How the SOC handles a case — and how fast you hear about it — depends on the severity, your escalation contacts, and the response authorizations you set. This guide covers all three.
Severity levels
| Severity | Meaning | Typical handling |
|---|---|---|
| Critical | Active compromise or imminent business impact | Immediate response + phone escalation |
| High | Confirmed malicious activity, contained scope | Rapid investigation + notification |
| Medium | Suspicious activity needing validation | Investigated in queue, summarized |
| Low / Info | Policy or hygiene findings | Logged, included in reporting |
Severity is set by the analyst during triage, not by the raw rule — the same detection can be Critical in one context and Low in another.
Escalation contacts
Set your contacts in Portal → SOC → Escalation. Provide an ordered list so the SOC knows who to reach and in what order, including an after-hours path.
Warning
Critical escalations use phone first. If your after-hours number is wrong or unmonitored, response slows down. Verify contacts quarterly.
Response authorizations
Decide, per action, whether the SOC may act autonomously or must get approval first. Configure these in Portal → SOC → Response policy.
- Isolate endpoint — cut a device off the network while preserving it for investigation.
- Disable identity — suspend a compromised account and revoke sessions.
- Block indicator — push a domain/IP/hash block to your controls.
Pre-authorizing containment for Critical cases is the single biggest lever on "time to contain." Many teams pre-authorize endpoint isolation and identity disable, and require approval for anything that could disrupt production.
Notification channels
Route case notifications to the channels your team already uses:
- Email and SMS to escalation contacts
- A shared inbox or ticketing system
- Chat (via webhooks into Slack or Teams)
- Your SIEM/SOAR via the Managed SOC API
Reviewing outcomes
Every closed case records what happened, what was done, and why — evidence, chain of custody, and the investigation timeline are held in multi-tenant SIEM case management rather than in an analyst's notes. Monthly reviews summarize trends, tuning changes, and recommendations. Request an ad-hoc incident report anytime from a case in the Portal.
