Workshop Resources

Respond · Reference sheet

Incident Severity Matrix

Match what you're seeing to a priority level — and check it's actually an incident before you declare one.

P1 Critical

Business outage. All or most users affected. Immediate, all-hands response required.

Cybersecurity
Active ransomware encrypting production systems; confirmed data exfiltration in progress.
InfoSec
Confirmed breach of a customer database with a public disclosure obligation.
IT Operations
Total loss of the production environment; primary data center or region offline.
DevOps
CI/CD pipeline compromised and shipping malicious code to prod.
SaaS
Platform-wide outage; core service returning errors for all customers.
Weather / Climate
Facility evacuated for hurricane or wildfire; power grid down with no failover.
P2 High

Major impact. Multiple users or services degraded. Needs fast resolution, same-shift response.

Cybersecurity
Malware detected and contained on a subset of endpoints; unauthorized access.
InfoSec
Phishing campaign compromises several employee accounts.
IT Operations
Major service degradation affecting multiple regions or customer segments.
DevOps
Bad deploy forces a partial rollback; alerting/monitoring goes dark (blind spot).
SaaS
Key feature (billing, login, checkout) unavailable for a subset of customers.
Weather / Climate
Storm knocks out one data center or office; flooding threatens on-prem hardware.
P3 Medium

Limited impact. A workaround exists. Handled within normal SLA, no need to interrupt other work.

Cybersecurity
Isolated malware on a single non-critical endpoint; contained by existing controls.
InfoSec
DLP tool flags a policy violation; no data loss confirmed.
IT Operations
Non-critical service degraded; documented workaround available.
DevOps
Deploy rolled back on failing tests before reaching customers; staging environment down.
SaaS
Minor feature bug affecting a subset of users; workaround exists.
Weather / Climate
Snow day — office closed, remote work continues without disruption.
P4 Low

Minor issue. Cosmetic or single-user. Planned resolution, no urgency.

Cybersecurity
Reported phishing email confirmed benign; low-severity scan finding, patch scheduled.
InfoSec
Documentation gap found during a routine access review.
IT Operations
Cosmetic UI bug; a single non-critical alert misfiring.
DevOps
Flaky test in the CI pipeline; noisy logging from a deprecated service.
SaaS
Single-user account issue; upcoming planned maintenance window.
Weather / Climate
Light rain delays an outdoor event; no operational impact.

What is not an incident

Not everything is an incident. If it's clearly a P4, it may just be a ticket. A small bug with a fix already on its way, a routine request, a single-user hiccup — handle it in the normal flow. Right-size the response: declaring an incident pulls people onto a bridge and out of their work, so do it when you need coordinated response, not just effort.

Declaring an incident

"Incident" is an overloaded term. ITIL incidents, security incidents, infrastructure incidents, and the things your lawyers must call an incident are not the same list. Disambiguate inside your org before you need it — including which kinds Legal declares, not just engineering.

Some incidents are declared for you. Data-loss and reporting duties — Form 8-K, NIS2, GDPR, DORA — come with clocks that start at detection, whatever the situation feels like.

Decide now who may declare. Keep the list short and explicit, and when it happens, log who declared and when — it's the first line on the run sheet.