strike48 / security bulletins

Priority & escalation

Every bulletin carries a priority and an exposure level. This page is what they mean. Both come from the Strike48 Incident Response Plan, so the label on a bulletin is a classification against a published standard rather than an adjective.

They answer different questions and are set independently. Priority drives how we respond; exposure describes what was actually reached; residual risk, shown on each bulletin, is what remains for a customer after containment.

Classification

Every record is first classified by what it is. The distinction drives the level of response and the reporting obligations, and it can change after review — an event that turns out to threaten data becomes an incident; one that discloses personal or sensitive information becomes a breach.

Event An observable, significant occurrence in a system or network that may result in a change to normal behaviour — a suspicious login, a malware alert. All incidents are events; many events are not incidents.
Incident An adverse event that threatens the confidentiality, integrity, or availability of data or systems: a policy violation, unauthorized access, loss of confidentiality or availability, denial of service, or misuse of a service or system.
Breach Unauthorized access to, or disclosure of, personal or sensitive information.

Two things, set separately

Priority · P1–P4

How urgently do we respond?

Set at triage from service impact and confirmed exposure. It determines who is Incident Commander, when the CISO and Legal are pulled in, and how often leadership is updated. It is about our response, not the customer's risk.

Exposure

What was actually reached?

The sensitivity and volume of data that was accessed or could have been. A P1 can carry limited exposure and a P2 can carry confirmed exposure — the two do not move together.

Residual risk

What does this mean for you now?

A customer's remaining exposure after containment and the controls that held. Shown with its reasoning on each bulletin, and what decides whether the required customer action is “none” or something specific.

Priority matrix

P1

Service disruption, confirmed data exposure, or multiple customers impacted.

Incident Commander

Incident Commander + CISO engaged immediately

Executive cadence

Executive update every 4 hours or on material change

P2

Elevated threat with limited exposure, affecting a single customer or internal assets.

Incident Commander

SOC Lead acts as Incident Commander

Executive cadence

Executive update daily

P3

A contained or low-impact event.

Incident Commander

SecOps acts as Incident Commander

Executive cadence

Executive update weekly or on request

P4

False positive or negligible impact.

Incident Commander

Closed by the SOC

Executive cadence

Final summary only

Legal is notified for P1 through P3. The Incident Commander for every priority is recorded on the bulletin, and status transitions are logged in its revision history.

Exposure scale

Assigned at triage and revised as the investigation establishes what was reached. The distinction between possible and confirmed is load-bearing: we do not record exposure as confirmed-absent when it was merely not yet investigated, and we do not record it as confirmed-present without evidence.

No exposure No data was accessed or viewed.
Possible exposure Access could have occurred; unconfirmed.
Limited exposure A small amount of low- or moderate-sensitivity data was accessed.
Confirmed exposure A meaningful amount of sensitive or confidential data was accessed.
High-volume / high-sensitivity A large dataset or highly sensitive data was breached.
Severe exposure Restricted or regulated data was exposed; legal or regulatory impact likely.

Compensating controls

Residual risk is usually lower than the priority alone would suggest, because something limited the damage. Each bulletin lists those controls and marks each one held, partial, or failed.

Failures are listed alongside the ones that held, on purpose. A list of only the controls that worked is marketing; the failures are where the remediation comes from.

Reporting clocks

Regulatory clocks begin on confirmation of data exposure, not at closure.

GDPR / CCPA
72-hour reporting where personal data was exposed.
DORA
4-hour notification for a major ICT incident.
Contractual SLAs
Customer-specific timelines, which often run shorter than the statutory ones.
NIST / ATO
System-owner notification per the terms of the authorization.