Escalation Matrix.
The Shared Definition Every Playbook Assumes You Already Have.
Every alert playbook on this site says "escalate to L2" or "escalate immediately" without defining what those mean against — this page is that definition. A four-tier severity model, a reference response-SLA baseline for each tier, and the escalation path that follows. Standing operational reference, used across every incident regardless of alert type, not tied to any one playbook.
Severity Classification Matrix
A standard four-tier model, named P1–P4 in some orgs and Critical/High/Medium/Low in others — both namings are common, this page uses Sev1–Sev4 alongside the Critical/High/Medium/Low label for each tier. The SLA column is a sensible reference baseline, not a formal external standard: there's no single industry-mandated number for "how fast is fast enough," and every org codifies its own targets in its IR plan. Treat these as a defensible starting point to adapt, not a compliance requirement.
| Severity | Definition | Example Scenarios | Initial Response SLA | Escalation Path |
|---|---|---|---|---|
| Sev1 / Critical | Active, confirmed compromise with business impact. The activity is not suspected — it's confirmed, and it's causing or about to cause material damage. | Ransomware actively executing/encrypting; confirmed data exfiltration in progress; a critical business system down as a direct result of attack. | Immediate — e.g. 15-minute acknowledgment | Auto-escalates to Tier 2/3 immediately; leadership and the IR team are notified on declaration, not after initial triage. |
| Sev2 / High | Confirmed malicious activity, but contained or of limited scope. The "what" is known and malicious; the "how far" is bounded. | Isolated malware execution on a single endpoint; one compromised user account with no evidence of lateral movement yet. | Fast — e.g. 30–60 minute acknowledgment | Escalates to Tier 2 for investigation and containment; Tier 1 stays engaged for supporting triage. |
| Sev3 / Medium | Suspicious activity that warrants investigation but is not yet confirmed malicious. The alert could be a false positive or the first sign of something larger. | Unusual login pattern (impossible travel, off-hours access); a policy violation that could be benign or could be precursor activity. | Standard — e.g. within the same business day / shift | Tier 1 investigates; escalates to Sev1/Sev2 and Tier 2 immediately if the activity is confirmed malicious. |
| Sev4 / Low | Informational, low-risk, or matches a confirmed false-positive pattern. No credible indication of malicious intent or impact. | Known-benign scanner traffic; a previously-tuned alert firing on an already-understood pattern; routine policy noise. | Routine — e.g. next business day / batch review | Tier 1 closes or logs directly; no escalation unless a pattern across multiple Sev4s emerges. |
Working With Severity
The matrix above is a starting classification, not a fixed label. How severity gets used correctly through the life of an incident.