Kit · Incident
Triage & escalation kit
The decision gates that turn an alert queue into a procedure. Written so that the same alert gets the same treatment regardless of who is on shift and what time it is.
- Cadence
- Every shift
- Tiers
- L1 · L2 · L3
- Rule
- Escalate on trigger, not on feeling
Mandatory intake fields
Capture these at registration. Every one of them is expensive to reconstruct later and impossible to reconstruct honestly.
The triage decision sequence
- 1
Is this an obvious false positive?
Gate 1 · L1If yes: close it, and record whether the rule needs tuning. Closing without answering the tuning question is how the same alert costs you the same minutes next week. - 2
Does an existing playbook resolve this?
Gate 2 · L1If yes: execute it and record the outcome. If the playbook does not fit cleanly, that is an escalation and a playbook defect — record both. - 3
Does this meet an escalation trigger?
Gate 3 · L1 → L2Triggers are written conditions: no playbook exists, the playbook outcome is ambiguous, or the alert touches an asset flagged as critical. Not 'it feels significant'. - 4
Is this a genuine incident?
Gate 4 · L2Deeper assessment of context, threat vector and impact. Assign the incident group, the sub-group, and the statutory impact category. Complete within 24 hours of registration. - 5
Does this exceed L2 capability or authority?
Gate 5 · L2 → L3Scope crossing trust boundaries, adversary persistence or evasion, a need for forensic imaging or reverse engineering, or likely legal involvement. - 6
Is this notifiable?
Gate 6 · SOC OfficerApply the significant-incident test. When in doubt, start the clock — an early warning that turns out to be unnecessary costs far less than a missed deadline.
Escalation triggers, written
| From → to | Trigger | What must be recorded |
|---|---|---|
| L1 → L2 | No playbook covers the alert; the playbook result is ambiguous; the asset is flagged critical; the alert repeats across multiple hosts | Reason for escalation, time, and everything L1 already checked |
| L2 → L3 | Adversary persistence or evasion observed; scope crosses a trust boundary; forensic imaging or code analysis needed; legal or law-enforcement involvement likely | Scope established so far, evidence already collected, and the specific question L3 is being asked |
| L3 → SOC Officer | Business decision required; notification threshold approached; containment would materially disrupt operations | The decision being requested, the options, and the consequence of each |
| Any tier → immediate | Active data exfiltration, ransomware deployment in progress, or safety impact | Act first under the containment mandate, document immediately after |
The unrecorded close
An analyst who decides an alert is nothing and moves on has done reasonable work and left no evidence of it. Later you cannot show the alert was seen, and you cannot tell whether that rule fires three times a week or three hundred. Every triage decision produces a record — including ‘no action’.
Next kit
Regulatory notification kit
The significant-incident test in operational language, the 24h / 72h / one-month submission pack, and the notification clock.