H3AD-REF / SOC OPS / ESCALATION MATRIX & SEVERITY CLASSIFICATION

Escalation Matrix.
The Shared Definition Every Playbook Assumes You Already Have.

Every alert playbook on this site says "escalate to L2" or "escalate immediately" without defining what those mean against — this page is that definition. A four-tier severity model, a reference response-SLA baseline for each tier, and the escalation path that follows. Standing operational reference, used across every incident regardless of alert type, not tied to any one playbook.

Severity Classification Matrix

A standard four-tier model, named P1–P4 in some orgs and Critical/High/Medium/Low in others — both namings are common, this page uses Sev1–Sev4 alongside the Critical/High/Medium/Low label for each tier. The SLA column is a sensible reference baseline, not a formal external standard: there's no single industry-mandated number for "how fast is fast enough," and every org codifies its own targets in its IR plan. Treat these as a defensible starting point to adapt, not a compliance requirement.

Severity Definition Example Scenarios Initial Response SLA Escalation Path
Sev1 / Critical Active, confirmed compromise with business impact. The activity is not suspected — it's confirmed, and it's causing or about to cause material damage. Ransomware actively executing/encrypting; confirmed data exfiltration in progress; a critical business system down as a direct result of attack. Immediate — e.g. 15-minute acknowledgment Auto-escalates to Tier 2/3 immediately; leadership and the IR team are notified on declaration, not after initial triage.
Sev2 / High Confirmed malicious activity, but contained or of limited scope. The "what" is known and malicious; the "how far" is bounded. Isolated malware execution on a single endpoint; one compromised user account with no evidence of lateral movement yet. Fast — e.g. 30–60 minute acknowledgment Escalates to Tier 2 for investigation and containment; Tier 1 stays engaged for supporting triage.
Sev3 / Medium Suspicious activity that warrants investigation but is not yet confirmed malicious. The alert could be a false positive or the first sign of something larger. Unusual login pattern (impossible travel, off-hours access); a policy violation that could be benign or could be precursor activity. Standard — e.g. within the same business day / shift Tier 1 investigates; escalates to Sev1/Sev2 and Tier 2 immediately if the activity is confirmed malicious.
Sev4 / Low Informational, low-risk, or matches a confirmed false-positive pattern. No credible indication of malicious intent or impact. Known-benign scanner traffic; a previously-tuned alert firing on an already-understood pattern; routine policy noise. Routine — e.g. next business day / batch review Tier 1 closes or logs directly; no escalation unless a pattern across multiple Sev4s emerges.

Working With Severity

The matrix above is a starting classification, not a fixed label. How severity gets used correctly through the life of an incident.

REASSESS CONTINUOUSLY

Severity Is Reassessed, Not Fixed At Ticket Creation

A Sev3 unusual-login alert that turns out, twenty minutes into investigation, to be lateral movement from a compromised account becomes Sev1 immediately — not at the next scheduled review, not once the shift lead has time. The initial classification is a starting point for triage, not a commitment that survives new evidence.
SEVERITY ≠ PRIORITY

Severity Is Impact. Priority Is Queue Order.

Severity describes the incident's own impact and urgency — it doesn't change based on what else is happening. Priority describes where it sits in the analyst's work queue right now, which is affected by staffing, concurrent incidents, and what's already in progress. A Sev2 can briefly outrank a Sev1 in priority if the Sev1 already has three analysts assigned and the Sev2 has none — the severity label didn't change, the queue order did.
AVOID OVER-CLASSIFICATION

Alert Fatigue From Treating Everything As High Severity

Labeling routine or ambiguous alerts as Sev1/Critical to force fast attention erodes the entire scale's meaning. Once "everything is critical," analysts stop trusting the label and start triaging by gut feel instead of the matrix — which means the incidents that are genuinely Sev1 wait behind noise instead of getting the response the tier is supposed to guarantee.
BASELINE, NOT STANDARD

These SLA Numbers Are A Reference, Not A Mandate

No single external body sets a universal "15 minutes for Sev1" rule — NIST, SANS, and vendor frameworks describe the tiering concept but leave exact timings to each organization. The SLA column above is a defensible baseline to adapt to your team's staffing and tooling, then formalize in your own IR plan, not a number to cite as an industry requirement.
RELATED, NOT THE SAME AXIS
This page answers "how bad is it and how fast do we respond." SOC Operations Reference answers a separate question — which analyst tier picks it up and when it escalates from Tier 1 to Tier 2 to Tier 3. The two models compose: a Sev1 still starts wherever the tier model says triage begins.