Skip to Content

A Significant Incident Is Not a Fact, It Is a Decision

Severity classification is a judgement call, and when nobody owns the call, the judgement drifts downwards.

Most incident management advice assumes the hard part is the response. It is not. The hard part is the sentence that has to be said out loud first: this is a major incident. That sentence starts clocks, wakes people up, informs customers and regulators, and commits budget. It is also, unavoidably, somebody's judgement rather than a reading off an instrument.

Severity is not a property of the incident. It is a decision about the incident. And decisions that nobody has been assigned tend to resolve in the direction that requires the least action.

A recent audit of European incident handling documents this at a scale that is hard to argue with, which makes it a useful mirror for anyone running a smaller operation.

The case

In September 2025, ransomware hit software used to process passengers at airports. Several major European airports fell back to manual handling, with the worst disruption at Heathrow, Brussels, Berlin Brandenburg and Dublin (Box 1).

No member state assessed the event as a significant or large-scale cross-border incident. Because it was not classified that way, ENISA and the other member states were not informed, the CSIRTs network did not alert EU-CyCLONe, and coordinated incident management did not take place (Box 1).

Read that sequence carefully, because the causality runs in an unintuitive direction. The coordination machinery did not fail to work. It was never started, and it was never started because a classification decision did not get made.

The pattern

This was not a one-off.

Since 2016, no member state has ever labelled any incident large-scale. The EU-CyCLONe escalation procedure has never been fully activated (para. 40). That set of non-events includes WannaCry in 2017, NotPetya in 2017, and the global outage caused by a faulty CrowdStrike update in July 2024 (Figure 3).

If a category exists for a decade and is never once used, the category is not describing reality. Either nothing that qualifies has happened, which the last decade makes implausible, or the act of putting something in that category is harder than the events that belong in it.

Why it happens

The auditors identify the mechanism, and it is disappointingly mundane.

The CSIRTs network and EU-CyCLONe never agreed a common taxonomy of severity levels, nor common definitions for basic terms such as threat, incident and impact. That leaves what the report calls room for interpretation about when an incident is significant or large-scale. All three member states visited during the audit raised the missing taxonomy independently (para. 30).

Room for interpretation sounds like flexibility. In practice it is a vacuum, and vacuums get filled by whoever is under the least pressure to act.

Consider what declaring a major incident costs the person declaring it. It is visible. It is potentially wrong, and being wrong upwards is embarrassing in a way that being wrong downwards is not, because nobody ever gets asked to justify the incident they did not escalate. It creates work for colleagues, some of whom will be woken up. And in the absence of a written rule, the declarer carries that entirely personally.

Now consider the cost of not declaring. In the moment, zero. The cost arrives later, is diffuse, and by then it attaches to the event rather than to the decision.

That asymmetry is the whole story. It does not require anyone to be negligent, and it reproduces perfectly in a company of thirty people.

The measurement gap this produces

The reporting figures show what the vacuum does to data.

Significant cross-border incidents reported were 3 in 2022, 0 in 2023, 2 in 2024 and 14 in 2025 (para. 38). For comparison, ENISA identified 322 incidents targeting two or more member states from open sources alone in its 2024 threat landscape (para. 38).

The gap between those numbers is not a measure of how much happened. It is a measure of how often somebody decided to file. There is also no European platform that receives reports in real time and correlates them by sector or indicator of compromise (para. 39), so nothing reassembles the picture from below.

The lesson generalises. Incident statistics measure your classification behaviour at least as much as they measure your threat environment. If your P1 count fell last quarter, one explanation is that things improved. Another is that the person who used to declare P1s changed roles.

What this means for your own operation

Here is the uncomfortable transfer. The organisations in this audit have the classification duty written into law, dedicated staff, and standing coordination structures. The classification still did not happen.

Your team, at five o'clock on a Friday, with an ambiguous alert and no written rule, will do the same thing. Not because they are worse, but because they face the same asymmetry with less support.

What removes the asymmetry is not urging people to be brave. It is making the decision cheap, fast and pre-authorised:

  • Write the severity matrix before you need it, with worked examples rather than adjectives. "Significant" is not a definition. "Customer-facing service degraded for more than 30 minutes, or any suspected unauthorised access to production data" is.
  • Define the vocabulary. Threat, incident, impact, event. If two people in a call mean different things by incident, the classification conversation is unwinnable. The EU-level version of this exact problem is what the audit is describing.
  • Name the person who makes the call, with a deputy, and put the name where it can be seen at three in the morning. Classification by consensus means classification by whoever is least willing to escalate.
  • Make ambiguity escalate upwards by default. Write the rule down: if it is unclear whether this is a P1, it is a P1 until someone senior downgrades it. This converts a personal risk into a procedural one, which is the only version anyone will actually take.
  • Separate the classification from the consequences. If declaring a major incident automatically triggers a postmortem with an audience, people will avoid declaring. Decouple them, at least for the first hour.
  • Review downgrades, not just incidents. The decisions worth auditing are the ones where something was classified downwards and turned out not to be small.

Taxonomy is infrastructure

The instinct is to treat severity definitions as documentation: worth writing, filed somewhere, reviewed annually if anyone remembers.

The audit is a decade-long demonstration that they are not documentation. They are load-bearing. Everything downstream - reporting, escalation, coordination, the statistics that feed the next round of decisions - runs on a classification step, and when that step is undefined the entire chain below it silently does not execute. Nothing alarms. There is no error state for a decision that was never made.

Which is why it is worth checking, before the next incident, whether the sentence this is a major incident has an owner in your organisation, or whether it is currently waiting for a volunteer.


Source: European Court of Auditors, Special Report 19/2026, "Detecting and responding to cybersecurity incidents", adopted 16 June 2026. Available at eca.europa.eu under CC BY 4.0. Paragraph numbers in the text refer to the report so the findings can be checked.

An Indicator Without a Baseline Is Not a Metric
A dashboard reported as on track is not evidence of a healthy state. It can also mean nobody checked.