Glossary · Duties and incidents

Incident

Definition

Under the NIS Regulations 2018 as amended by the Cyber Security and Resilience Bill, an incident is any event having, or capable of having, an adverse effect on the operation or security of network and information systems. The Bill adds events that merely could cause harm, and harm to how systems operate, not only their security.

What did the 2018 definition say, and what does it say now?

Regulation 1(2) of the NIS Regulations 2018 currently defines an incident as "any event having an actual adverse effect on the security of network and information systems". That wording excluded two things: attempts that were stopped before causing harm, and failures that disrupted a service without any security compromise.

Clause 15(2) of the Cyber Security and Resilience Bill rewrites it. Once commenced, an incident will be any event having, or capable of having, an adverse effect on the operation or security of network and information systems. The phrase network and information systems keeps its 2018 meaning.

Does every incident have to be reported?

No. "Incident" is the starting category, not the reporting trigger. Each regulated group has its own test for a significant incident, and only incidents that pass it must be notified within the 24-hour and 72-hour clocks.

For operators of essential services, digital service providers and managed service providers, the test requires that the incident "has affected or is affecting" the operation or security of the relevant systems, and that its impact is or is likely to be significant. The data centre test in regulation 11A(3) is wider, because it also catches incidents that "could have had" a significant impact. This is why "near miss" reporting is clearest for data centres.

Why does the wider definition matter in practice?

The definition shapes security duties as well as reporting. Regulations 10, 12 and 14B require measures to prevent and minimise the impact of incidents, so a definition that includes potential and operational harm widens what those measures must address.

It also changes evidence. Regulators with information and inspection powers can ask how you identified, triaged and decided not to report an event. Organisations should log events capable of adverse effect, record the significance assessment, and keep that record even when the answer is "not reportable".

  • Blocked intrusion attempts and failed ransomware deployments are now incidents.
  • A misconfiguration that takes a service offline is an incident, even with no attacker involved.
  • Whether either must be notified still depends on the significance tests.

Common misconceptions

Myth: The Bill makes every blocked attack reportable.

Reality: Blocked attacks become incidents, but notification still depends on the significance test for your category. Outside data centres, the incident must have affected or be affecting the relevant systems.

Myth: Only cyber attacks count as incidents.

Reality: Adding "operation" means non-malicious events that adversely affect how systems operate, such as a failed update causing an outage, also fall within the definition.

Where it appears in the Bill

  • Cl.15(2)Amends the definition of "incident" in NIS reg 1(2).
  • NIS reg 1(2)Home of the definition, in the 2018 Regulations rather than the Bill.
  • New reg 11A(3)Data centre incidents include impact the incident "could have had".
  • New regs 11(3), 12A(2), 14E(2)Reportability tests built on the amended definition.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

What is the difference between an incident and a significant incident?

An incident is any event having, or capable of having, an adverse effect on the operation or security of network and information systems. A significant incident is one that meets the reporting test for your category in regulation 11, 11A, 12A or 14E. Only significant incidents trigger the 24-hour initial notification and 72-hour full notification.

Does a system outage with no attacker count as an incident?

Yes, once the Bill is in force. Clause 15(2) adds "operation" to the definition, so an event that adversely affects how network and information systems operate is an incident even without a security breach. A failed software update or a hardware fault that takes a service down can therefore qualify, subject to the significance test for reporting.

When does the new incident definition apply?

Not yet. The Cyber Security and Resilience Bill is still in the House of Lords, with Report Stage next and no date set. Royal Assent is expected between late 2026 and spring 2027, and most Part 2 changes will then be brought into force by commencement regulations. Until then, the 2018 definition requiring an actual adverse effect on security applies.

Related guidance

Official sources

More in Duties and incidents

Full glossary