Cyber Incident
A cyber incident is an event that actually or imminently harms the confidentiality, integrity, or availability of information or an information system, without lawful authority. In practical terms, it covers situations where systems or data are compromised, disrupted, or exposed in ways that were not authorized. Certain cyber incidents must be reported to the federal government, though specific reporting triggers and timelines depend on the applicable authority and should be verified against current official guidance.
As reflected in the NIST CSRC glossary, a cyber incident is generally described as an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system, or that constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable-use policies. The closely related term 'cybersecurity incident' is defined in similar terms in the CSRC glossary; both glossary entries aggregate multiple source definitions, and the specific verbs used (for example 'actually,' 'imminently,' or 'potentially') vary across those underlying sources rather than serving as a fixed distinction between the two terms. Practitioners should note that reporting obligations, thresholds, and definitions may differ across authorities and system types (for example CISA guidance for federal reporting versus DoD or agency-specific requirements), and the precise governing definition should be confirmed against the applicable authoritative source and revision.
Why it matters
A cyber incident is the trigger that sets an organization's incident response, reporting, and continuous monitoring obligations in motion. Because the term covers events that actually or imminently jeopardize the confidentiality, integrity, or availability of information or an information system without lawful authority, correctly recognizing and classifying an event determines whether reporting requirements apply and what timeline governs. Misjudging whether an event rises to the level of a reportable cyber incident can leave an organization out of compliance with federal, DoD, or agency-specific obligations.
Reporting is not a single, uniform requirement. CISA publishes guidance on when, what, and how to report a cyber incident to the federal government, but reporting triggers, thresholds, and timelines vary across authorities and system types. Federal civilian reporting expectations may differ from DoD requirements or from agency-specific rules, and the governing definition should always be confirmed against the applicable authoritative source and revision. Practitioners should not assume that meeting one authority's reporting obligation satisfies another's.
A common expert correction is to distinguish detection and assessment from the compliance obligation to report and respond. Recognizing that an event is a cyber incident is only the first step; the definition itself does not resolve which threshold applies, and the specific verbs used across source definitions (for example 'actually,' 'imminently,' or 'potentially') vary rather than establishing a fixed rule. Organizations should treat incident classification as a documented, evidence-based judgment tied to current official guidance, not an informal label.
Who it's relevant to
Inside Cyber Incident
Common questions
Answers to the questions practitioners most commonly ask about Cyber Incident.