All Playbooks

Incident Severity Scoring

8-dimension weighted assessment based on CISA NCISS methodology

8
Dimensions
0-100
Score Range
4
Severity Levels
How to use: Score each dimension based on observed incident characteristics. The composite severity rating updates automatically. Use the materiality flags to signal governance escalation needs. Export the assessment for your incident record.
All calculations run in your browser. No data is transmitted anywhere.
Operational Continuity
20%
Impact on ability to deliver core business services and maintain operations.
Data Exposure
16%
Extent and sensitivity of data potentially accessed, exfiltrated, or compromised.
Threat Activity
12%
Nature and intensity of observed threat actor behavior within the environment.
Asset Criticality
12%
Business criticality of affected systems, assets, and infrastructure (Tier 0/1/2).
Threat Sophistication
10%
Complexity and capability of the threat actor based on TTPs and tooling observed.
Recovery Complexity
10%
Estimated effort and time to restore affected systems to full operational status.
Attack Progression
10%
Stage of the attack in the kill chain and whether it has been contained.
Control Effectiveness
10%
How well existing security controls detected, prevented, and mitigated the incident.

Materiality Indicators

These flags do not affect the severity score. They signal whether governance, legal, or regulatory escalation may be needed — a parallel track to technical response.

Severity Level Reference

Score Severity Response Posture Escalation
70-100 Critical All IR roles activated, immediate CISO notification Executive Liaison assesses sub-crisis activation
45-69 High IR Lead + Handlers, specialized roles on demand Executive Liaison notified for possible escalation
20-44 Medium IR Lead coordinates, consultation for complexity Operational management consultation preferred
0-19 Low Handler manages independently None unless complexity increases
Composite Severity Rating
--
Not Assessed
0255075100
Operational Continuity--
Data Exposure--
Threat Activity--
Asset Criticality--
Threat Sophistication--
Recovery Complexity--
Attack Progression--
Control Effectiveness--