Laserfiche WebLink
<br /> 6 <br />Incident Classification for Critical Insight MDR <br /> <br />Incident <br />Severity <br /> <br />Description <br />Urgent <br />An urgent priority security incident is a network event or set of network events <br />that is believed to present a serious and immediate risk to the Customer’s <br />network environment. CI will contact the Customer (contact on file) via phone <br />and email to attempt resolution. Examples of urgent priority security incidents <br />include: <br />• Suspected account compromise with account misuse observed <br />• Customer security device has alerted CI to a likely compromise that has <br />been verified using other MDR data/tools with no evidence the security <br />device has mitigated the incident <br />• Suspected malware infection with evidence of immediate business impact <br />• Communications observed with a suspected malicious host with evidence of <br />data exfiltration or immediate business impact <br />• Regulated data seen unencrypted going to an external destination <br /> <br />High <br />A high priority security incident is a network event or set of network events that is <br />believed to present a risk to the Client’s network environment. CI will contact the <br />Customer (contact on file) via phone and email to attempt resolution. Examples <br />of high priority security incidents include: <br />• Suspected or potential account compromise with no misuse observed <br />• Suspected malware infection with evidence of malware spreading but no <br />evidence of immediate business impact <br />• Suspected or potential system compromise with no evidence of misuse <br />• Regulated data seen unencrypted between two internal hosts <br />Medium <br />A medium priority security incident is a network event or set of network events <br />that may be a risk to the Client’s network environment and may inform future <br />customer actions. CI will contact the Customer (contact on file) via email to <br />attempt resolution. Examples of medium priority security incidents include: <br />• Attempted account compromise with no evidence of success <br />• Suspected malware infection with no evidence of malware spread or <br />immediate business impact