Severity before the outage
If severity is decided in the war room, your playbook already failed the first decision.
- severity
- playbooks
Incident response audits for fintech systems fail most often at the first classification step. Teams invent severity after emotions rise instead of mapping customer impact, payment volume, and data exposure beforehand.
Write severity as observable conditions: failed settlement batch, exposed credentials with live tokens, fraud rate above a named threshold. Avoid adjectives like ‘major’ without numbers.
In Hong Kong desks we ask who can raise severity at 02:00 HKT without waiting for a daytime manager. If the answer is unclear, containment waits for daylight.
A short severity matrix shared with on-call and compliance beats a forty-page policy nobody opens during an event.