# Incident Severity Matrix

Owner: __________  Version: __________  Last tested: __________

| Level | Operational impact | Scope | Data / identity impact | Required coordination | Initial update target |
|---|---|---|---|---|---|
| SEV-1 Critical | Safety, critical service, or enterprise operations at risk | Enterprise, privileged control plane, or rapidly expanding | Confirmed material data loss, destructive action, or privileged identity compromise | IR lead, executive leadership, legal/privacy, communications, insurer, applicable authorities | 15 minutes |
| SEV-2 High | Major service degradation or high-value system affected | Multiple systems, business units, or sensitive environment | Probable sensitive-data access or high-confidence privileged abuse | IR lead, system owner, legal/privacy as applicable | 30 minutes |
| SEV-3 Moderate | Limited service or user impact | Contained host, account, application, or segment | No confirmed sensitive-data access | Incident lead and system owner | 2 hours |
| SEV-4 Low | No material operational impact | Single low-risk asset or blocked attempt | No evidence of unauthorized access | Queue owner | Business day |

## Rating record

- Current severity and UTC time:
- Evidence supporting the rating:
- Business services affected:
- Confidence: Low / Medium / High
- Conditions that require escalation:
- Approver:

Severity is dynamic. Reassess after every material scope, impact, or confidence change.
