Set severity by business impact, not malware drama
Assess incident severity using mission impact, scope, and recovery implications rather than technical novelty alone.
Good severity models answer one question: how hard should the organization move? If the label only reflects how alarming the technical artifact looks, the model fails. A scary ransom screen is visible and easy to escalate. A stolen session token, suspicious OAuth grant, or tampered backup policy may look quieter while carrying far larger downstream risk. Use at least four lenses. Business impact: what services, users, revenue, or obligations are at risk? Scope: how many assets, identities, or environments are implicated? Adversary leverage: did the attacker gain privilege, persistence, or lateral movement paths? Recovery burden: can you restore cleanly, or…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in