Building SOC Escalation Matrix

SkillSecurity

This is a skill that guides an AI agent through building a SOC escalation matrix for security incidents. It defines P1-P4 severity tiers with response SLAs, tiered analyst roles, and escalation triggers, using a decision matrix that combines incident severity with asset criticality, business risk, and data sensitivity.

Use Building SOC Escalation Matrix in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Building SOC Escalation Matrix and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Building SOC Escalation Matrix skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have familiarity with SOC operations concepts and tools.

Building SOC Escalation MatrixStart free

What your AI can do with it

  • Define P1-P4 severity tiers with response SLAs for security incidents
  • Structure tiered analyst roles from alert triage through senior threat hunting
  • Set automatic and time-based escalation triggers between tiers
  • Build a decision matrix combining incident severity with asset criticality
  • Incorporate business risk and data sensitivity into escalation criteria
  • Provide communication templates for incident notifications

Getting started

  1. Have familiarity with SOC operations concepts and tools.
  2. Prepare a test or lab environment for safe execution.
  3. Install Python 3.8 or later with the required dependencies.
  4. Ensure appropriate authorization for any testing activities.
  5. Add the skill to your agent and ask it to draft or revise an escalation matrix for your SOC.

What this skill tells your AI

The instructions your AI receives, as published by mukul975/anthropic-cybersecurity-skills in skills/building-soc-escalation-matrix/SKILL.md and read by ahel’s review.

Overview

A SOC escalation matrix defines how security incidents move through the organization based on severity, impact, and response requirements. Modern SOCs use context-driven escalation combining business risk, asset criticality, and data sensitivity rather than purely severity-based models. Organizations using AI and automation in their SOC cut detection-and-containment lifecycle to approximately 161 days, an 80-day improvement over the 241-day industry average.

When to Use

  • When deploying or configuring building soc escalation matrix capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with soc operations concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

SOC Tier Structure

Tier 1 - Alert Triage Analyst

  • Monitors SIEM dashboards and alert queues
  • Performs initial alert classification (true/false positive)
  • Handles P3 and P4 incidents to resolution
  • Escalates P1 and P2 incidents to Tier 2 within SLA
  • Documents initial findings in ticketing system

Tier 2 - Incident Analyst

  • Performs deep-dive investigation on escalated incidents
  • Conducts root cause analysis and scoping
  • Executes containment procedures
  • Handles P2 incidents to resolution
  • Escalates P1 incidents to Tier 3 or management

Tier 3 - Senior Analyst / Threat Hunter

  • Handles P1 critical incidents and APT investigations
  • Performs proactive threat hunting
  • Develops detection rules and playbooks
  • Conducts malware reverse engineering
  • Leads incident response for major breaches

Management Escalation

  • SOC Manager: Operational decisions, resource allocation
  • CISO: Business impact decisions, executive communication
  • Legal/PR: Data breach notification, media response
  • External IR: Third-party incident response engagement

Severity Classification

P1 - Critical

AttributeValue
ImpactActive data breach, ransomware spreading, critical systems compromised
Business ImpactRevenue loss, regulatory exposure, customer data at risk
Initial Response15 minutes
Escalation to Tier 2Immediate
Escalation to Management30 minutes
Resolution Target4 hours
CommunicationEvery 30 minutes to stakeholders
ExamplesActive ransomware, confirmed data exfiltration, domain admin compromise

P2 - High

AttributeValue
ImpactConfirmed compromise, limited scope, no active exfiltration
Business ImpactPotential revenue impact, contained risk
Initial Response30 minutes
Escalation to Tier 230 minutes if unresolved
Escalation to Management2 hours
Resolution Target8 hours
CommunicationEvery 2 hours to SOC management
ExamplesCompromised user account, malware on single endpoint, insider threat indicator

P3 - Medium

AttributeValue
ImpactSuspicious activity requiring investigation
Business ImpactLow immediate risk
Initial Response4 hours
Escalation to Tier 28 hours if unresolved
Resolution Target24 hours
CommunicationDaily status update
ExamplesPolicy violation, failed brute force, suspicious email report

P4 - Low

AttributeValue
ImpactInformational alerts, routine security events
Business ImpactMinimal
Initial Response8 hours
EscalationOnly if pattern emerges
Resolution Target72 hours
CommunicationWeekly summary
ExamplesVulnerability scan findings, expired certificates, policy exceptions

Escalation Decision Matrix

                    Asset Criticality
                    Low        Medium      High        Critical
Severity  Low      P4         P4          P3          P3
          Medium   P4         P3          P2          P2
          High     P3         P2          P2          P1
          Critical P2         P1          P1          P1

Context-Driven Escalation Triggers

Automatic Escalation (no analyst decision needed)

TriggerAction
Ransomware detected on any endpointP1 - Immediate Tier 3 + Management
Domain admin account compromiseP1 - Immediate Tier 3 + Management
Active data exfiltration to external IPP1 - Immediate Tier 3 + Management
Critical infrastructure (DC, SCADA) alertP1 - Immediate Tier 2 minimum
Executive account anomalyP2 - Immediate Tier 2
Multiple hosts with same malwareP1 - Immediate Tier 2

Time-Based Escalation

ConditionAction
P2 unresolved after 4 hoursEscalate to Tier 3
P3 unresolved after 12 hoursEscalate to Tier 2
Any incident unresolved past SLAEscalate to SOC Manager
P1 unresolved after 2 hoursEscalate to CISO

Communication Templates

P1 Initial Notification

SUBJECT: [P1 CRITICAL] Security Incident - {Incident_ID}

Incident Summary:
- Type: {incident_type}
- Affected Systems: {systems}
- Affected Users: {users}
- Current Status: {status}
- Assigned To: {analyst}

Impact Assessment:
- Business Impact: {impact}
- Data at Risk: {data_risk}
- Containment Status: {containment}

Next Actions:
- {action_1}
- {action_2}

Next Update: {time} (30-minute intervals)
Bridge Line: {conference_details}

Escalation Matrix Implementation

SOAR Integration

# XSOAR escalation playbook trigger
trigger:
  condition: incident.severity == "critical" AND incident.asset_criticality == "high"
  action:
    - assign_tier: 3
    - notify: [soc_manager, ciso]
    - create_war_room: true
    - start_bridge: true
    - set_sla: 4h

auto_escalation_rules:
  - name: P2 Time-Based Escalation
    condition: incident.severity == "high" AND incident.age > 4h AND incident.status != "resolved"
    action:
      - escalate_tier: 3
      - notify: soc_manager
      - add_comment: "Auto-escalated due to SLA breach"

References

Signals

GitHub stars
34k
Forks
4k
Last commit
Aug 2026

Questions

What severity tiers does it define?
It defines four tiers: P1 (critical, e.g. active data breach or ransomware spreading), P2, P3, and P4, each with response SLAs and handling rules.
How does escalation work between analyst tiers?
Tier 1 triages alerts and handles P3/P4 incidents, escalating P1/P2 to Tier 2 within SLA. Tier 2 investigates and contains P2 incidents, escalating P1 to Tier 3 or management.
What criteria does it use beyond severity?
It uses a context-driven decision matrix combining incident severity with asset criticality, plus business risk and data sensitivity.
Advanced
Item type
skill
Key
building-soc-escalation-matrix-mukul975
Source
github.com/mukul975/anthropic-cybersecurity-skills