Initial Response
Incident Classification Matrix
Decision tree and matrix to help responders classify incidents and determine appropriate escalation paths.
Initial Response · beginner · 10-15 min
Framework for classifying security incidents by type and severity to guide response priorities.
Steps
4
01
Determine Incident Category
Classify the type of security incident.
- Malware: Virus, ransomware, trojan, worm detected
- Phishing: Fraudulent email attempting credential theft or malware delivery
- Account Compromise: Unauthorized access to user or service account
- Data Breach: Confirmed or suspected unauthorized data access
- Denial of Service: Service availability impacted by attack
- Insider Threat: Malicious or negligent insider activity
- Vulnerability Exploitation: Active exploitation of system vulnerability
02
Assess Severity Level
Determine the severity based on impact and scope.
- Critical (P1): Active data breach, ransomware, executive compromise
- High (P2): Contained malware, single account compromise, active attack
- Medium (P3): Blocked phishing, policy violation, suspicious activity
- Low (P4): Security alerts requiring investigation, failed attacks
03
Identify Data Sensitivity
Consider the sensitivity of potentially affected data.
- Regulated Data: PII, PHI, PCI, GDPR-covered data
- Confidential: Trade secrets, financial data, strategic plans
- Internal: Business operations data, employee information
- Public: Already publicly available information
04
Determine Escalation Path
Based on classification, determine who to involve.
- P1: CISO, Legal, Executive team, potential law enforcement
- P2: Security team lead, IT management, affected department heads
- P3: Security analyst, IT operations, affected system owner
- P4: Security team member for investigation
Checklist
- Incident category identified
- Severity level assigned
- Data sensitivity assessed
- Escalation path determined
- Initial responders assigned
- Communication channels established
Evidence
- Classification documentation
- Escalation notification records
- Initial incident details