Communication
Escalation Matrix and Procedures
Framework for determining when and how to escalate security incidents based on severity.
Communication · beginner · Template - customize for organization
Escalation procedures and contact matrix for security incidents.
Steps
5
01
Severity Classification
Determine incident severity.
- Critical (P1): Active breach, ransomware, executive compromise
- High (P2): Contained incident, significant risk
- Medium (P3): Limited impact, under control
- Low (P4): Minor incident, no immediate risk
02
Initial Escalation
First level escalation based on severity.
- P1: Immediate call to security leadership + CISO
- P2: Security team lead notification within 30 min
- P3: Security team notification within 2 hours
- P4: Ticket creation, normal queue
03
Executive Escalation
When to involve executive leadership.
- P1: CISO briefs CEO/COO within 1 hour
- P1: Board notification per policy
- P2: CISO briefed within 4 hours, C-suite if needed
- P3/P4: Include in regular security reporting
04
External Escalation
External parties to engage.
- Legal counsel for any potential breach
- Cyber insurance for significant incidents
- Law enforcement for criminal activity
- Forensic firm for major investigations
- Regulatory bodies per notification requirements
05
Communication Channels
How to escalate.
- P1: Direct phone call, out-of-band communication
- P2: Secure messaging + email
- P3: Email notification
- P4: Ticket system
Checklist
- Severity correctly classified
- Appropriate parties notified per severity
- Notification timelines met
- External parties engaged as needed
- Communication channels appropriate to severity
- Escalation documented
- Acknowledgment received
Evidence
- Escalation records
- Notification timestamps
- Acknowledgment records
- Contact records