Skip to main content

Evidence-led intelligence · rolling 90-day view

Cyber Incident Impact Areas

An impact area describes what a cyber incident actually caused, not how the attacker operated. Shadow Tier classifies an impact only when current reporting or precise upstream VERIS evidence confirms the consequence.

Published guides

Which cyber incident impacts can you explore?

How can you browse other classified impacts?

Use these filters to focus the current incidents on a specific consequence, including data exposure, service disruption, data integrity issues and financial loss.

Current signals

Which reputational impact signals are visible now?

No matching classified signals are visible in the current 90-day window.

The view updates when new evidence becomes available.

FAQ

How does Shadow Tier connect incidents to impacts?

What evidence is required?

The title or summary must explicitly confirm the impact, or a precise upstream VERIS attribute must support it.

Why separate attack and impact?

Ransomware, phishing and exploitation describe actions. Exposure and disruption describe consequences and require their own evidence.

Can one incident have several impacts?

Yes. The same incident can expose data, interrupt services, undermine data integrity and cause financial loss when the available evidence supports each consequence.