What it does. Build a structured SOC escalation matrix defining severity tiers, response Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-soc-escalation-matrix, or copy the skill folder into ~/.claude/skills/building-soc-escalation-matrix/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/building-soc-escalation-matrix/SKILL.md
SKILL.md (verbatim)
name: building-soc-escalation-matrix
description: Build a structured SOC escalation matrix defining severity tiers, response
SLAs, tiered escalation paths, and notification procedures for security incidents,
using context-driven criteria that combine business risk, asset criticality, and
data sensitivity. Use when designing or revising how a SOC triages and escalates
incidents across analyst tiers.
domain: cybersecurity
subdomain: soc-operations
tags:
- soc
- escalation
- incident-management
- severity
- sla
- triage
- tiered-soc
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- DE.AE-02
- RS.MA-01
- DE.AE-06
mitre_attack:
- T1078
- T1071
- T1041
Building SOC Escalation Matrix
Overview
A SOC escalation matrix defines how security incidents move through the organization based on severity, impact, and response requirements. Modern SOCs use context-driven escalation combining business risk, asset criticality, and data sensitivity rather than purely severity-based models. Organizations using AI and automation in their SOC cut detection-and-containment lifecycle to approximately 161 days, an 80-day improvement over the 241-day industry average.
When to Use
- When deploying or configuring building soc escalation matrix capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Familiarity with soc operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
SOC Tier Structure
Tier 1 - Alert Triage Analyst
- Monitors SIEM dashboards and alert queues
- Performs initial alert classification (true/false positive)
- Handles P3 and P4 incidents to resolution
- Escalates P1 and P2 incidents to Tier 2 within SLA
- Documents initial findings in ticketing system
Tier 2 - Incident Analyst
- Performs deep-dive investigation on escalated incidents
- Conducts root cause analysis and scoping
- Executes containment procedures
- Handles P2 incidents to resolution
- Escalates P1 incidents to Tier 3 or management
Tier 3 - Senior Analyst / Threat Hunter
- Handles P1 critical incidents and APT investigations
- Performs proactive threat hunting
- Develops detection rules and playbooks
- Conducts malware reverse engineering
- Leads incident response for major breaches
Management Escalation
- SOC Manager: Operational decisions, resource allocation
- CISO: Business impact decisions, executive communication
- Legal/PR: Data breach notification, media response
- External IR: Third-party incident response engagement
Severity Classification
P1 - Critical
| Attribute |
Value |
| Impact |
Active data breach, ransomware spreading, critical systems compromised |
| Business Impact |
Revenue loss, regulatory exposure, customer data at risk |
| Initial Response |
15 minutes |
| Escalation to Tier 2 |
Immediate |
| Escalation to Management |
30 minutes |
| Resolution Target |
4 hours |
| Communication |
Every 30 minutes to stakeholders |
| Examples |
Active ransomware, confirmed data exfiltration, domain admin compromise |
P2 - High
| Attribute |
Value |
| Impact |
Confirmed compromise, limited scope, no active exfiltration |
| Business Impact |
Potential revenue impact, contained risk |
| Initial Response |
30 minutes |
| Escalation to Tier 2 |
30 minutes if unresolved |
| Escalation to Management |
2 hours |
| Resolution Target |
8 hours |
| Communication |
Every 2 hours to SOC management |
| Examples |
Compromised user account, malware on single endpoint, insider threat indicator |
P3 - Medium
| Attribute |
Value |
| Impact |
Suspicious activity requiring investigation |
| Business Impact |
Low immediate risk |
| Initial Response |
4 hours |
| Escalation to Tier 2 |
8 hours if unresolved |
| Resolution Target |
24 hours |
| Communication |
Daily status update |
| Examples |
Policy violation, failed brute force, suspicious email report |
P4 - Low
| Attribute |
Value |
| Impact |
Informational alerts, routine security events |
| Business Impact |
Minimal |
| Initial Response |
8 hours |
| Escalation |
Only if pattern emerges |
| Resolution Target |
72 hours |
| Communication |
Weekly summary |
| Examples |
Vulnerability scan findings, expired certificates, policy exceptions |
Escalation Decision Matrix
Asset Criticality
Low Medium High Critical
Severity Low P4 P4 P3 P3
Medium P4 P3 P2 P2
High P3 P2 P2 P1
Critical P2 P1 P1 P1
Context-Driven Escalation Triggers
Automatic Escalation (no analyst decision needed)
| Trigger |
Action |
| Ransomware detected on any endpoint |
P1 - Immediate Tier 3 + Management |
| Domain admin account compromise |
P1 - Immediate Tier 3 + Management |
| Active data exfiltration to external IP |
P1 - Immediate Tier 3 + Management |
| Critical infrastructure (DC, SCADA) alert |
P1 - Immediate Tier 2 minimum |
| Executive account anomaly |
P2 - Immediate Tier 2 |
| Multiple hosts with same malware |
P1 - Immediate Tier 2 |
Time-Based Escalation
| Condition |
Action |
| P2 unresolved after 4 hours |
Escalate to Tier 3 |
| P3 unresolved after 12 hours |
Escalate to Tier 2 |
| Any incident unresolved past SLA |
Escalate to SOC Manager |
| P1 unresolved after 2 hours |
Escalate to CISO |
Communication Templates
P1 Initial Notification
SUBJECT: [P1 CRITICAL] Security Incident - {Incident_ID}
Incident Summary:
- Type: {incident_type}
- Affected Systems: {systems}
- Affected Users: {users}
- Current Status: {status}
- Assigned To: {analyst}
Impact Assessment:
- Business Impact: {impact}
- Data at Risk: {data_risk}
- Containment Status: {containment}
Next Actions:
- {action_1}
- {action_2}
Next Update: {time} (30-minute intervals)
Bridge Line: {conference_details}
Escalation Matrix Implementation
SOAR Integration
# XSOAR escalation playbook trigger
trigger:
condition: incident.severity == "critical" AND incident.asset_criticality == "high"
action:
- assign_tier: 3
- notify: [soc_manager, ciso]
- create_war_room: true
- start_bridge: true
- set_sla: 4h
auto_escalation_rules:
- name: P2 Time-Based Escalation
condition: incident.severity == "high" AND incident.age > 4h AND incident.status != "resolved"
action:
- escalate_tier: 3
- notify: soc_manager
- add_comment: "Auto-escalated due to SLA breach"
References
Other files in this skill
assets/template.md (verbatim)
SOC Escalation Matrix Template
Priority Definitions
| Priority |
Response SLA |
Resolution SLA |
Assigned Tier |
Mgmt Notification |
| P1 - Critical |
15 min |
4 hours |
Tier 3 |
30 min |
| P2 - High |
30 min |
8 hours |
Tier 2 |
2 hours |
| P3 - Medium |
4 hours |
24 hours |
Tier 1 |
As needed |
| P4 - Low |
8 hours |
72 hours |
Tier 1 |
Weekly |
| Role |
Name |
Phone |
Email |
Availability |
| Tier 1 Lead |
|
|
|
24/7 |
| Tier 2 Lead |
|
|
|
24/7 |
| Tier 3 Lead |
|
|
|
On-call |
| SOC Manager |
|
|
|
Business hours + on-call |
| CISO |
|
|
|
On-call for P1 |
Auto-Escalation Rules
| Trigger |
Priority |
Action |
| Ransomware detected |
P1 |
Tier 3 + CISO |
| Domain admin compromise |
P1 |
Tier 3 + CISO |
| Active data exfiltration |
P1 |
Tier 3 + CISO |
| Executive account anomaly |
P2 |
Tier 2 + SOC Manager |
| SLA breach |
+1 Tier |
Notify SOC Manager |
references/api-reference.md (verbatim)
API Reference: SOC Escalation Matrix
Priority Tiers
| Tier |
Response SLA |
Update SLA |
Resolution SLA |
| P1 Critical |
15 min |
1 hour |
4 hours |
| P2 High |
30 min |
2 hours |
8 hours |
| P3 Medium |
1 hour |
4 hours |
24 hours |
| P4 Low |
4 hours |
8 hours |
72 hours |
Alert Categories
| Category |
Default Priority |
Auto-Escalate Triggers |
| Malware |
P2 |
ransomware, wiper, apt |
| Phishing |
P3 |
executive_target, credential_harvested |
| Unauthorized Access |
P2 |
admin_account, domain_controller |
| Data Exfiltration |
P1 |
pii, financial, classified |
| Insider Threat |
P2 |
privileged_user, data_staging |
Escalation Chain
P1: SOC Analyst → SOC Lead → IR Manager → CISO
P2: SOC Analyst → SOC Lead → IR Manager
P3: SOC Analyst → SOC Lead
P4: SOC Analyst
Notification Channels
| Tier |
Channels |
| P1 |
Slack #critical-alerts, PagerDuty, Email CISO, SMS |
| P2 |
Slack #soc-alerts, PagerDuty, Email IR Manager |
| P3 |
Slack #soc-alerts, Email SOC Lead |
| P4 |
Slack #soc-triage |
POST https://events.pagerduty.com/v2/enqueue
{
"routing_key": "SERVICE_KEY",
"event_action": "trigger",
"payload": {
"summary": "P1 Alert: Data exfiltration detected",
"severity": "critical",
"source": "SOC SIEM"
}
}
Slack Webhook Notification
POST https://hooks.slack.com/services/T.../B.../xxx
{
"channel": "#critical-alerts",
"text": "P1 Incident: ..."
}
Auto-Escalation Rules
| Condition |
Action |
| Response SLA exceeded |
Escalate to next in chain |
| >= 3 correlated alerts |
Increase priority by 1 |
| VIP user affected |
Auto-escalate to P1 |
| Critical asset impacted |
Increase priority by 1 |
references/standards.md (verbatim)
Standards - SOC Escalation Matrix
NIST SP 800-61 Rev 2 Incident Handling
- Defines incident categories and severity levels
- Recommends functional impact, information impact, and recoverability as factors
- Guides escalation based on incident classification
ITIL Incident Management
- P1-P4 priority classification framework
- Impact x Urgency = Priority matrix
- SLA management for each priority level
SOC-CMM (SOC Capability Maturity Model)
- Level 1: Ad-hoc escalation, no formal process
- Level 2: Defined escalation paths, documented SLAs
- Level 3: Automated escalation with SOAR integration
- Level 4: Context-driven escalation with risk scoring
- Level 5: AI-assisted prioritization and auto-escalation
Response Time Standards
| Priority |
Industry Standard |
Best Practice |
| P1 |
15 min response, 4h resolution |
5 min response, 2h containment |
| P2 |
30 min response, 8h resolution |
15 min response, 4h containment |
| P3 |
4h response, 24h resolution |
2h response, 12h resolution |
| P4 |
8h response, 72h resolution |
4h response, 48h resolution |
references/workflows.md (verbatim)
Workflows - SOC Escalation Matrix
Escalation Flow
Alert Generated
|
v
Tier 1 Triage (15 min)
|
+-- P4/P3: Handle to resolution
|
+-- P2: Escalate to Tier 2
| |
| +-- Resolved: Close
| +-- Unresolved (4h): Escalate to Tier 3
|
+-- P1: Immediate escalation
|
v
Tier 3 + Management Notified
|
v
War Room / Bridge Activated
|
v
Containment within SLA
|
v
Resolution + Post-Incident Review
Notification Matrix
| Priority |
Tier 1 |
Tier 2 |
Tier 3 |
SOC Mgr |
CISO |
Legal |
| P1 |
Aware |
Aware |
Lead |
Notified |
Notified |
Standby |
| P2 |
Aware |
Lead |
Consulted |
Informed |
- |
- |
| P3 |
Lead |
Consulted |
- |
- |
- |
- |
| P4 |
Lead |
- |
- |
- |
- |
- |
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.