Incident Triage & Severity Calculator | JHarris Advisory
Incident Response · Live Triage Tool
Incident Triage & Severity Calculator
Something just happened. How bad is it, and who needs to know in the next hour?
Free, no emailUnder 2 minutes4 severity tiersNothing leaves your browser
No Triggers Checked
If you are in an active incident, use this tool and stop there. Your severity, escalation clock, and notification timelines are below and require no email, no signup, and nothing sent anywhere. The optional after-action report at the bottom is for later, when the incident is stable.
Nothing you type here is transmitted. The incident details, names, and notes below stay in your browser and are never sent to JHarris Advisory or anyone else. Closing the tab clears them. Print or save the page to keep a record.
Privilege note: A triage and severity determination may be protected as attorney work product if it is prepared at the direction of counsel. That protection is not automatic and it does not attach simply because you used this tool. If privilege matters for this incident, decide the designation with counsel before circulating this document. JHarris Advisory LLC provides consulting services, not legal services, and is not your counsel.

Incident Details

Optional · stays local

Severity Trigger Checklist

Check all that apply. Severity is the highest tier with any box checked.

S1 — Critical (immediate escalation)

S2 — High (escalate within 1 hour)

S3 — Moderate (escalate within 4 hours)

S4 — Low (document and monitor)

Check triggers above to determine severity
Select every trigger that applies. The result is free and appears immediately.

Severity Level Reference

S1
Critical
Incident commander within 15 min
Counsel within 1 hr
Executive brief within 2 hrs
S2
High
Escalate within 1 hr
Response team within 2 hrs
Executive awareness within 4 hrs
S3
Moderate
Escalate within 4 hrs
Response team same day
Management awareness same day
S4
Low
Document and monitor
Team lead within 24 hrs
No immediate escalation

Borderline Decision Guide

S1 or S2
Personal data or PHI confirmed affected: S1
Business-critical system fully down: S1
Regulatory notification likely required: S1
Scope unknown but data is highly sensitive: default S1, downgrade after assessment
S2 or S3
Partial degradation, not full outage: S2 if customer or patient facing, S3 if internal only
Unauthorized access suspected but unconfirmed: S2 pending investigation
Contained, no exfiltration evidence: S3
S3 or S4
Single account compromised, no privilege escalation: S4
Phishing email opened, no credentials entered: S4
Multiple users or escalation risk: S3
Any data movement observed: S3 minimum
When in doubt, classify high. Downgrading later with documented rationale is routine. Explaining why an incident sat at S3 for two days while data left the building is not. Severity can be revised at any point; record the reason and the time when you change it.

Escalation Log

Stays local · print to keep

Record who was notified and when. Timing is the first thing anyone reviewing this incident will ask about.

What Else This Incident Triggers

Some incident characteristics start a second workstream that runs in parallel with containment. If any of these apply, someone needs to own it now, not after the technical response wraps up.

If this is trueAtStart this in parallelOwned?
A vendor or third-party system is involvedAny severityVendor coordination: contract review for notification duties, evidence requests, and who controls communications
Personal data or PHI is confirmed or suspectedS1 / S2Breach determination analysis and the notification clock. See the timeline box above
An AI system, model, or automated decision is involvedAny severityAI failure review: what decisions were affected, who was affected, and whether outputs need to be reversed
A clinical system is impacted or patient safety is in questionS1Clinical continuity: downtime procedures, and the safety reporting path separate from the security path
Regulatory notification is required or likelyS1 / S2Notification and communications: draft holding statements before you need them
Forensic evidence may be neededS1 / S2Evidence preservation and chain of custody. Stop overwriting logs now; this is the one that becomes irreversible fastest

Post-incident readiness report

Everything above is yours already. This is the part for after the incident is stable: what this incident just revealed about your program, and the 30 days that follow.

  • A 30-day after-action plan sequenced from this incident's severity
  • The program gaps this specific incident exposed, matched to what you checked
  • Notification and documentation obligations you may still be carrying
  • Questions to answer before the next incident, not during it
  • Printable report for your incident file
Mid-incident? Skip this entirely. Nothing behind it helps you in the next hour, and you can come back later. If you need help right now, call rather than filling out a form.
Only your name and email are sent. Your incident details, notes, and the names in the escalation log stay in your browser and are never transmitted. JHarris Advisory LLC provides consulting services, not legal services. It is not a law firm, and submitting this form does not create an attorney-client relationship.
Have the plan before the incident

This calculator tells you how bad it is. The Incident Readiness Toolkit gives you the runbook, tabletop exercises, breach notification templates, and the board briefing, built while nothing is on fire.

Educational triage tool, not legal advice and not a substitute for counsel or a qualified incident responder. JHarris Advisory LLC provides consulting services, not legal services; it is not a law firm, and no attorney-client relationship is created by using this tool. Severity tiers are a general framework and do not override your organization's own incident classification policy or contractual notification obligations. Regulatory timelines cited are current as of August 2026; confirm them against your specific facts with counsel.
© JHarris Advisory LLC.