any incident involving safety-related systems should involve safety experts and may require the plant to move to a safe state.
- Documentation: Incident records document timeline, affected assets, actions and lessons learned. Operating manuals should tell operators what signs of a possible incident look like and whom to inform.
Security incident vs. hazardous event
A security incident compromises systems or data. A Hazardous event in machine safety is an event that can cause harm to people. A security incident can lead to a hazardous event, but the terms belong to different analyses.