Incident Severity
Pronunciation: IN-sih-dent suh-VAIR-ih-tee
Also known as: Incident priority level, Incident impact level
Definition
Incident severity is a graded assessment of the actual or potential harm caused by an incident, commonly considering service impact, affected users, data loss, financial exposure, safety, duration, and regulatory consequences. It differs from incident classification because severity determines urgency and response level, whereas classification describes the incident type. Operationally, teams should define measurable thresholds, include both current and potential impact, permit reassessment, and connect levels to escalation and communications.
Overview
Incident severity is a graded assessment of the actual or potential harm caused by an incident, commonly considering service impact, affected users, data loss, financial exposure, safety, duration, and regulatory consequences.
Incident Severity is closely connected to Incident Classification, Major ICT-Related Incident, and Risk Impact. It differs from incident classification because severity determines urgency and response level, whereas classification describes the incident type.
Operational implementation should define measurable thresholds, include both current and potential impact, permit reassessment, connect levels to escalation and communications, and avoid relying on a single technical indicator.
The principal failure modes include underestimating latent impact, inflating routine events, inconsistent executive escalation, ignoring customer harm, and leaving severity unchanged as evidence evolves.
Useful measures include severity distribution, time to assign, escalation compliance, severity changes, response time by level, and post-incident calibration findings.
Operationally, teams should define measurable thresholds, include both current and potential impact, permit reassessment, and connect levels to escalation and communications. Key risks include underestimating latent impact, inflating routine events, inconsistent executive escalation, and ignoring customer harm.
A production treatment of Incident Severity should test a graded assessment of the actual or potential harm caused by an incident, commonly considering service impact, affected users, data loss, financial exposure, safety, duration, and regulatory consequences within the relevant asset, decision, or service state. The Incident Severity context record for graded assessment of the actual, potential harm caused by an incident, and commonly considering service impact should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Incident Severity should determine whether safeguards addressing graded assessment of the actual, potential harm caused by an incident, and commonly considering service impact changed exposure in practice, not merely whether a document or setting existed.
Key Takeaway
Incident severity is a graded assessment of the actual or potential harm caused by an incident, commonly considering service impact, affected users, data loss, financial exposure, safety, duration, and regulatory consequences.
Sources
- Incident Response Recommendations and Considerations, NIST SP 800-61 Rev. 3 — NIST (2026-08-03)
- Commission Delegated Regulation (EU) 2024/1772 on ICT Incident Classification — European Union (2026-08-03)
- Guide for Conducting Risk Assessments, NIST SP 800-30 Rev. 1 — NIST (2026-08-03)