WHEN A BUSINESS SECURITY INCIDENT SHOULD BE ESCALATED
Not every security event requires the same response. Organizations should establish clear escalation criteria before an incident occurs.
1. ESCALATE WHEN IMPACT IS HIGH
Consider prompt escalation when an incident involves:
- Financial loss or an attempted fraudulent payment
- Administrator or privileged accounts
- Sensitive customer or employee information
- Multiple compromised accounts or devices
- Malware or ransomware
- Significant business disruption
- A lost device with high-impact access
2. ESCALATE WHEN THE SITUATION IS UNCLEAR
Uncertainty itself can be a reason to involve someone with greater responsibility or expertise.
Employees should not feel required to solve serious security problems alone.
3. KNOW INTERNAL CONTACTS
Identify who handles security incidents, finance emergencies, technology problems and management decisions.
4. KNOW WHEN TO INVOLVE EXTERNAL HELP
Depending on the incident, appropriate assistance may include a bank or payment provider, technology provider, cybersecurity professional, legal adviser, regulator or law-enforcement authority.
The appropriate contact depends on the circumstances and applicable requirements.
5. BUSINESS EXAMPLE
An employee believes a business email account has been compromised and that the attacker may have accessed customer records.
The incident should not remain only with the employee. It should be escalated through the organization's security and management process so the scope and obligations can be assessed.
6. PRACTICAL CHECK
- Internal escalation contacts identified
- Financial escalation route known
- Technical escalation route known
- Management escalation route known
- External assistance options identified
- Employees know they can report uncertainty
WHY THIS MATTERS
Clear escalation prevents serious incidents from becoming isolated problems handled by people who may not have the authority or expertise to respond.
VERIFY BEFORE YOU TRUST.
Verify who is authorized to make high-impact incident decisions and use the organization's established escalation path.
