Severity Levels: Why 3 Levels Beat 5 for Small Teams
Ask a small team what "P3" means and you'll get five different answers. That's
the core failure of enterprise-grade severity matrices: they assume a 24/7 SOC
where a matrix is a routing table for on-call engineers. If you have ten people
and no security staff, a five-level matrix isn't precision — it's five chances
to argue instead of act.
Why 5 levels fail
Two reasons, both practical:
- Distinctions nobody can enforce. The difference between a P2 and a P3
on paper is usually response-time targets like "1 hour vs 4 hours". In a
small team, nobody is timing it. When the targets aren't real, the levels
aren't real, and the matrix becomes decoration.
- Triage debt. Under pressure, every extra level is a decision you have
to make before you're allowed to act. Three levels get decided in seconds.
Five get debated for twenty minutes while the incident runs.
Why 3 levels stick
Three maps to what a small team can actually do:
- SEV1 — stop everything. Something is actively spreading or customers are
impacted. Cancel whatever you were doing; the whole team is on this.
- SEV2 — contain, then continue. A machine or account is compromised but
it's not spreading. Isolate it, keep the business running, fix inside the day.
- SEV3 — schedule it. Something is wrong but not on fire. It gets a ticket
and a date. No midnight wakes.
The only rule that matters: the level names the first move. One look, one
decision. If your matrix doesn't tell you what to do in the first ten minutes,
it isn't a matrix — it's a taxonomy.
What belongs next to it
A severity level without authority attached is just a label. Your matrix
should say, per level: who can declare it, who can pull machines off the
network, and who talks to customers. Small teams skip this because it feels
like overkill — until the day everyone waits for someone else to decide.
---
The full matrix in the Ops Starter Kit is three levels with escalation
authority, example triggers, and first moves pre-filled — plus the tabletop
exercises that let you find out where your own team disagrees before a real
incident does it for you.
*This is general guidance, not legal or regulatory advice. Adapt every template
to your own environment.*