This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Information security incident

Information Security

An information security incident is an unforeseen, unwanted event or chain of events that creates a threat and violates the confidentiality, integrity or availability of data. In simple words, it is an occurrence when information falls into the wrong hands, is irretrievably lost or systems become unavailable.

What is an information security incident

An information security (IS) incident is any unwanted or unforeseen event (or a series of them) that violates or creates a threat of violation of the confidentiality, integrity or availability of information and IT systems. In simple words, it is an occurrence when your data ended up in the wrong hands, was irretrievably lost or the system stopped working.

Types of information security incidents Categories of security incidents: malware (viruses, ransomware), unauthorized access (account compromise), data leakage and availability disruption (DDoS attacks). 48. Security incident — types Malware Viruses, ransomware Unauthorized access Account compromise Data leakage Confidentiality theft Availability disruption DDoS attacks
Information security incident — term diagram

It is important to distinguish an incident from a security event. An event is any change in the system that can be both normal and suspicious (for example, a user entered a wrong password). An incident is an event that caused or could cause real damage (for example, an attacker hacked a password and entered the system, stole data or encrypted files).

According to statistics, more than 80% of companies face at least one serious IS incident a year. The cost of eliminating the consequences of one incident on average amounts to millions of rubles, and restoring a reputation can take years. According to Kaspersky Lab, in 2025 the average cost of one incident for Russian business was 12.4 million rubles, and the recovery time was from several days to several weeks. Read about preventing such situations in the article Information security.

Main types of incidents

Information security incidents are classified by the type of threat and the nature of the impact. The most common types:

  • Malware: Infection with viruses, ransomware (encryptors), spyware, trojans, worms and rootkits. Malware can steal data, encrypt files, make the system part of a botnet or completely take it out of operation.
  • Unauthorized access: Hacking attacks, password cracking, illegal privilege escalation, theft of accounts, use of vulnerabilities to gain access to systems. Unauthorized access is one of the most common causes of data leaks.
  • Data leaks and compromise: Illegal copying, deletion or publication of confidential documents, client databases, personal data, trade secrets or state secrets. Leaks can be both external (hackers) and internal (insiders).
  • Availability violation: DDoS attacks (distributed denial-of-service attacks), system blocking, equipment damage, software failures because of which employees and clients cannot access services.
  • Social engineering: Successful phishing attacks, when employees follow malicious links, open infected attachments or give attackers credentials and confidential documents under the pretext of a “check” or “official request”.
  • Internal violations (insider threats): Intentional or accidental disclosure of data by employees, sending confidential information to the wrong addressee, transferring data to personal media or cloud storage.

Read more about types of cyberattacks in the article Cyber fraud.

Incident lifecycle

According to standards (for example, NIST SP 800-61 and domestic methodological recommendations), the classic incident handling process includes the following stages:

  • Detection and recording: Detection of suspicious activity in the system. This can be a trigger of an SIEM system, EDR, antivirus, a user complaint or detection of anomalies in logs.
  • Analysis: Assessment of the scope of the threat, identification of affected systems, determination of the attack type and search for its source. SOC analysts conduct an investigation using logs, network traffic and forensics data.
  • Containment and response: Blocking the attack and preventing its spread. Isolation of infected systems from the network, blocking attackers' IP addresses, disabling compromised accounts.
  • Remediation and recovery: Removal of malware, data recovery from backups (backup system), restoration of system operability, closing the vulnerabilities through which the penetration occurred.
  • Incident analysis (post-mortem): Identification of vulnerabilities, development of measures to prevent similar situations in the future, updating security policies, training employees, preparing a report for management and regulators (if necessary).

Read about data recovery methods in the article Data backup.

How to respond to an incident

Correct response to an incident is critical for minimizing damage. The recommended order of actions:

  • Immediately isolate infected systems from the network (disconnect from the local network and the internet) to prevent the attack from spreading to other devices.
  • Save all logs and evidence for the investigation: system logs, event files, memory dumps, copies of infected files. Do not delete or modify any data until the investigation is complete.
  • Notify management and the security service in accordance with the internal incident response procedure.
  • Involve specialists in incident investigation (forensics) for professional analysis and evidence collection.
  • Notify regulators (Roskomnadzor, FSTEC, Bank of Russia) in cases provided by law (for example, in case of a personal data leak under 152-FZ or incidents at critical information infrastructure facilities). The notification period is usually 24 hours from the moment of detection.

Read about legal aspects in the article Federal Law 152-FZ.

Frequently asked questions

What is an information security incident?

An IS incident is any event that violates or creates a threat of violation of the confidentiality, integrity or availability of information. Examples: password cracking, data leak, DDoS attack, infection with a ransomware virus, unauthorized access to a system. Read about types of threats in the article Cyber fraud.

What types of incidents are there in the field of information security?

The main types of incidents: malware (viruses, encryptors), unauthorized access (account hacking), data leaks (theft or accidental sending of confidential information), DDoS attacks (availability violation), social engineering (phishing), insider threats (employee actions). Each type requires its own approach to response and prevention. Read about protecting against them in the article Information security.

What is the difference between a security event and an IS incident?

An event is any change in the system (for example, a failed login attempt, an antivirus trigger, a configuration change). An incident is an event that caused or could cause real damage (for example, a successful account hack, data theft, system infection). Not all events become incidents, but every incident begins with an event. Read about event monitoring in the article SIEM system.

What to do when an IS incident is detected?

When an incident is detected, it is necessary to: immediately isolate infected systems from the network, save all logs and evidence for the investigation, notify management and the security service, involve investigation specialists (forensics), notify regulators if necessary (Roskomnadzor, FSTEC, Bank of Russia). After elimination, conduct an analysis of the causes and update protection measures. Read about the response plan in the article SOAR.

What are the 3 foundations of information security?

The CIA triad: Confidentiality (access only for authorized persons), Integrity (protection from unauthorized changes) and Availability (data is available when needed). These three principles underlie all information security measures. An IS incident is a violation of one or more of these principles. Read more in the article Information security.

Which incidents are subject to mandatory notification of regulators?

Incidents related to the leak of personal data (152-FZ) are subject to mandatory notification — within 24 hours from the moment of detection to Roskomnadzor. Also incidents at critical information infrastructure facilities — notification to FSTEC within 24 hours. For financial organizations — notification to the Bank of Russia in accordance with the regulator's requirements. Fines are provided for untimely notification.

How to prevent information security incidents?

Preventing incidents requires a comprehensive approach: regular software updates and elimination of vulnerabilities, use of antiviruses, EDR, SIEM and firewalls, regular training of employees in cybersecurity basics (especially the fight against phishing), implementation of secure access policies (MFA, the principle of least privilege), regular data backup (backup system) and penetration testing.

Was this information helpful?

Information Security Back

Information security incident

An information security incident is an unforeseen, unwanted event or chain of events that creates a threat and violates the confidentiality, integrity or availability of data. In simple words, it is an occurrence when information falls into the wrong hands, is irretrievably lost or systems become unavailable.

Protect your network today

Leave a request — our information security specialists will help you select, configure and integrate information security incident into your infrastructure. We will protect your data from threats.

Guaranteed result
Selection for your budget
Comprehensive approach
Certified experts

Or contact us:

+7 (499) 238-01-32 sales@fintech.ru

Open from 9:00 am to 6:00 pm