Respond · Reference sheet
Incident Severity Matrix
Match what you're seeing to a priority level — and check it's actually an incident before you declare one.
Business outage. All or most users affected. Immediate, all-hands response required.
- Cybersecurity
- Active ransomware encrypting production systems; confirmed data exfiltration in progress.
- InfoSec
- Confirmed breach of a customer database with a public disclosure obligation.
- IT Operations
- Total loss of the production environment; primary data center or region offline.
- DevOps
- CI/CD pipeline compromised and shipping malicious code to prod.
- SaaS
- Platform-wide outage; core service returning errors for all customers.
- Weather / Climate
- Facility evacuated for hurricane or wildfire; power grid down with no failover.
Major impact. Multiple users or services degraded. Needs fast resolution, same-shift response.
- Cybersecurity
- Malware detected and contained on a subset of endpoints; unauthorized access.
- InfoSec
- Phishing campaign compromises several employee accounts.
- IT Operations
- Major service degradation affecting multiple regions or customer segments.
- DevOps
- Bad deploy forces a partial rollback; alerting/monitoring goes dark (blind spot).
- SaaS
- Key feature (billing, login, checkout) unavailable for a subset of customers.
- Weather / Climate
- Storm knocks out one data center or office; flooding threatens on-prem hardware.
Limited impact. A workaround exists. Handled within normal SLA, no need to interrupt other work.
- Cybersecurity
- Isolated malware on a single non-critical endpoint; contained by existing controls.
- InfoSec
- DLP tool flags a policy violation; no data loss confirmed.
- IT Operations
- Non-critical service degraded; documented workaround available.
- DevOps
- Deploy rolled back on failing tests before reaching customers; staging environment down.
- SaaS
- Minor feature bug affecting a subset of users; workaround exists.
- Weather / Climate
- Snow day — office closed, remote work continues without disruption.
Minor issue. Cosmetic or single-user. Planned resolution, no urgency.
- Cybersecurity
- Reported phishing email confirmed benign; low-severity scan finding, patch scheduled.
- InfoSec
- Documentation gap found during a routine access review.
- IT Operations
- Cosmetic UI bug; a single non-critical alert misfiring.
- DevOps
- Flaky test in the CI pipeline; noisy logging from a deprecated service.
- SaaS
- Single-user account issue; upcoming planned maintenance window.
- Weather / Climate
- Light rain delays an outdoor event; no operational impact.
What is not an incident
Not everything is an incident. If it's clearly a P4, it may just be a ticket. A small bug with a fix already on its way, a routine request, a single-user hiccup — handle it in the normal flow. Right-size the response: declaring an incident pulls people onto a bridge and out of their work, so do it when you need coordinated response, not just effort.
Declaring an incident
"Incident" is an overloaded term. ITIL incidents, security incidents, infrastructure incidents, and the things your lawyers must call an incident are not the same list. Disambiguate inside your org before you need it — including which kinds Legal declares, not just engineering.
Some incidents are declared for you. Data-loss and reporting duties — Form 8-K, NIS2, GDPR, DORA — come with clocks that start at detection, whatever the situation feels like.
Decide now who may declare. Keep the list short and explicit, and when it happens, log who declared and when — it's the first line on the run sheet.