Concept and mechanism
A near miss reveals a situation that could have caused impact even when a control prevented loss. If a second person detects an incorrect amount before transmission, record what happened, what was prevented, and how detection occurred. Do not turn potential value into realized loss. Do not omit the case to improve a zero-incident metric either. Records should distinguish occurrence, discovery, and accounting when those dates differ. This information helps explain detection delay and process weaknesses. Concrete classification and granularity follow institutional policy; exercises prescribe neither a complete regulatory taxonomy nor an actual accounting entry.
Guided application
During response, communicate confirmed facts, labelled estimates, gaps, and the next update. Final cause is not required before mobilizing owners, but a hypothesis should not be presented as certainty. NIST SP 800-61 Revision 3, published in April 2025, connects response and continuous learning with risk management. Internal coordination, public communication, and formal notification are distinct activities with their own roles and requirements. Legal deadlines depend on scope and current rules; this pathway does not invent a universal clock. If restarting resolves three episodes but failure returns, link the events and address common causes and controls. Restoring service is progress but does not establish elimination of exposure.
Example: failure Friday, discovery Monday, and cost recorded Wednesday. Retaining three dates supports detection measurement without creating three fictional losses.
Common pitfalls
Zero loss treated as no learning; hypothesis treated as cause; restart treated as prevention; accounting date treated as complete timeline.
Related topics: Scope, governance, and accountability · Risk assessment and control effectiveness · Indicators, reporting, and acceptance
Preserve timeline and uncertainty, respond, and turn evidence into improvement.
Reference: Incident Response Recommendations and Considerations for Cybersecurity Risk Management · DR operational risk professional assessment2026.10