Incident Response and Crisis Management
Purpose
Incident response ensures that security events are detected, assessed, contained, eradicated, recovered and learned from.
Severity Model
SEV1 Critical
Confirmed major compromise, material data exposure, loss of critical service or active threat.
Immediate mobilisation, executive escalation, customer notification assessment and crisis cadence.
SEV2 High
Serious incident affecting sensitive data, privileged access, production service or supplier boundary.
Same day escalation, containment plan and formal incident record.
SEV3 Medium
Limited incident, suspicious activity or contained vulnerability exploitation.
Managed through security operations with tracked actions.
SEV4 Low
Minor policy breach, unsuccessful attack or low-impact anomaly.
Record, triage and close with evidence.
Response Phases
Detect and report.
Triage and classify.
Preserve evidence.
Contain the threat.
Eradicate root cause.
Recover service.
Validate integrity.
Notify stakeholders where required.
Conduct post-incident review.
Track corrective actions to closure.
Evidence
incident record;
timeline;
logs and indicators;
decisions and approvals;
notifications;
containment actions;
recovery validation;
lessons learned;
corrective action plan.
Rule
Never sacrifice evidence preservation, legal notification obligations or customer trust for speed unless there is a clear safety, operational or security reason to act immediately.
Last updated
Was this helpful?

