Severity & Escalation

Severity can change as new evidence becomes available. Consider risk of harm, operational disruption, number of users affected and notification requirements.

Severity
Typical impact
Lead response
MTTA / MTTR
Low
Minimal disruption, single user, very low financial or reputational impact.
Incident Handler
48h / 72h
Medium
Small group of users or one privileged user, low financial risk.
Incident Handler, escalate if needed
12h / 48h
High
May cause harm, affect many users or SLT, likely notification and reputational risk.
CSIRT Lead
8h / 12h
Critical
Likely harm, significant disruption, large user impact, major notification and reputational risk.
Crisis Management / CMT structure
4h / 8h
Core Principles
Report early

Report suspicious activity immediately, even if unsure. Early reporting helps contain threats and reduce impact.

Preserve evidence

Do not delete emails, screenshots, logs, alerts or files that may help investigation.

Do not self-investigate

Avoid fixing, hiding or sharing incident details. ICT and security teams should manage investigation and response.

Protect CIA

Response decisions should protect confidentiality, integrity and availability of systems and data.

Strengthening Cybersecurity Awareness and Incident Response Capacity for Humanitarian Operations · Version 1.0 · August 2026