Glossary

Incident severity

Incident severity is a classification of the business, technical, legal, and customer impact of a security incident.

June 11, 2026Updated June 2026
Incident responseTriage

Incident severity helps a team decide how quickly to respond, who should be involved, and which communications or legal steps may be required.

Severity should consider:

  • Business impact
  • Affected systems
  • Data exposure
  • Customer impact
  • Attacker activity
  • Legal or regulatory obligations

The initial severity can change as the facts improve. The important point is that the team uses a consistent decision path.

Related page: IncidentAI.