Incident Response

Incident Severity Levels Explained

How iCoreFusion classifies and responds to different threats.

P1 - Critical (active breach)

Confirmed or strongly suspected active breach, ransomware in progress, credential compromise of privileged accounts, or data exfiltration in progress. Response: call immediately on +44 7983 880089. Target response: 15 minutes.

P2 - High (credible threat)

Suspicious activity that has not yet confirmed as a breach but poses serious risk: unusual admin login patterns, large data movements, multiple failed MFA attempts on senior accounts. Response: email hello@icorefusion.com. Target response: 1 hour.

P3 - Medium (investigation needed)

Anomalous but non-urgent behaviour flagged by SIEM rules: policy violations, failed logins from unusual locations, suspicious email links clicked but no payload detected. Response: raised in your next scheduled review or sooner if requested.

P4 - Low (informational)

Non-urgent alerts and observations included in your monthly security report. No immediate action required.

Need more help? Contact Adam directly.

Use email for general support, or phone for active P1/P2 incidents.

Related articles