How should continuing harm and urgency be assessed?¶
Base urgency on what is happening now, what could get worse, and what evidence is at risk — not simply on the colour or severity label attached to an alert.
A dramatic alert may describe a blocked attempt. A modest-looking event may sit inside a serious ongoing compromise.
Identify the harm that is still live¶
Ask whether there is continuing:
- unauthorised access;
- data copying or publication;
- financial loss;
- victim contact or impersonation;
- service disruption;
- safety impact;
- malicious infrastructure still in use; or
- evidence about to expire or be overwritten.
Record which of those are confirmed and which are still suspected.
Separate impact from escalation risk¶
An incident can be serious because of what has already happened.
It can also be urgent because of what may happen next.
For example:
That gives decision-makers something much more useful than “severity: critical”.
Balance containment and evidence loss¶
Shutdown may reduce harm but destroy volatile evidence.
Waiting may preserve visibility but allow more damage.
So the decision should consider:
- current harm;
- likely escalation;
- evidence at risk;
- business/safety impact;
- specialist advice;
- what containment will change.
There is no universal answer. The value is in making the trade-off deliberately.
Record the decision while it is being made¶
Capture:
- what was known;
- what was uncertain;
- options considered;
- advice received;
- authority;
- action chosen;
- expected evidential effect.
That makes later review fairer because it preserves the decision context rather than judging it using information learned afterwards.
The practical point is: urgency comes from continuing harm, escalation and evidence loss together. Record the facts that drove the decision, not just the alert severity.