What are Events?

In the digital realm, events are considered any observable occurrence or activity within a computer system that can be logged and recorded (and that could potentially impact an organization’s operations or information security). By this definition, events compromise a rather broad range of activities. For example, an event could be as simple as a user logging into an account, a spike in network traffic, or the receipt of a suspicious email. Or an event could be as complex as a ransomware attack or data breach. While events provide valuable information about a system’s activities and can help security teams identify potential risks, vulnerabilities, or malicious activities, they often occur in such great numbers that it’s impossible to manage and respond to every single one.

Cyber incidents, for instance, are a subset of events. They are events that are known to violate security policies or compromise information and other assets, whether by accident or as a result of malicious intent, and that pose a real-time threat to the integrity of an organization’s infrastructure and business operations. What becomes important is distilling events down and prioritizing them in such a way that teams are able to focus their efforts where they will have the most impact in terms of ensuring business continuity and data protection.


