Skip to content

Kit · Incident

Triage & escalation kit

The decision gates that turn an alert queue into a procedure. Written so that the same alert gets the same treatment regardless of who is on shift and what time it is.

Cadence
Every shift
Tiers
L1 · L2 · L3
Rule
Escalate on trigger, not on feeling
All kits

Mandatory intake fields

Capture these at registration. Every one of them is expensive to reconstruct later and impossible to reconstruct honestly.

Per event
0/9

The triage decision sequence

  1. 1

    Is this an obvious false positive?

    Gate 1 · L1
    If yes: close it, and record whether the rule needs tuning. Closing without answering the tuning question is how the same alert costs you the same minutes next week.
  2. 2

    Does an existing playbook resolve this?

    Gate 2 · L1
    If yes: execute it and record the outcome. If the playbook does not fit cleanly, that is an escalation and a playbook defect — record both.
  3. 3

    Does this meet an escalation trigger?

    Gate 3 · L1 → L2
    Triggers are written conditions: no playbook exists, the playbook outcome is ambiguous, or the alert touches an asset flagged as critical. Not 'it feels significant'.
  4. 4

    Is this a genuine incident?

    Gate 4 · L2
    Deeper assessment of context, threat vector and impact. Assign the incident group, the sub-group, and the statutory impact category. Complete within 24 hours of registration.
  5. 5

    Does this exceed L2 capability or authority?

    Gate 5 · L2 → L3
    Scope crossing trust boundaries, adversary persistence or evasion, a need for forensic imaging or reverse engineering, or likely legal involvement.
  6. 6

    Is this notifiable?

    Gate 6 · SOC Officer
    Apply the significant-incident test. When in doubt, start the clock — an early warning that turns out to be unnecessary costs far less than a missed deadline.

Escalation triggers, written

From → toTriggerWhat must be recorded
L1 → L2No playbook covers the alert; the playbook result is ambiguous; the asset is flagged critical; the alert repeats across multiple hostsReason for escalation, time, and everything L1 already checked
L2 → L3Adversary persistence or evasion observed; scope crosses a trust boundary; forensic imaging or code analysis needed; legal or law-enforcement involvement likelyScope established so far, evidence already collected, and the specific question L3 is being asked
L3 → SOC OfficerBusiness decision required; notification threshold approached; containment would materially disrupt operationsThe decision being requested, the options, and the consequence of each
Any tier → immediateActive data exfiltration, ransomware deployment in progress, or safety impactAct first under the containment mandate, document immediately after

The unrecorded close

An analyst who decides an alert is nothing and moves on has done reasonable work and left no evidence of it. Later you cannot show the alert was seen, and you cannot tell whether that rule fires three times a week or three hundred. Every triage decision produces a record — including ‘no action’.

Next kit

Regulatory notification kit

The significant-incident test in operational language, the 24h / 72h / one-month submission pack, and the notification clock.

Open Regulatory notification kit