In this work, we study security incidents that occurred over period of 5 years at the National Center for Supercomputing Applications at the University of Illinois. The analysis conducted: (i) quantifies the key characteristics of the incidents, such as category, severity, and detection latency, (ii) develops a data-driven, finite state machine model for describing incidents and exemplifies its use in the context of a credential compromise incident, and (iii) can facilitate the design and deployment of new techniques for security monitoring.