The reference desk / In practice

Triage

A short, time-boxed judgment of severity, uncertainty, and next action when an alert arrives.

What it means

Triage is the first structured assessment of a reported security problem. It aims to choose the next useful action, not finish every part of the investigation. Consider the credibility of the signal, the affected asset, possible business impact, urgency, and what remains unknown. A time limit helps prevent one ambiguous case from consuming the queue, but high-consequence evidence may demand immediate escalation. Record the reason for the decision so another analyst can continue without reconstructing your thinking from scattered messages.

AN ILLUSTRATIVE SCENARIO

Two alerts arrive during a busy support shift

A retailer receives one alert about an old scanning attempt and another about a newly created administrator exporting customer records. The analyst checks enough source evidence to understand each, then prioritizes the account activity because of its potential impact and current behavior. The first alert remains tracked rather than silently forgotten. For the second, the analyst records missing application details and contacts the person authorized to approve containment.

Put it to work

  1. Confirm the source and basic facts: affected identity or system, time window, relevant behavior, and whether the signal still reflects a current situation.
  2. Estimate potential impact and uncertainty, then choose an action such as investigate, escalate, monitor, or close with evidence. Use established authority for any disruptive containment.
  3. Write a concise handoff with facts, unanswered questions, actions already taken, and the next owner. Set a follow-up time for deferred cases rather than leaving them indefinitely idle.

How to check your work

Review a sample triage decision with a colleague. They should understand why the case received its priority, which evidence supports it, and what happens next. Compare decisions across analysts to uncover unclear criteria.

Connect the ideas

  • Alert

    A notification that a rule or model wants a human to look at one or more records.

  • Incident

    An event or set of events that actually or potentially causes a security loss requiring coordinated handling.

  • Impact

    How badly people or the business are hurt if the loss actually happens.

  • Uncertainty

    What you still do not know, written explicitly so it is not filled with false precision.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.