Skip to content
atlas

Don't confuse these

Security incident vs Threat

Why they differ

A threat is something that could cause harm; an incident is harm that is actually happening or has happened.

Security incident

Fundamentals

An event that has harmed, or may soon harm, the confidentiality, integrity or availability of information or systems.

Formal

An actual or likely breach of the CIA triad, or of the organisation's security policy, that calls for a response. Unlike a threat, which is only a possibility, an incident is something that is happening or has happened.

In plain English

Not the storm warning on the radio, but the water now dripping through the ceiling - something is already wrong, and someone has to act.

In practice

On Monday morning the IT support desk at a Danish upper-secondary school finds that files on several laptops will not open, and the IT lead opens an incident case and starts the incident response plan.

Why it matters

Calling something an incident starts the clock - NIS2 asks for an early warning within 24 hours of a significant incident, and GDPR gives 72 hours to report a personal data breach.

Threat

Fundamentals

Anything that could harm the organisation - an attacker, a careless mistake, a fire or a power cut.

Formal

Any person, event or circumstance with the potential to cause harm to information or systems by damaging their confidentiality, integrity or availability. A threat does harm only when it meets a weakness it can use.

In plain English

Like a burglar in the neighbourhood or a storm in the forecast - it has not hurt you yet, but it could.

In practice

A Danish shipping company lists its threats - criminal groups sending phishing mails, staff mistakes, a supplier's remote access and flooding of the basement server room.

Why it matters

You cannot guard against what you have not named; knowing the threats tells you what to prepare for and what to ignore.

Shared connections

Atlas is in beta.