Declaration Threshold
Definition
The criteria defined in an organisation's IR plan that a suspected event must meet before it is formally declared a confirmed incident, assigned a case number, and escalated to the full IR team. Thresholds are typically expressed in terms of confirmed malicious activity, impact level, and data exposure.
- Location
- Defined in an organisation's incident response plan
- Trigger
- Suspected event meeting defined criteria
- Result of crossing
- Formal incident declaration, case number, escalation
- Criteria basis
- Confirmed malicious activity, impact level, data exposure
- Field
- Incident scoping and confirmation
Common questions
Why does an organisation need a formal declaration threshold instead of treating every alert as an incident?+
Security tools generate far more alerts than genuine incidents, so a formal threshold filters out noise and reserves the full incident response process, with its case number, escalation, and resourcing, for events that meet a defined bar of confirmed impact rather than every unconfirmed alert.
What is the risk of setting a declaration threshold too high?+
A threshold set too high delays formal escalation until an incident has already caused significant impact, losing the early containment window and potentially breaching regulatory notification deadlines that are measured from when the organisation reasonably should have known, not just from formal declaration.
Related terms
- Blast Radius
- The full set of systems, accounts, and data that an attacker has accessed or could access given their current level of compromise....
- Corroboration
- The practice of confirming an observed attacker action by finding evidence of the same action in at least two independent data sources,...
- Dwell Time
- The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
- Initial Indicator of Compromise (IoC)
- The first observable artefact or event that triggers the investigation: a hash match, a suspicious process, an anomalous login, or an alert...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...