Ask a small team what "P3" means and you'll get five different answers. That's
the core failure of enterprise-grade severity matrices: they assume a 24/7 SOC
where a matrix is a routing table for on-call engineers. If you have ten people
and no security staff, a five-level matrix isn't precision — it's five chances
to argue instead of act.
Why 5 levels fail
Two reasons, both practical:
- Distinctions nobody can enforce. The difference between a P2 and a P3 on paper is usually response-time targets like "1 hour vs 4 hours". In a small team, nobody is timing it. When the targets aren't real, the levels aren't real, and the matrix becomes decoration.
- Triage debt. Under pressure, every extra level is a decision you have to make before you're allowed to act. Three levels get decided in seconds. Five get debated for twenty minutes while the incident runs.
Why 3 levels stick
Three maps to what a small team can actually do:
- SEV1 — stop everything. Something is actively spreading or customers are impacted. Cancel whatever you were doing; the whole team is on this.
- SEV2 — contain, then continue. A machine or account is compromised but it's not spreading. Isolate it, keep the business running, fix inside the day.
- SEV3 — schedule it. Something is wrong but not on fire. It gets a ticket and a date. No midnight wakes.
The only rule that matters: the level names the first move. One look, one
decision. If your matrix doesn't tell you what to do in the first ten minutes,
it isn't a matrix — it's a taxonomy.
What belongs next to it
A severity level without authority attached is just a label. Your matrix
should say, per level: who can declare it, who can pull machines off the
network, and who talks to customers. Small teams skip this because it feels
like overkill — until the day everyone waits for someone else to decide.
The full matrix in the Ops Starter Kit is three levels with escalation
authority, example triggers, and first moves pre-filled — plus the tabletop
exercises that let you find out where your own team disagrees before a real
incident does it for you.
This is general guidance, not legal or regulatory advice. Adapt every template
to your own environment.
Full templates in the Ops Starter Kit.
Free checklist + full templates
- The First 30 Minutes — free one-page quick-start checklist: https://hive80lab.gumroad.com/l/first-30-minutes
- Ops Starter Kit — Incident Response for Small Teams ($14): 3-level severity matrix with escalation authority, IR plan template, 5 tabletop exercises, comms templates, containment checklists → https://hive80lab.gumroad.com/l/ohrpxa
- Everything is also browsable/verifiable on GitHub (release with SHA256 checksums): https://github.com/Hive80-lab/hive80-toolkit
Launch coupon HIVE-LAUNCH30 takes 30% off the kit for the next 48 hours.
We're Hive80 Lab — a small ops lab shipping honest, no-fluff security templates for teams with no security staff. If your team runs a severity matrix, tell us how many levels it has and who is allowed to declare a SEV1 — comments are open.
Top comments (0)