Severity & Escalation
Severity can change as new evidence becomes available. Consider risk of harm, operational disruption, number of users affected and notification requirements.
Severity
Typical impact
Lead response
MTTA / MTTR
Low
Minimal disruption, single user, very low financial or reputational impact.
Incident Handler
48h / 72h
Medium
Small group of users or one privileged user, low financial risk.
Incident Handler, escalate if needed
12h / 48h
High
May cause harm, affect many users or SLT, likely notification and reputational risk.
CSIRT Lead
8h / 12h
Critical
Likely harm, significant disruption, large user impact, major notification and reputational risk.
Crisis Management / CMT structure
4h / 8h
Core Principles
Report early
Report suspicious activity immediately, even if unsure. Early reporting helps contain threats and reduce impact.
Preserve evidence
Do not delete emails, screenshots, logs, alerts or files that may help investigation.
Do not self-investigate
Avoid fixing, hiding or sharing incident details. ICT and security teams should manage investigation and response.
Protect CIA
Response decisions should protect confidentiality, integrity and availability of systems and data.