
Module 4 · Lesson 4.1
What is a security incident?
A security incident is any event that threatens the confidentiality, integrity, or availability of company systems or data.
Always watching. Always protecting.
What qualifies as an incident?
- Clicked a phishing link
- Lost or stolen device
- Unauthorized system access
- Sending sensitive information to the wrong person
- Malware or ransomware infection
- Suspicious login alerts or MFA prompts
If you’re unsure — report it. It’s better to over-report than under-report.
Why quick identification matters
Early detection reduces damage. The faster Security can respond, the smaller the impact.
- Limits data exposure
- Prevents spread to other systems
- Reduces downtime
- Protects customers and company reputation