Precursors and Indicators
Precursors and indicators are the warning signs that security teams watch for when detecting potential security incidents. A precursor is a sign that an attack may be coming or being prepared, while an indicator is evidence that an incident is already occurring or has already happened. Together they help responders decide when and how to react to a possible incident.
In incident response practice, a precursor is a sign that an attacker may be preparing to cause an incident, signaling a potential future event, whereas an indicator is an observable artifact or piece of evidence suggesting that an incident is currently occurring or has already occurred. The distinction is temporal: precursors point to potential future incidents, while indicators reflect ongoing or past activity. Detection depends on the monitoring capabilities, logging, and alerting in place, so the specific signals treated as precursors or indicators vary by environment and scope. In a SOC 2 examination these concepts typically support controls evaluated under the Security (Common Criteria) category related to incident detection and response, and in an ISO/IEC 27001 ISMS they inform information security event and incident management processes; the exact controls and evidence assessed depend on scope and the applicable criteria or Statement of Applicability.
Why it matters
The distinction between precursors and indicators shapes how a security team allocates attention across the timeline of a potential incident. A precursor gives responders a chance to act before harm occurs, allowing hardening, heightened monitoring, or preventive measures. An indicator, by contrast, signals that activity is already underway or has already taken place, shifting the emphasis toward containment, eradication, and recovery. Recognizing which type of signal is present helps teams calibrate an appropriate and timely response rather than treating every alert identically.
For organizations pursuing SOC 2 or ISO/IEC 27001 outcomes, the ability to distinguish and act on these warning signs underpins the credibility of incident detection and response capabilities. A SOC 2 examination attests only to the controls and the period covered and does not guarantee freedom from breaches; demonstrating that precursors and indicators are defined, monitored, and acted upon provides evidence that detection controls were suitably designed and, in a Type II engagement, operating effectively over the review period. Similarly, an ISO 27001 ISMS treats these concepts as inputs to information security event and incident management processes, but only within the defined scope of the ISMS.
Because detection depends on the monitoring, logging, and alerting actually in place, the practical value of these concepts is bounded by an organization's visibility. Signals that go uncaptured cannot be classified as either precursors or indicators, so gaps in instrumentation directly limit an incident response program's reach regardless of how well the terminology is understood.
Who it's relevant to
Inside Precursors and Indicators
Common questions
Answers to the questions practitioners most commonly ask about Precursors and Indicators.