Severity model overview
~32 tokIncidents are classified SEV-1 through SEV-4. Severity drives response time, staffing, and executive notification. Misclassification delays are treated as process findings in post-incident review.
Severity model, escalation paths, and SEV classification criteria
Incidents are classified SEV-1 through SEV-4. Severity drives response time, staffing, and executive notification. Misclassification delays are treated as process findings in post-incident review.
We classify SEV-1 incidents as those with confirmed or highly likely compromise of CUI, active ransomware encryption, critical production outage affecting customer delivery SLAs, or safety risk. SEV-1 requires immediate incident commander assignment, 15-minute bridge establishment, CISO notification within 30 minutes, and customer/contracting officer notification per contract flow-down (typically within 72 hours for cyber incidents involving CUI).
SEV-2: significant degradation without confirmed CUI compromise; response within 1 hour. SEV-3: limited impact, contained systems; response within 4 hours. SEV-4: minor issues tracked in ticket queues during business hours.