Security Incident Or Data Breach

An engineer reports a company laptop missing after a train journey. What you call that event decides what happens next. A security incident starts an investigation, while a personal data breach can start a 72-hour clock. The CIPM exam tests whether you can tell the two apart under pressure. So does the job the exam certifies you for.

Every breach begins as a security incident

A security incident is any event that compromises the confidentiality, integrity or availability of systems or data. The category is wide on purpose: phishing attempts, malware detections, misdirected emails and lost devices all belong in it. NIST finalised Special Publication 800-61 Revision 3 in April 2025. The revision restructures its incident response guidance around the Cybersecurity Framework, and its scope covers exactly this broad class of events.

The GDPR carves a subset out of that class. A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access affecting personal data. Two elements have to combine: a security failure, and personal data actually affected. A malware infection on a build server holding no personal data stays a security incident. The same infection on the HR database becomes a breach.

The lost laptop is instructive. Personal data on it was lost, so the event is a breach even where strong encryption protects the contents. Encryption changes the risk, and risk is what governs notification.

When a security incident starts the clock

Article 33 of the GDPR sets the notification duty. The controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware. One exception exists: a breach unlikely to result in a risk to people’s rights and freedoms needs no notification. The EDPB’s Guidelines 9/2022 on breach notification pin down the trigger. A controller becomes aware once it has a reasonable degree of certainty that a security incident occurred and compromised personal data.

When awareness begins

The clock does not start at the first alert, because a first alert proves nothing. It starts when investigation turns suspicion into reasonable certainty. That reading cuts both ways. It allows genuine triage, and it removes the excuse of leaving an alert sitting uninvestigated.

Notification in phases

Complete information rarely exists within 72 hours, and the regulation accepts that. The controller may notify in phases, supplying detail as the investigation produces it. Reasons must accompany an initial notification that arrives late. A processor that detects a breach tells the controller without undue delay, which is why processor contracts fix tight reporting windows.

Where the breach is likely to produce a high risk for the people affected, Article 34 adds a second duty: communicating with those people directly.

The register that proves the judgement

Article 33(5) requires the controller to document every personal data breach, including the ones never notified. The register records the facts, the effects and the remedial action. It exists so a supervisory authority can check the reasoning afterwards. A register showing twenty assessed events and two notifications tells a defensible story. An empty one invites the question of what went unexamined.

Keeping that discipline is an assessment habit, the same habit that runs through Privacy Threshold Analysis Before The DPIA. Deciding who owns each step of the response belongs to programme design. That choice is worked through in Which Privacy Governance Model Fits.

How the CIPM exam tests the security incident

The Body of Knowledge, the IAPP’s published outline of what the exam covers, places incident handling in the domain on responding to requests and incidents. Sequencing questions dominate: containment generally precedes external notification, and assessment precedes both. Definition questions turn on the subset relationship between incident and breach. The register earns questions of its own, precisely because unnotified breaches still carry documentation duties.

Two study steps fit this subject. The CIPM Trial Exam at 65 euros shows how the exam frames process questions. The CIPM Exam Question Masterclass at 195 euros teaches the method for answering them first time.

Similar Posts