Skip to main content
Category: Incident Response & Reporting

Cyber Incident

Also known as: Cybersecurity Incident
Simply put

A cyber incident is an event that actually or imminently harms the confidentiality, integrity, or availability of information or an information system, without lawful authority. In practical terms, it covers situations where systems or data are compromised, disrupted, or exposed in ways that were not authorized. Certain cyber incidents must be reported to the federal government, though specific reporting triggers and timelines depend on the applicable authority and should be verified against current official guidance.

Formal definition

As reflected in the NIST CSRC glossary, a cyber incident is generally described as an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system, or that constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable-use policies. The closely related term 'cybersecurity incident' is defined in similar terms in the CSRC glossary; both glossary entries aggregate multiple source definitions, and the specific verbs used (for example 'actually,' 'imminently,' or 'potentially') vary across those underlying sources rather than serving as a fixed distinction between the two terms. Practitioners should note that reporting obligations, thresholds, and definitions may differ across authorities and system types (for example CISA guidance for federal reporting versus DoD or agency-specific requirements), and the precise governing definition should be confirmed against the applicable authoritative source and revision.

Why it matters

A cyber incident is the trigger that sets an organization's incident response, reporting, and continuous monitoring obligations in motion. Because the term covers events that actually or imminently jeopardize the confidentiality, integrity, or availability of information or an information system without lawful authority, correctly recognizing and classifying an event determines whether reporting requirements apply and what timeline governs. Misjudging whether an event rises to the level of a reportable cyber incident can leave an organization out of compliance with federal, DoD, or agency-specific obligations.

Reporting is not a single, uniform requirement. CISA publishes guidance on when, what, and how to report a cyber incident to the federal government, but reporting triggers, thresholds, and timelines vary across authorities and system types. Federal civilian reporting expectations may differ from DoD requirements or from agency-specific rules, and the governing definition should always be confirmed against the applicable authoritative source and revision. Practitioners should not assume that meeting one authority's reporting obligation satisfies another's.

A common expert correction is to distinguish detection and assessment from the compliance obligation to report and respond. Recognizing that an event is a cyber incident is only the first step; the definition itself does not resolve which threshold applies, and the specific verbs used across source definitions (for example 'actually,' 'imminently,' or 'potentially') vary rather than establishing a fixed rule. Organizations should treat incident classification as a documented, evidence-based judgment tied to current official guidance, not an informal label.

Who it's relevant to

Information System Security Managers and Incident Responders
These practitioners classify detected events against the applicable definition of a cyber incident and initiate response actions. They must recognize that identifying an incident is distinct from satisfying a reporting obligation, and that the governing definition and thresholds should be verified against current official guidance.
Compliance Officers and Auditors
Compliance and audit personnel evaluate whether an organization correctly identifies reportable cyber incidents and meets the applicable reporting requirements. They should account for the fact that reporting triggers and timelines differ across authorities such as CISA, DoD, and individual agencies, and confirm which requirement applies to a given system.
Government Contractors
Contractors handling federal or defense information must understand which cyber incident reporting obligations apply to their systems, recognizing that requirements can vary by authority and system type. They should not assume that meeting one authority's obligation satisfies another's and should confirm the applicable requirements against current authoritative sources.
Authorizing Officials
Authorizing officials rely on accurate incident identification and reporting as part of continuous monitoring and ongoing authorization decisions. They benefit from clear organizational criteria for what constitutes a cyber incident, anchored to the applicable governing definition and revision.

Inside Cyber Incident

Actual or Imminent Jeopardy
A cyber incident generally involves an event that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system. This 'actual or imminent' element distinguishes an incident from a mere anomaly or a lower-severity event. Practitioners should confirm the exact wording against the current NIST glossary source definition, as multiple source definitions exist and the applicable phrasing may vary by publication.
Violation or Threat of Violation of Policy or Law
In addition to jeopardizing CIA of information or systems, common NIST-aligned definitions also frame a cyber incident as an occurrence that constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable-use policies. Omitting this second clause produces an incomplete definition; both the CIA-jeopardy clause and the policy-violation clause appear in the governing wording.
Relationship to Related Terms
'Cyber incident' and 'cybersecurity incident' are closely related terms that appear in NIST glossary entries with multiple source definitions. The CSRC glossary pages for both terms list several source definitions, and neither term is exclusively tied to a single qualifying verb such as 'imminently' or 'potentially.' Readers should not assume a rigid distinction between the two labels without checking the specific source publication being cited.
Source and Scope Dependence
The precise definition applied depends on the governing authority and system context, for example, federal civilian systems under FISMA, DoD systems under the RMF, or contractor systems handling CUI under DFARS-related requirements. Reporting thresholds, timelines, and definitions may differ by framework, agency tailoring, and applicable revision, so the operative definition should be confirmed against current official sources.

Common questions

Answers to the questions practitioners most commonly ask about Cyber Incident.

Are 'cyber incident' and 'cybersecurity incident' distinguished by whether the threat is 'imminent' versus merely 'potential'?
No. This is a common misreading. The NIST CSRC glossary pages for both terms list multiple source definitions, and either wording can appear under either term; neither term is exclusively tied to a single verb such as 'imminently' or 'potentially.' Treating the two terms as separated by that distinction is not supported by the authoritative glossary. Readers should consult the specific governing publication or agency policy that applies to their system, because the operative definition can vary by source and context. Verify the current authoritative text at NIST CSRC before relying on any fixed distinction.
Does a definition of 'cyber incident' only cover events that actually harm a system, or does it also include policy violations?
A complete reading of the NIST wording covers more than harm to a system's confidentiality, integrity, or availability. It also generally includes an event that constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable-use policies. Omitting that second clause produces an incomplete definition. Because agencies and contractual instruments may tailor or reference different source definitions, confirm the precise language applicable to your environment against the current authoritative source.
How should an organization determine whether an observed event rises to the level of a reportable cyber incident?
Organizations generally apply the definition in their governing policy or contract together with documented triage and severity criteria to decide whether an event qualifies. Because reporting thresholds and definitions differ across federal civilian systems under FISMA, DoD systems under the RMF, and CUI-handling obligations under applicable DFARS clauses, the determination should be made against the specific authority that binds the system. This entry does not cover contract-specific or agency-specific reporting thresholds, which the reader must confirm against current official sources.
Who within an organization is typically responsible for classifying and escalating a cyber incident?
Responsibility is usually assigned in an incident response plan and often involves roles such as the information system security manager, the incident response team, and the authorizing official for decisions affecting a system's authorization status. Exact roles, escalation paths, and delegations vary by organization and by the governing framework. Confirm role assignments against your organization's approved incident response plan and applicable policy rather than assuming a standard structure.
How does identifying a cyber incident relate to continuous monitoring and an existing Authority to Operate?
Detection of cyber incidents is generally supported by the continuous monitoring processes associated with a system's authorization. An ATO is time-bound and subject to continuous monitoring, so a significant incident can affect the risk posture the authorizing official relied upon and may prompt reassessment. Incident handling and authorization are related but distinct activities; identifying an incident does not by itself change authorization status. Consult your continuous monitoring strategy and authorizing official's guidance for specifics.
Should the definition of cyber incident used for reporting be taken from NIST alone, or from the applicable contract or regulation?
For reporting purposes, the operative definition is generally the one specified in the applicable regulation, contract clause, or agency policy, which may reference or tailor a NIST source definition. Because definitions and reporting obligations can differ across DoD, federal civilian, and CUI contexts, and because state, local, tribal, and territorial obligations may differ, do not assume a single NIST glossary entry governs all cases. Verify the controlling definition and any reporting timeline against the current authoritative text that binds your system.

Common misconceptions

The NIST glossary cleanly distinguishes 'cyber incident' from 'cybersecurity incident' by using 'imminently' for one and 'potentially' for the other.
The CSRC glossary pages for both terms list multiple source definitions, and either wording can appear under either term. Neither term is exclusively tied to a single qualifying verb, so any claimed one-to-one distinction based on those words is not supported by the glossary.
A cyber incident is defined solely as an event that jeopardizes the confidentiality, integrity, or availability of information or systems.
Common NIST-aligned wording also includes a second clause: an occurrence that constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable-use policies. Dropping this clause yields an incomplete definition.
One universal definition of 'cyber incident' applies across all federal, defense, and contractor environments.
Definitions, reporting thresholds, and obligations can vary by governing authority and system context, and by applicable revision or agency tailoring. The operative definition should be verified against the current official source relevant to the specific system and framework.

Best practices

Cite the specific NIST source definition (and its publication) you are relying on rather than referencing a single generic 'cyber incident' definition, since multiple source definitions exist.
Capture both clauses of the definition in policies and playbooks: the actual or imminent jeopardy to confidentiality, integrity, or availability, and the violation or imminent threat of violation of law, security policies, procedures, or acceptable-use policies.
Avoid drawing rigid distinctions between 'cyber incident' and 'cybersecurity incident' based on qualifying verbs; confirm the intended meaning against the applicable source before treating the terms as different.
Identify the governing framework for the system in question (for example FISMA, DoD RMF, or CUI-related contractual requirements) and apply the definition, thresholds, and reporting obligations that framework specifies.
Re-verify the operative definition against the current authoritative text periodically, because control baselines, terminology, and revisions change over time.
Document the rationale and source used when classifying an event as a cyber incident so that assessments and audits can trace the determination back to a specific authority.