Skip to main content
INCIDENT-RESPONSE-IT5 MIN READ

Set severity by business impact, not malware drama

Assess incident severity using mission impact, scope, and recovery implications rather than technical novelty alone.

Good severity models answer one question: how hard should the organization move? If the label only reflects how alarming the technical artifact looks, the model fails. A scary ransom screen is visible and easy to escalate. A stolen session token, suspicious OAuth grant, or tampered backup policy may look quieter while carrying far larger downstream risk. Use at least four lenses. Business impact: what services, users, revenue, or obligations are at risk? Scope: how many assets, identities, or environments are implicated? Adversary leverage: did the attacker gain privilege, persistence, or lateral movement paths? Recovery burden: can you restore cleanly, or…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us