📊

Understanding Alert Severity Levels

A comprehensive guide to understanding and responding to security alerts based on their severity level.

Alert Severity Levels

Level Meaning Response Example
🔴 CRITICAL Active attack in progress Immediate Ransomware, C2, data breach
🟠 HIGH Suspicious activity detected Within 1 hour Brute force, privilege escalation
🟡 MEDIUM Unusual, not immediately threatening Within 4 hours New user, system warning
🔵 LOW Minor anomalies detected Within 24 hours Config changes, metrics

📋 Response Protocol

🔴 CRITICAL

  • Check alert immediately
  • Ask AI for analysis
  • Isolate if confirmed
  • Auto-block enabled

🟠 HIGH

  • Review within 1 hour
  • Investigate source IP
  • Ask AI for context
  • Block if malicious

🟡 MEDIUM

  • Review within 4 hours
  • Check if expected
  • Mark false positive if needed

🔵 LOW

  • Review during regular checks
  • Use for trend analysis
  • No immediate action needed