While terminology varies, most organizations use a tiered severity model.
Severity 1 – Critical Incident
Definition:
A confirmed incident causing or likely to cause severe business impact.
Examples:
- Ransomware impacting critical systems
- Widespread credential compromise
- Active data exfiltration
- Production outages caused by malicious activity
Typical Response:
- Immediate response
- Executive and legal escalation
- Full incident response team engagement
- Continuous monitoring until resolved
Severity 2 – High Incident
Definition:
A significant incident with limited scope or contained impact.
Examples:
- Compromised user account with privileged access
- Malware on a critical system with containment in place
- Targeted phishing campaign with multiple victims
Typical Response:
- Rapid response
- Security and IT coordination
- Targeted containment and eradication
- Management notification
Severity 3 – Medium Incident
Definition:
A confirmed incident with minimal impact and limited scope.
Examples:
- Malware blocked before execution
- Isolated endpoint compromise
- Suspicious activity with no evidence of spread
Typical Response:
- Standard response procedures
- Limited escalation
- Documentation and monitoring
Severity 4 – Low Incident
Definition:
Low-risk events with little or no impact.
Examples:
Failed phishing attempts
- Blocked malicious connections
- Policy violations without compromise
Typical Response:
- Routine handling
- No escalation required
- Logged for trend analysis