In discussing the difference between incident detection precursors and incident detection
indicators, we must first understand that both are designed to catch threats and attacks
on a system. I look at precursors as a forewarning of potential threats and attacks,
companies would find out about these types of incidents via security blogs or through the
information that's available publicly. In an industry such as healthcare where PII and PHI
would be what companies protect. This is done through "predefined incident response
(IR) procedure, which includes preparation, detection and analysis, containment,
eradication, and recovery, and post-incident activities"(He, Ying, et al. “Healthcare
Security Incident Response Strategy - A Proactive Incident Response (IR) Procedure.)
As for indicators, these are alerts or notifications that will popup based on an incident