The Art of CTO Incident Severity Classifier assigns a SEV1 to SEV4 level from nine inputs grouped as impact (users affected, functionality lost), business (revenue impact, reputation risk), technical (data loss, security breach, system down) and operational (workaround available, automated alerting). A security breach or data loss forces SEV1 regardless of user impact, and the result carries the reasoning that produced it.
How severe is this incident?
A consistent SEV level with the reasoning, ready for the postmortem.
About 3 min · Calculator · Free
About this toolWhy it matters, common mistakes, FAQ
How Bad Is This, Really?
Severity drives everything that follows — who gets woken, what gets communicated, whether the customer hears from you first. Getting it wrong in either direction is expensive.
Severity is negotiated per incident, which means it tracks who is in the channel rather than customer impact. Consistent criteria matter most at the boundary, where the incentive to under-call is strongest.
Questions CTOs ask
- How do you define incident severity levels?
- Most organizations use 4-5 severity levels: SEV1/Critical (complete outage or data breach affecting all users — all-hands response, executive notification), SEV2/Major (significant degradation affecting many users — dedicated response team, customer communication), SEV3/Minor (partial impact affecting a subset of users — normal response during business hours), SEV4/Low (minimal impact, cosmetic issues — addressed in normal workflow). Classification should be based on objective criteria: how many users are affected, how much functionality is lost, the revenue and reputation exposure, whether data was lost or security was breached, and whether a workaround exists. This tool asks those nine questions and short-circuits to SEV1 on data loss or a security breach, so the two cases most often under-called cannot be argued down in the channel.
- What is the difference between severity and priority?
- Severity measures the impact of an incident on users and business operations — it is an objective assessment of harm. Priority determines the order in which incidents are addressed — it incorporates business context like customer tier, contractual SLAs, and available resources. A SEV3 incident affecting your largest enterprise customer might be prioritized above a SEV2 incident affecting free-tier users. Separating these concepts prevents gaming (inflating severity to get faster response) and enables more nuanced resource allocation during concurrent incidents.
Related Reading
Incident Severity Classification Tool Guide: SEV Level Definitions That Don’t Collapse Under Pressure
Incident severity classification tool guide: SEV level definitions that don’t collapse under pressure
guidesOn-Call Rotation Planner Guide: How to Build a Fair, Sustainable Schedule
On-call rotation planner: how to build a fair, sustainable schedule
guidesArchitecture Calculator Guide: Capacity Planning and Infrastructure Sizing for Series A CTOs
Architecture Calculator Guide: system capacity planning calculator for infrastructure sizing