Skip to content
atlas

Don't confuse these

False positive vs Security incident

Why they differ

A security incident is real harm or a real threat; a false positive only looked like one until someone checked.

False positive

Detection & response

An alarm about an attack or problem that turns out not to exist, because harmless activity was taken for harmful.

Formal

The result when a monitoring tool, rule or model marks harmless activity as harmful; its opposite, a false negative, is a real attack that raises no alarm at all.

In plain English

Like a car alarm that goes off every time a lorry drives past; after a week, nobody on the street even looks up.

In practice

At a pension fund, an alarm reports “possible data theft” from the finance drive; the analyst sees it is the report job that runs on the last day of every month, and closes it.

Why it matters

Each one wastes a little time, but many of them teach staff to ignore alarms - and then the one real attack is waved through with the rest.

Security incident

Fundamentals

An event that has harmed, or may soon harm, the confidentiality, integrity or availability of information or systems.

Formal

An actual or likely breach of the CIA triad, or of the organisation's security policy, that calls for a response. Unlike a threat, which is only a possibility, an incident is something that is happening or has happened.

In plain English

Not the storm warning on the radio, but the water now dripping through the ceiling - something is already wrong, and someone has to act.

In practice

On Monday morning the IT support desk at a Danish upper-secondary school finds that files on several laptops will not open, and the IT lead opens an incident case and starts the incident response plan.

Why it matters

Calling something an incident starts the clock - NIS2 asks for an early warning within 24 hours of a significant incident, and GDPR gives 72 hours to report a personal data breach.

Atlas is in beta.