When something happens · 4.1

What counts as an incident

What counts as an incident. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see NIST incident-response guidance.

Why the definition matters

Because a clock attaches to it

Most organisations have an informal sense of what an incident is, and it is calibrated to how bad the day feels. Reporting obligations are not calibrated that way: they attach to a definition written in a contract clause, and that definition is broader than the informal sense.

Which means the first question after something happens is not how serious it is but which definition it meets.

Four words that are not synonyms

Event, incident, breach, finding

An event is anything the systems recorded. Most are nothing.

An incident is an event that meets a defined threshold, and the threshold that matters is the contractual one rather than the one in your internal policy.

A breach is a term from data protection law with its own definitions and its own obligations, which may be engaged at the same time and by a different regime.

A finding is something an assessor identifies. It is not an incident, it does not carry a reporting clock, and the two are confused often enough to be worth separating.

The contractual threshold

Lower than people expect

The defence clause requires rapid reporting of cyber incidents that affect covered defence information or the contractor's ability to perform certain contract requirements. It does not require the incident to have been successful in the way people imagine, and it does not require certainty.

Read the clause in your own contract rather than a summary of it, including this one, because the wording governs.

Rests on

The safeguarding clause in the defence acquisition regulation supplement, which states the reporting requirement and the definitions it uses. The clause text is published.

Which version of the clause is in your contract, and what it obliges, is a question about that contract.

Worked examples

Five things and whether they count

A laptop with covered information is lost. Almost certainly reportable. Encryption is relevant to the consequences and not necessarily to the obligation.

Covered information is emailed to the wrong supplier. Reportable, and commonly not recognised as an incident at all because nobody attacked anything.

Ransomware on a system with no covered information. Depends on whether it affected the ability to perform, which is the second limb of the clause and the one people forget.

A machine controller behaves oddly and is reimaged. Possibly reportable, and now unanswerable, because the evidence was destroyed. The entry on the first hour is about this.

An assessor finds a control not operating. Not an incident.

Who decides

One named person, reachable

The determination is a judgement made quickly, sometimes at night, on incomplete information. It needs a named decision-maker with a deputy, both reachable, and both with the authority to start a report.

Where the decision requires assembling three people who are not on call, the clock runs while the meeting is arranged.

Documenting the decision

Including the decision not to report

A written record of what happened, what was considered, and why it was or was not reportable. Dated at the time rather than reconstructed later.

This protects a reasonable decision that turns out to have been wrong, and its absence makes a reasonable decision look like an oversight.

Over-reporting

Not free, and better than the alternative

Reporting things that turn out to be nothing consumes your time and the recipient's, and it is recoverable. Failing to report something that was reportable is not, and the discovery usually happens at the worst moment.

Where the judgement is genuinely balanced, take advice quickly rather than deliberating past the deadline.

Also

Elsewhere in when something happens