JHarris Advisory | IR-01
Triage & Severity Calculator
No Triggers Checked
⚖️ Privilege Notice: This triage and severity determination may constitute attorney work product if prepared at the direction of legal counsel. Privilege designation should be assessed prior to sharing with external parties.
Incident Metadata
Severity Trigger Checklist
Check all that apply — severity auto-calculatesS1 — Critical (Immediate Escalation Required)
S2 — High (Escalate Within 1 Hour)
S3 — Moderate (Escalate Within 4 Hours)
S4 — Low (Document & Monitor)
Check triggers above to determine severity
Severity Level Reference
S1
Critical
⏱ Immediate — IC notified within 15 min
External legal within 1 hr
Exec brief within 2 hrs
External legal within 1 hr
Exec brief within 2 hrs
S2
High
⏱ Escalate within 1 hr
IR team convened within 2 hrs
Exec awareness within 4 hrs
IR team convened within 2 hrs
Exec awareness within 4 hrs
S3
Moderate
⏱ Escalate within 4 hrs
IR team notified same day
Management awareness same day
IR team notified same day
Management awareness same day
S4
Low
⏱ Document and monitor
Team lead notified within 24 hrs
No immediate escalation required
Team lead notified within 24 hrs
No immediate escalation required
Borderline Decision Guide
S1 vs. S2
PHI/PII confirmed affected → escalate to S1
Business-critical system fully down → S1
Regulatory notification likely required → S1
Unknown scope but high sensitivity → default S1; downgrade after assessment
S2 vs. S3
Partial system degradation (not full outage) → S2 if patient-facing, S3 if internal only
Suspected but unconfirmed unauthorized access → S2 pending investigation
No data exfiltration evidence, contained → S3
S3 vs. S4
Single user account compromise, no privilege escalation → S4
Phishing email opened but no credentials entered → S4
Multiple users or escalation risk → S3
Any data movement observed → minimum S3
General Rule: When in doubt, classify at the higher severity level. Downgrading is easier than managing an under-escalated incident. Severity can be revised at any point with documented rationale.
Escalation Contact Template
Complete the escalation notification details below for logging and handoff.
Cross-Module Triggers
Certain incident characteristics automatically require parallel activation of other IR modules.
| Trigger Condition | Severity Threshold | Module Activated | Active? |
|---|---|---|---|
| Third-party / vendor system involved | Any severity | IR-08: Third-Party IR Coordination | |
| PHI/PII confirmed or suspected | S1 / S2 | Breach Notification Decision Tree (IR-05) | |
| AI system involved (model, API, automated decision) | Any severity | AI IR Integration Review (IR-12) | |
| Clinical system impacted / patient safety concern | S1 | Clinical Continuity Protocol (IR-06) | |
| Regulatory notification required or likely | S1 / S2 | Notification & Comms Module (IR-05) | |
| Forensic evidence required | S1 / S2 | Evidence Preservation & Chain of Custody (IR-02, Phase 3) |
Build this into your incident response plan
This calculator tells you how severe an incident is. The Incident Readiness Toolkit gives you the runbook, tabletop exercises, breach notification templates, and board briefing — built before you need them.
Get the Incident Readiness Toolkit →