Spillage
Spillage is what happens when information that is supposed to be protected at a higher classification or sensitivity level ends up on a system that is not approved to handle it. For example, classified data appearing on an unclassified network is considered a spillage. It is treated as a security incident that must be reported and remediated.
Per the NIST CSRC glossary, spillage is a security incident that occurs whenever classified data is transferred onto an information system not authorized to store, process, or transmit data at that classification level (for example, classified data spilled onto an unclassified information system). Handling a spillage generally requires incident response actions such as containment, reporting through the applicable chain, sanitization or remediation of affected media and systems, and coordination with the relevant security authorities. The specific reporting timelines, cleanup procedures, and authorities involved are governed by agency-specific and program-specific policy, and readers should confirm the applicable requirements against current authoritative sources.
Why it matters
Spillage is treated as a security incident rather than a routine data-handling error because it places protected information on a system that lacks the safeguards, accreditation, and access controls appropriate to that information's classification or sensitivity level. Once classified or otherwise controlled data lands on an unauthorized system, every user, connection, and storage medium touched by that system may become part of the exposure, which is why spillage generally triggers formal incident response rather than an informal fix.
The consequences extend beyond the moment of the spill. Remediation typically involves containing the affected system, reporting through the applicable chain, and sanitizing or otherwise remediating impacted media and systems. These actions can take systems offline and require coordination with security authorities, so a single spillage can disrupt operations well beyond the individuals directly involved. Because the specific reporting timelines and cleanup procedures are set by agency-specific and program-specific policy, the operational impact and required response can vary significantly from one environment to another.
A common expert correction is that spillage is not merely a matter of deleting a file. Because the data reached a system not authorized to handle it, remediation is governed by formal sanitization and reporting requirements rather than casual cleanup, and readers should confirm the exact obligations that apply to their environment against current authoritative sources rather than assuming a uniform standard.
Who it's relevant to
Inside Spillage
Common questions
Answers to the questions practitioners most commonly ask about Spillage.