MSP IT Services • Irvine • Orange County

Incident Response & Digital Forensics for Orange County Businesses

When a cybersecurity incident, ransomware alert, suspicious login, email compromise, firewall warning, or cloud security threat appears, your systems should alarm, notify the right IT administrators and managers, preserve evidence, and support a fast, organized response.

25+ YearsIT, security, cloud, network and audit experience
AI-AwareEDR, MDR, XDR, SIEM, SOAR and analytics guidance
Local FocusIrvine and Orange County business support
CertifiedCISSP, CCISO, MCSE, MCITP, CCNP experience
Security Event Detected
Endpoint Alert
Suspicious process behavior isolated for investigation.
Microsoft 365 Alert
Risky sign-in, mailbox rule, and audit log review initiated.
Network Alert
Firewall, VPN, and outbound traffic indicators correlated.
Incident management dashboard for cyber incident response and risk assessment
Detect • Report • Assess • Respond • Resolve
Customer-Focused Incident Response

Cyber incidents require speed, evidence, and experienced decision-making.

A security incident may begin with a phishing message, compromised Microsoft 365 account, unusual VPN login, malicious endpoint process, suspicious firewall event, cloud alert, or backup anomaly. OC Security Audit helps businesses organize the response, review the evidence, and reduce the chance of repeated disruption.

Our work supports organizations that need practical SMB IT security services, enterprise business network security, and network security in Orange County without overwhelming internal teams.

AI-Powered Detection & Automated Response

Systems should alarm, notify, correlate, and escalate when threats appear.

Modern MSP IT services and internal IT teams need security technologies that can identify abnormal behavior, prioritize alerts, notify managers, and help administrators respond before the incident grows.

EDR, MDR & XDR

Endpoint, managed, and extended detection technologies help identify malware, ransomware, suspicious scripts, lateral movement, and active compromise.

🧠

Machine Learning Analytics

AI-assisted analytics can reduce noise, detect abnormal patterns, and help prioritize alerts across endpoints, cloud systems, identity, and network devices.

🛡️

Firewalls & Network Devices

Firewall, router, switch, VPN, DNS, and network monitoring logs help reveal blocked traffic, suspicious access, and possible data movement.

☁️

Microsoft 365 & Azure

Cloud alerts can reveal risky sign-ins, unauthorized inbox rules, privileged changes, suspicious OAuth consent, and abnormal cloud resource access.

🔁

Backups & Disaster Recovery

Backup platforms should be reviewed for failed jobs, deletion attempts, encryption activity, retention changes, and clean restore points.

🔗

SIEM, Logging & SOAR

Centralized logging and automation help open tickets, notify teams, disable risky access, isolate systems, and document response activities.

Digital Forensic Investigation

What should happen after an incident is reported?

After a reported incident, the priority is not only cleanup. The organization must preserve useful evidence, identify affected accounts and systems, contain active risk, investigate the root cause, and document what must change. OC Security Audit helps review logs, alerts, systems, and security controls so business leaders and IT teams can make informed decisions.

Confirm the incident and business impact

Review the first alert, affected users, critical systems, current availability, and whether the threat is still active.

Preserve evidence before destructive changes

Collect firewall logs, VPN records, endpoint telemetry, Microsoft 365 audit logs, Azure sign-in logs, email headers, backup logs, and administrator activity records.

Contain the threat carefully

Disable compromised accounts, revoke sessions, isolate endpoints, remove malicious forwarding rules, block suspicious traffic, and protect backup systems.

Investigate root cause and scope

Determine whether the incident involved phishing, stolen credentials, malware, exposed remote access, misconfiguration, privilege misuse, or cloud account compromise.

Recover, validate, and improve

Restore clean services, validate security controls, monitor for repeat activity, and document a prioritized remediation plan.

Network & Cloud Categories

Organized investigation across the systems that run your business.

A strong incident response review categorizes the environment so no major evidence source is missed. This is especially important for MSP-supported businesses, healthcare offices, professional services, manufacturers, financial offices, and growing companies in Irvine and Orange County.

Perimeter & Network

Cloud & Identity

Endpoint & Email

  • Servers, laptops, workstations, EDR and antivirus
  • Email security, message trace and mailbox rules
  • Account Control Audit

Recovery & Compliance

  • Backups, disaster recovery, logs and reporting
  • HIPAA, PCI-DSS, SOC 2, NIST, ISO and CMMC readiness
  • Compliance Consulting
AI threat detection illustration for incident response and cyber attack investigation
AI-assisted alert correlation across endpoints, networks, cloud and email
Services OC Security Audit Provides

Incident response support with audit, compliance, cloud, and MSP IT service experience.

Incident Response Planning

Create practical response procedures, escalation paths, evidence checklists, and notification workflows for IT teams and leadership.

Forensic Investigation Review

Review logs, alerts, accounts, systems, cloud activity, endpoint indicators, and timelines to understand what happened.

Logging & Monitoring Strategy

Improve SIEM readiness, alert routing, log retention, firewall monitoring, Microsoft 365 logging, Azure visibility, and administrator reporting.

Cloud Security Review

Review Microsoft 365, Office 365, Azure, identity, conditional access, privileged access, and cloud audit logs.

Firewall & Network Review

Analyze firewall rules, VPN access, network segmentation, router and switch configuration, and suspicious traffic indicators.

Post-Incident Remediation

Document findings, improve controls, harden systems, validate backups, strengthen account security, and prioritize risk reduction.

Built for Irvine and Orange County organizations that need practical help now.

OC Security Audit supports businesses that rely on stable IT operations, secure email, protected cloud accounts, reliable backups, and clear executive guidance.

CISSPCCISOMCSEMCITPCCNP25+ Years
Local Orange County Service Area

MSP IT services, incident response, and digital forensics support near Irvine, California.

OC Security Audit provides incident response guidance, forensic investigation review, security audits, Microsoft 365 and Azure security support, firewall review, and monitoring advisory services for businesses throughout Orange County.

IrvineNewport BeachCosta MesaTustinSanta AnaOrangeAnaheimFullertonHuntington BeachFountain ValleyLake ForestMission ViejoLaguna HillsLaguna NiguelAliso ViejoDana PointSan ClementeYorba LindaBreaGarden GroveWestminsterCypressBuena ParkPlacentia
Cyber security incident response and disaster recovery services in Irvine Orange County
Start the Conversation

Need incident response guidance for a cyber alert, email compromise, cloud warning, or suspicious network activity?

OC Security Audit helps organizations evaluate what happened, what evidence should be reviewed, what systems may be affected, and what steps are needed to contain, investigate, recover, and improve security.

Incident ResponseDigital ForensicsMicrosoft 365AzureFirewall LogsBackupsMSP IT Services
Incident Response Planning Cheat Sheet

A Practical Incident Checklist for IT Managers, Network Engineers, and Project Teams

Use this interactive incident response cheat sheet to quickly identify common IT and cybersecurity incidents, assign the right technician, preserve the right evidence, contain the issue, validate recovery, and document prevention improvements after the incident is closed.

What this cheat sheet helps your IT team do

This guide turns incident response planning into an operational worksheet. It helps administrators and managers move from “something is wrong” to a structured response: triage, assign, preserve evidence, contain risk, recover service, and improve controls.

  • Clarify first-response actions for security, cloud, endpoint, network, backup, and outage events.
  • Guide technician assignment for Microsoft 365, Azure, firewall, server, endpoint, and network teams.
  • Protect forensic value by identifying logs and evidence to preserve before cleanup.
  • Improve future readiness with lessons learned and prevention guidance for every incident.

Cheat sheet snapshot

100Incident scenarios
9Operational categories
54P1 immediate items
33P2 urgent items
Showing 100 incidents
Scroll horizontally to review the full incident response workflow. Header row and first columns remain visible while reviewing long procedures.
IDIncident NameCategorySubcategorySeverityPriorityImpacted AreaTypical Trigger / AlertTechnician AssignedInitial 5-10 ActionsEvidence / Logs to PreserveContainment StepsRecovery / ValidationEscalate / NotifyWhat We LearnedHow to Prevent RecurrenceTarget Response SLAService Reference URLStatus
1Phishing email reported by userEmail & PhishingPhishingHighP2 – UrgentMicrosoft 365 / EmailUser reports suspicious email or security gateway alertMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Users need a simple reporting path and rapid triage.Implement phishing reporting, user awareness, DMARC/DKIM/SPF, stronger email filtering.30 minutesRelated serviceNew
2Business email compromise suspectedEmail & PhishingBECCriticalP1 – ImmediateExecutive mailbox / FinanceUnusual invoice request, forwarding rule, or suspicious sent itemsMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Payment workflows and mailbox controls need stronger verification.Use MFA, conditional access, payment verification procedures, mailbox rule monitoring.15 minutesRelated serviceNew
3Malicious attachment deliveredEmail & PhishingMalware emailHighP1 – ImmediateEmail / EndpointsAttachment sandbox alert or user opened fileSOC Analyst1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Attachment detonation and endpoint correlation are critical.Block risky file types, sandbox attachments, improve EDR response and user training.15 minutesRelated serviceNew
4Malicious link clickedEmail & PhishingCredential phishingHighP1 – ImmediateEmail / IdentityURL click alert, suspicious login after clickSOC Analyst1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.URL protection must be paired with identity review.Enable safe links, MFA, conditional access, risky sign-in monitoring.15 minutesRelated serviceNew
5External email forwarding detectedEmail & PhishingMailbox ruleHighP1 – ImmediateMicrosoft 365 mailboxNew forwarding rule or external forwarding alertMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Attackers often use forwarding rules for persistence.Disable external forwarding by default, alert on new rules, review mailbox delegates.30 minutesRelated serviceNew
6Suspicious inbox rule createdEmail & PhishingMailbox ruleHighP2 – UrgentMicrosoft 365 mailboxRule hides security emails or moves invoicesMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Mailbox rules can hide evidence of compromise.Alert on hidden/delete rules, audit mailbox changes, enable MFA.30 minutesRelated serviceNew
7Mass spam sent from internal accountEmail & PhishingOutbound spamHighP1 – ImmediateEmail reputation / User accountOutbound spam alert or bounce stormMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Compromised accounts can damage domain reputation quickly.Implement outbound spam alerts, MFA, password reset automation, conditional access.15 minutesRelated serviceNew
8Domain spoofing detectedEmail & PhishingSpoofingMediumP3 – NormalEmail domainCustomers report spoofed messagesMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Brand/domain protection requires DNS and monitoring.Enforce DMARC, DKIM, SPF, monitor spoofing, publish reporting policy.4 hoursRelated serviceNew
9Email quarantine release mistakeEmail & PhishingEmail operationsMediumP3 – NormalEmail security gatewayMalicious mail released from quarantineSOC Analyst1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Quarantine release requires approval workflow.Restrict quarantine release, require security review for high-risk messages.4 hoursRelated serviceNew
10Shared mailbox compromiseEmail & PhishingShared mailboxHighP1 – ImmediateShared mailboxUnusual access or mailbox activityMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Shared accounts/mailboxes need ownership and access review.Audit delegates, enforce MFA on users, remove stale access, monitor shared mailbox rules.30 minutesRelated serviceNew
11OAuth consent phishingEmail & PhishingOAuth appCriticalP1 – ImmediateMicrosoft 365 / Cloud appsSuspicious app consent or abnormal graph accessCloud/IAM Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.OAuth permissions can bypass password resets.Restrict user consent, review app permissions, require admin approval, monitor consent grants.15 minutesRelated serviceNew
12CEO impersonation attemptEmail & PhishingSocial engineeringMediumP2 – UrgentEmail / FinanceExecutive impersonation email reportedMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Business process controls reduce financial fraud risk.Use warning banners, domain impersonation protection, finance approval workflow.1 hourRelated serviceNew
13Data exfiltration through emailEmail & PhishingData lossCriticalP1 – ImmediateEmail / Sensitive dataLarge outbound attachment or DLP alertCompliance/Privacy Lead1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Sensitive data movement must be monitored and classified.Implement DLP, encryption, least privilege, outbound monitoring, approved sharing.15 minutesRelated serviceNew
14Email outageEmail & PhishingService outageHighP1 – ImmediateEmail serviceUsers cannot send/receive mailMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Service dependencies and communication channels must be documented.Monitor service health, maintain alternate communications, test mail flow.15 minutesRelated serviceNew
15Mail flow connector failureEmail & PhishingMail routingHighP2 – UrgentEmail security gatewayDelayed/bounced email or connector alertMicrosoft 365 Admin1 Preserve email and headers; 2 search tenant for similar messages; 3 block sender/domain/URL; 4 remove malicious mail; 5 reset affected passwords; 6 revoke sessions; 7 check mailbox rules; 8 alert users; 9 improve filters; 10 document indicators.Message trace, email headers, mailbox audit logs, anti-phishing alerts, URLs/attachments, sender details.Quarantine messages, block sender/domain/URL, disable forwarding, revoke sessions, reset credentials.Confirm malicious messages removed, mailbox rules clean, passwords/MFA verified, no suspicious sends.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Mail routing changes require change control and monitoring.Document connectors, monitor queues, create rollback plan, test changes.30 minutesRelated serviceNew
16Password revealed or posted onlineIdentity & AccessCredential exposureCriticalP1 – ImmediateUser account / IdentityDark web, paste, or user reportCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Credential exposure can quickly lead to lateral movement.Use MFA, passwordless, breach monitoring, password reset procedures.15 minutesRelated serviceNew
17Impossible travel sign-inIdentity & AccessRisky sign-inHighP1 – ImmediateMicrosoft Entra IDSign-in from unusual locationCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Location anomalies require rapid session review.Conditional access, MFA, geo-risk policies, impossible travel alerting.15 minutesRelated serviceNew
18MFA fatigue attackIdentity & AccessMFA abuseHighP1 – ImmediateUser identityRepeated MFA prompts or denied approvalsCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Push MFA can be abused without number matching.Enable number matching, phishing-resistant MFA, user reporting.15 minutesRelated serviceNew
19Administrator account compromiseIdentity & AccessPrivileged accessCriticalP1 – ImmediateAdmin identityAdmin sign-in anomaly or unauthorized changesIncident Commander1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Privileged accounts require extra controls and monitoring.Use PIM, dedicated admin accounts, conditional access, hardware MFA.ImmediateRelated serviceNew
20Unauthorized privilege escalationIdentity & AccessPrivilege changeCriticalP1 – ImmediateActive Directory / Entra IDGroup membership or role assignment alertCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Privilege changes must be logged and approved.Alert on role/group changes, enforce least privilege, quarterly access reviews.15 minutesRelated serviceNew
21Service account abuseIdentity & AccessService accountHighP2 – UrgentServers / ApplicationsAbnormal login from service accountServer/Systems Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Service accounts need ownership and restrictions.Use managed identities, rotate secrets, limit interactive login, monitor usage.30 minutesRelated serviceNew
22Account lockout stormIdentity & AccessAuthentication issueMediumP3 – NormalActive DirectoryMany repeated account lockoutsServer/Systems Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Lockouts may indicate attack or broken configuration.Identify source, tune lockout policy, monitor brute force, update stored credentials.2 hoursRelated serviceNew
23Disabled employee account still activeIdentity & AccessJoiner/mover/leaverHighP2 – UrgentIdentity / HR processFormer employee account sign-in or access foundCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Offboarding gaps create avoidable risk.Automate offboarding, disable accounts, revoke sessions, remove group membership.1 hourRelated serviceNew
24Suspicious VPN loginIdentity & AccessRemote accessHighP1 – ImmediateVPN / IdentityVPN login from unexpected country/timeNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Remote access must be treated as high-risk.Enforce MFA, geo-blocking, device compliance, VPN log monitoring.15 minutesRelated serviceNew
25Password spray attackIdentity & AccessCredential attackHighP1 – ImmediateIdentity platformMany failed sign-ins across usersCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Attackers test common passwords at scale.MFA, smart lockout, conditional access, passwordless rollout, alert tuning.15 minutesRelated serviceNew
26Conditional access policy disabledIdentity & AccessSecurity policyCriticalP1 – ImmediateMicrosoft Entra IDPolicy change or gap detectedCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Policy changes need approval and alerting.Require change control, alert on policy changes, export policy backups.15 minutesRelated serviceNew
27Break-glass account usedIdentity & AccessEmergency accessCriticalP1 – ImmediateIdentity platformEmergency account sign-in alertIncident Commander1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Emergency accounts must be monitored and rare.Monitor break-glass use, store credentials securely, enforce post-use review.ImmediateRelated serviceNew
28Ransomware encryption detectedEndpoint & MalwareRansomwareCriticalP1 – ImmediateWorkstations / ServersEDR ransomware behavior or file encryption alertSecurity Engineer1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Fast isolation and backup validation reduce damage.EDR isolation, immutable backups, least privilege, application control, user training.ImmediateRelated serviceNew
29Virus/malware infectionEndpoint & MalwareMalwareHighP1 – ImmediateEndpointAntivirus/EDR malware alertEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Malware events need scope review beyond one device.Keep EDR/AV updated, patch endpoints, restrict local admin rights.15 minutesRelated serviceNew
30Trojan detectedEndpoint & MalwareMalwareHighP1 – ImmediateEndpointTrojan detection or command-and-control beaconSOC Analyst1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Trojan infections may indicate credential theft.EDR, DNS filtering, least privilege, credential rotation after infection.15 minutesRelated serviceNew
31Suspicious PowerShell activityEndpoint & MalwareScript abuseHighP1 – ImmediateEndpoint / ServerEDR detects encoded command or suspicious scriptSecurity Engineer1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Administrative tools can be used maliciously.Constrained language mode, script logging, PowerShell hardening, EDR rules.15 minutesRelated serviceNew
32Unapproved remote access toolEndpoint & MalwareRemote accessHighP1 – ImmediateEndpointAnyDesk/TeamViewer/RMM detected unexpectedlyEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Unauthorized remote tools create persistence.Application control, approved software list, EDR alerting, vendor allowlist.30 minutesRelated serviceNew
33Laptop stolenEndpoint & MalwareLost deviceHighP2 – UrgentLaptop / DataUser reports lost or stolen deviceEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Device encryption and remote wipe readiness are essential.Full disk encryption, MDM, remote wipe, asset inventory, user reporting process.1 hourRelated serviceNew
34USB malware riskEndpoint & MalwareRemovable mediaMediumP3 – NormalEndpointUSB insertion and malware alertEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Removable media controls reduce infection paths.Disable autorun, restrict USB, scan removable media, user training.2 hoursRelated serviceNew
35Endpoint EDR agent offlineEndpoint & MalwareMonitoring gapMediumP3 – NormalEndpoint securityEDR console shows offline agentEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Unmonitored endpoints create blind spots.Automated health checks, enforce agent install, alert on offline endpoints.4 hoursRelated serviceNew
36Unauthorized software installedEndpoint & MalwarePolicy violationMediumP3 – NormalEndpointSoftware inventory or EDR alertEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Software sprawl increases attack surface.Application allowlisting, least privilege, asset inventory, software approval.4 hoursRelated serviceNew
37Local admin misuseEndpoint & MalwarePrivilege misuseHighP2 – UrgentEndpointLocal admin action or unexpected tool installEndpoint/Desktop Support1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Local admin rights are high-risk.Remove local admin, use PAM/LAPS, monitor privileged actions.1 hourRelated serviceNew
38Suspicious browser extensionEndpoint & MalwareBrowser threatMediumP3 – NormalEndpoint / BrowserExtension requests excessive permissionsEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Browser extensions can exfiltrate data.Managed browser policies, extension allowlist, user training.4 hoursRelated serviceNew
39Endpoint disk full outageEndpoint & MalwareEndpoint outageLowP4 – ScheduledEndpointUser cannot work due to disk spaceEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Capacity monitoring avoids avoidable outages.Disk health monitoring, cleanup policies, OneDrive controls.1 business dayRelated serviceNew
40Lost mobile device with company emailEndpoint & MalwareMobile deviceHighP2 – UrgentMobile / EmailUser reports phone lostMicrosoft 365 Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Mobile access needs MDM and wipe controls.MDM enrollment, PIN/encryption, remote wipe, conditional access.1 hourRelated serviceNew
41Fileless malware behaviorEndpoint & MalwareAdvanced malwareCriticalP1 – ImmediateEndpointMemory/process anomaly without file artifactSecurity Engineer1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Advanced attacks require EDR telemetry and skilled review.Behavioral EDR, script controls, threat hunting, memory collection process.ImmediateRelated serviceNew
42Endpoint patch failure on critical CVEEndpoint & MalwarePatch managementHighP2 – UrgentEndpoint fleetPatch compliance report shows missed critical patchEndpoint/Desktop Support1 Isolate endpoint; 2 preserve EDR alert and hostname; 3 collect user/process details; 4 scan for malware; 5 check lateral movement; 6 validate backups; 7 clean or rebuild; 8 patch; 9 monitor; 10 update controls.EDR timeline, antivirus alerts, process tree, file hashes, user logon events, disk/memory notes if needed.Network-isolate endpoint, stop malicious process, quarantine malware, block IOC, remove persistence.Reimage or clean endpoint, patch, restore files, validate EDR health, run full scan and user testing.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Patch failures need exception tracking.Patch management, maintenance windows, reboot enforcement, vulnerability scans.4 hoursRelated serviceNew
43DDoS attackNetwork & PerimeterDDoSCriticalP1 – ImmediateInternet edgeTraffic spike, service unavailable, ISP alertNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.DDoS response depends on upstream coordination.DDoS protection, ISP escalation contacts, traffic baselines, WAF/CDN.ImmediateRelated serviceNew
44Internet downNetwork & PerimeterConnectivity outageHighP1 – ImmediateInternet WANUsers report no internet or monitoring alertVendor/ISP Coordinator1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Redundancy and ISP escalation reduce downtime.Dual ISP, SD-WAN/failover, monitoring, documented ISP contacts.15 minutesRelated serviceNew
45VPN downNetwork & PerimeterRemote access outageHighP1 – ImmediateVPN / FirewallRemote users cannot connectNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Remote access availability affects business continuity.HA VPN, capacity monitoring, certificate tracking, tested failover.15 minutesRelated serviceNew
46Firewall blocked critical applicationNetwork & PerimeterFirewall policyMediumP2 – UrgentFirewall / ApplicationApplication fails after firewall rule changeNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Firewall changes need testing and rollback.Change control, rule documentation, pre/post testing, application owner approval.1 hourRelated serviceNew
47Firewall compromise suspectedNetwork & PerimeterFirewall securityCriticalP1 – ImmediateFirewallUnauthorized config change or admin loginSecurity Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Security devices are high-value targets.Admin MFA, restricted management, config backups, firmware updates, alerting.ImmediateRelated serviceNew
48Router failureNetwork & PerimeterNetwork outageHighP1 – ImmediateWAN/LAN routingMonitoring alert or routing lossNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Routing devices need redundancy and config backups.HA routers, tested config backups, monitoring, spare hardware.15 minutesRelated serviceNew
49Core switch failureNetwork & PerimeterNetwork outageCriticalP1 – ImmediateLAN coreMultiple VLANs/services offlineNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Core network devices are critical infrastructure.Redundant core, UPS, config backups, lifecycle management.ImmediateRelated serviceNew
50Rogue DHCP serverNetwork & PerimeterNetwork misconfigurationHighP2 – UrgentLANUsers receive wrong gateway/DNSNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Rogue services can disrupt or intercept traffic.DHCP snooping, network access control, switch port security.30 minutesRelated serviceNew
51DNS outageNetwork & PerimeterName resolutionHighP1 – ImmediateDNS / AD / InternetUsers cannot resolve namesServer/Systems Admin1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.DNS is a dependency for nearly everything.Redundant DNS, monitoring, conditional forwarder documentation, change control.15 minutesRelated serviceNew
52Network loop / broadcast stormNetwork & PerimeterLAN outageHighP1 – ImmediateSwitchingHigh broadcast traffic, slow LANNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Layer 2 controls prevent widespread disruption.STP, loop guard, BPDU guard, port documentation, monitoring.15 minutesRelated serviceNew
53IDS/IPS detects exploit attemptNetwork & PerimeterIntrusion attemptHighP2 – UrgentFirewall / ServersIPS alert against public serviceSOC Analyst1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Internet-facing services need active monitoring.Patch exposed services, WAF/IPS, vulnerability scanning, minimize exposure.30 minutesRelated serviceNew
54Wireless network compromise suspectedNetwork & PerimeterWi-Fi securityHighP2 – UrgentWireless LANUnknown AP/client or unusual trafficNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Wireless access must be segmented and monitored.WPA3/enterprise auth, rogue AP detection, guest segmentation.1 hourRelated serviceNew
55Unauthorized device on networkNetwork & PerimeterRogue deviceMediumP2 – UrgentLANUnknown MAC/device detectedNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Asset visibility is foundational.NAC, device inventory, switch port authentication, segmentation.1 hourRelated serviceNew
56ISP packet loss / degraded serviceNetwork & PerimeterPerformance outageMediumP2 – UrgentInternet WANPacket loss/latency monitoring alertVendor/ISP Coordinator1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Performance issues require objective monitoring data.WAN monitoring, SLA tracking, secondary circuit, SD-WAN.1 hourRelated serviceNew
57Firewall license expiredNetwork & PerimeterSecurity service gapHighP2 – UrgentFirewall servicesThreat protection/license alertNetwork Engineer1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Licenses are operational controls.License lifecycle tracking, renewal reminders, vendor management.4 hoursRelated serviceNew
58Azure VM compromise suspectedCloud & Microsoft 365Cloud workloadCriticalP1 – ImmediateAzure VMSecurity alert or abnormal outbound trafficCloud/IAM Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Cloud workloads need logging and segmentation.Defender for Cloud, NSG hardening, patching, just-in-time access.ImmediateRelated serviceNew
59Azure storage public exposureCloud & Microsoft 365Cloud storageCriticalP1 – ImmediateAzure StoragePublic access detected or data exposure alertCloud/IAM Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Cloud storage defaults and permissions must be controlled.Disable public access, private endpoints, storage firewall, access review.15 minutesRelated serviceNew
60Suspicious Azure resource creationCloud & Microsoft 365Cloud abuseHighP1 – ImmediateAzure subscriptionUnexpected VM/resource or cost spikeCloud/IAM Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Compromised accounts may create cloud resources.Budget alerts, role review, PIM, policy restrictions, activity log alerting.15 minutesRelated serviceNew
61Microsoft 365 tenant admin changeCloud & Microsoft 365Tenant securityCriticalP1 – ImmediateM365 admin centerUnauthorized admin role or tenant setting changeMicrosoft 365 Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Tenant-wide changes can create lasting exposure.Admin role alerting, PIM, change control, audit log retention.ImmediateRelated serviceNew
62SharePoint external sharing exposureCloud & Microsoft 365Cloud data sharingHighP2 – UrgentSharePoint/OneDriveSensitive file shared externallyCompliance/Privacy Lead1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Collaboration tools need data governance.DLP, sensitivity labels, external sharing controls, access reviews.1 hourRelated serviceNew
63OneDrive mass file deletionCloud & Microsoft 365Cloud data lossHighP1 – ImmediateOneDriveMass delete alert or user reports missing filesMicrosoft 365 Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Cloud recycle/recovery windows must be understood.Retention policies, alert on mass deletion, user training, backup for M365.15 minutesRelated serviceNew
64Suspicious Teams guest accessCloud & Microsoft 365Collaboration riskMediumP3 – NormalMicrosoft TeamsUnknown external guest addedMicrosoft 365 Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Guest access needs ownership and expiration.Guest access review, sensitivity labels, team lifecycle policies.4 hoursRelated serviceNew
65Azure conditional access misconfigurationCloud & Microsoft 365Access controlHighP2 – UrgentMicrosoft Entra IDUnexpected access allowed or blockedCloud/IAM Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Access policies need testing and emergency access planning.Policy templates, test groups, change control, report-only testing.1 hourRelated serviceNew
66Cloud backup job failureCloud & Microsoft 365Cloud backupHighP2 – UrgentCloud backupBackup alert for failed jobBackup/DR Admin1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Backup failures are incident indicators.Monitor backup jobs, test restores, alert on failure, capacity planning.2 hoursRelated serviceNew
67Suspicious OAuth application in AzureCloud & Microsoft 365Application permissionCriticalP1 – ImmediateEntra ID appsHigh-privilege app consent detectedCloud/IAM Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Application permissions can be equivalent to account compromise.Admin consent workflow, app permission review, disable user consent.15 minutesRelated serviceNew
68Cloud security alert ignoredCloud & Microsoft 365Monitoring gapMediumP3 – NormalCloud security toolsAged unresolved cloud alertSOC Analyst1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Alert fatigue can hide real incidents.Alert tuning, ownership, triage SLAs, dashboard reporting.4 hoursRelated serviceNew
69M365 service health outageCloud & Microsoft 365Cloud service outageHighP2 – UrgentMicrosoft 365Microsoft service health alert or user reports outageMicrosoft 365 Admin1 Review Azure/M365 alerts; 2 identify affected identities/resources; 3 revoke sessions; 4 lock down access; 5 export audit/sign-in logs; 6 inspect permissions/apps; 7 remediate config; 8 validate service; 9 monitor; 10 document.Azure activity logs, Entra ID sign-in/audit logs, M365 audit logs, resource changes, app consent records.Disable risky identity/app, revoke consent/session, restrict public access, lock down permissions.Validate access policies, resource integrity, audit trail, app permissions, and ongoing cloud alerts.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Cloud outages need communication playbooks.Monitor service health, status templates, alternate communication plans.30 minutesRelated serviceNew
70Server outageServer & InfrastructureServer availabilityHighP1 – ImmediateServer / ApplicationMonitoring alert or user reports outageServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Server health monitoring and dependencies matter.Redundancy, monitoring, patching, capacity planning, runbooks.15 minutesRelated serviceNew
71Domain controller outageServer & InfrastructureIdentity infrastructureCriticalP1 – ImmediateActive DirectoryAuthentication failures or DC down alertServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Identity services require redundancy.Multiple DCs, DNS health checks, backups, replication monitoring.ImmediateRelated serviceNew
72File server unavailableServer & InfrastructureFile servicesHighP1 – ImmediateFile serverUsers cannot access sharesServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.File services need backup and access monitoring.Cluster/replication, backup testing, storage monitoring, permissions review.15 minutesRelated serviceNew
73Database server performance incidentServer & InfrastructureDatabaseHighP2 – UrgentDatabase serverHigh CPU/locks/slowness alertsServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Performance incidents require baselines.Capacity monitoring, query optimization, maintenance plans, backup validation.1 hourRelated serviceNew
74Certificate expiredServer & InfrastructureCertificate managementHighP2 – UrgentWeb/VPN/Email serviceCertificate warning or service failureServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Certificate lifecycle tracking is essential.Certificate inventory, renewal alerts, automation, owner assignment.1 hourRelated serviceNew
75Critical disk failureServer & InfrastructureStorageHighP1 – ImmediateServer / StorageRAID/disk alertServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Hardware events need proactive replacement.RAID monitoring, spare disks, lifecycle management, tested backups.30 minutesRelated serviceNew
76Server patch causes outageServer & InfrastructureChange incidentHighP2 – UrgentServer / ApplicationOutage after patch/rebootServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Patching needs testing and rollback planning.Maintenance windows, snapshots/backups, test environment, change approvals.1 hourRelated serviceNew
77Unauthorized server loginServer & InfrastructureSecurity eventCriticalP1 – ImmediateServerUnexpected admin login or RDP/SSH activitySecurity Engineer1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Server access must be tightly controlled.MFA/PAM, restricted RDP/SSH, jump boxes, log monitoring.ImmediateRelated serviceNew
78Application service crashServer & InfrastructureApplication outageMediumP2 – UrgentApplication serverService stopped alertServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Application dependencies need monitoring.Service monitors, auto-restart rules, capacity baselines, vendor support.1 hourRelated serviceNew
79Time synchronization failureServer & InfrastructureInfrastructure dependencyMediumP3 – NormalAD / Servers / LogsKerberos/log timestamp issuesServer/Systems Admin1 Confirm outage or compromise; 2 preserve system/event logs; 3 check resource health; 4 isolate if malicious; 5 validate dependencies; 6 restore service; 7 patch or rebuild; 8 verify apps; 9 monitor; 10 document.Windows/Linux event logs, application logs, performance counters, uptime monitors, change records.Isolate server if compromised, stop affected service, block access path, snapshot/preserve before rebuild.Restore services, verify application health, patch, validate authentication, monitor CPU/disk/network.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Time drift breaks auth and forensics.Reliable NTP, domain time hierarchy, monitoring, documentation.4 hoursRelated serviceNew
80Backup repository encrypted by ransomwareBackup & Disaster RecoveryBackup compromiseCriticalP1 – ImmediateBackup platformBackup files encrypted or repository inaccessibleBackup/DR Admin1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Backups must be isolated from production credentials.Immutable/offline backups, separate admin accounts, repository MFA, segmentation.ImmediateRelated serviceNew
81Backup job failed for critical serverBackup & Disaster RecoveryBackup failureHighP2 – UrgentBackup systemFailed backup alertBackup/DR Admin1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Backup monitoring must be actionable.Daily backup review, alert escalation, capacity checks, test restores.2 hoursRelated serviceNew
82Restore test failsBackup & Disaster RecoveryRecovery failureHighP2 – UrgentBackup/DRRestore validation failsBackup/DR Admin1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Backups are only useful if restorable.Scheduled restore testing, documented RTO/RPO, vendor review.4 hoursRelated serviceNew
83Retention policy changed unexpectedlyBackup & Disaster RecoveryBackup policyHighP1 – ImmediateBackup platformRetention reduced or changedBackup/DR Admin1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Attackers may reduce retention before ransomware.Alert on retention changes, role separation, approval workflow.30 minutesRelated serviceNew
84Immutable backup not enabledBackup & Disaster RecoveryBackup gapMediumP3 – NormalBackup platformAudit finds no immutable copyBackup/DR Admin1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Immutability is key against ransomware.Enable immutability, 3-2-1 strategy, offsite/offline copy.1 business dayRelated serviceNew
85Backup storage fullBackup & Disaster RecoveryCapacityMediumP3 – NormalBackup storageRepository capacity alertBackup/DR Admin1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Capacity issues can silently break recovery.Capacity forecasting, retention tuning, alerts, storage expansion plan.4 hoursRelated serviceNew
86Cloud backup account compromisedBackup & Disaster RecoveryBackup identityCriticalP1 – ImmediateCloud backupSuspicious admin login to backup portalBackup/DR Admin1 Disable or restrict risky account; 2 revoke sessions/tokens; 3 reset password; 4 verify MFA; 5 review sign-ins and admin changes; 6 check mailbox/cloud activity; 7 remove unauthorized access; 8 notify owner; 9 monitor; 10 update access controls.Sign-in logs, MFA logs, audit logs, session/token events, admin role changes, conditional access results.Disable/restrict account, revoke tokens, reset password, remove unauthorized privileges, enforce MFA.Validate sign-ins normalized, MFA enforced, privileges correct, risky sessions closed, monitoring active.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Backup portals need strong identity controls.MFA, IP restrictions, admin role review, separate credentials, alerting.ImmediateRelated serviceNew
87Disaster recovery failover requiredBackup & Disaster RecoveryDR activationCriticalP1 – ImmediateDR environmentPrimary site/service unavailableIncident Commander1 Protect backup repository; 2 check last good backup; 3 verify immutability; 4 review admin changes; 5 test restore; 6 isolate affected backups; 7 coordinate recovery; 8 monitor jobs; 9 adjust retention; 10 document.Backup job logs, repository access logs, retention settings, immutability status, restore test results.Lock repository access, disable suspicious admin account, stop destructive jobs, preserve clean restore points.Restore test selected data, validate clean recovery point, confirm schedules and immutable retention.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.DR plans must be tested before crisis.DR runbooks, annual tests, RTO/RPO alignment, failover communications.ImmediateRelated serviceNew
88Power outagePhysical / FacilitiesPowerCriticalP1 – ImmediateOffice / Server roomUtility outage or UPS alertFacilities/Power Coordinator1 Confirm safety and scope; 2 notify facilities/ISP/vendor; 3 check UPS/generator; 4 protect systems from improper shutdown; 5 document downtime; 6 restore power/connectivity; 7 validate services; 8 communicate status; 9 review redundancy; 10 document.UPS/generator logs, circuit/ISP status, environmental alerts, outage timeline, vendor tickets.Shift to UPS/generator/failover, shut down gracefully, reroute connectivity, protect critical equipment.Verify power/cooling/connectivity stable, systems online, monitoring green, users notified.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Power events need IT and facilities coordination.UPS/generator testing, graceful shutdown plan, redundant power, monitoring.ImmediateRelated serviceNew
89UPS battery failurePhysical / FacilitiesPower protectionHighP2 – UrgentServer room / Network closetUPS battery alarmFacilities/Power Coordinator1 Confirm safety and scope; 2 notify facilities/ISP/vendor; 3 check UPS/generator; 4 protect systems from improper shutdown; 5 document downtime; 6 restore power/connectivity; 7 validate services; 8 communicate status; 9 review redundancy; 10 document.UPS/generator logs, circuit/ISP status, environmental alerts, outage timeline, vendor tickets.Shift to UPS/generator/failover, shut down gracefully, reroute connectivity, protect critical equipment.Verify power/cooling/connectivity stable, systems online, monitoring green, users notified.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.UPS health must be tested regularly.Battery replacement schedule, UPS monitoring, load testing.1 hourRelated serviceNew
90Cooling failure in server roomPhysical / FacilitiesEnvironmentalCriticalP1 – ImmediateServer roomHigh temperature alertFacilities/Power Coordinator1 Confirm safety and scope; 2 notify facilities/ISP/vendor; 3 check UPS/generator; 4 protect systems from improper shutdown; 5 document downtime; 6 restore power/connectivity; 7 validate services; 8 communicate status; 9 review redundancy; 10 document.UPS/generator logs, circuit/ISP status, environmental alerts, outage timeline, vendor tickets.Shift to UPS/generator/failover, shut down gracefully, reroute connectivity, protect critical equipment.Verify power/cooling/connectivity stable, systems online, monitoring green, users notified.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Environmental monitoring prevents equipment damage.Temperature sensors, HVAC maintenance, emergency cooling plan.ImmediateRelated serviceNew
91Physical break-in at network closetPhysical / FacilitiesPhysical securityCriticalP1 – ImmediateNetwork closetDoor alert or evidence of tamperingIncident Commander1 Confirm safety and scope; 2 notify facilities/ISP/vendor; 3 check UPS/generator; 4 protect systems from improper shutdown; 5 document downtime; 6 restore power/connectivity; 7 validate services; 8 communicate status; 9 review redundancy; 10 document.UPS/generator logs, circuit/ISP status, environmental alerts, outage timeline, vendor tickets.Shift to UPS/generator/failover, shut down gracefully, reroute connectivity, protect critical equipment.Verify power/cooling/connectivity stable, systems online, monitoring green, users notified.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Physical access can lead to cyber compromise.Badge/access controls, cameras, locked racks, visitor logs.ImmediateRelated serviceNew
92Lost backup drivePhysical / FacilitiesPhysical data lossHighP2 – UrgentBackup mediaBackup media missingCompliance/Privacy Lead1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Physical media requires encryption and chain of custody.Encrypt removable media, inventory, check-in/out logs, secure storage.1 hourRelated serviceNew
93Office internet circuit cutPhysical / FacilitiesConnectivityHighP1 – ImmediateWAN / BuildingISP/facility reports cable cutVendor/ISP Coordinator1 Confirm scope and affected segments; 2 capture firewall/VPN/router logs; 3 block malicious traffic; 4 check device configs; 5 validate routing/DNS; 6 notify ISP/vendor if needed; 7 restore service; 8 monitor flows; 9 harden; 10 report.Firewall logs, VPN logs, router/switch configs, NetFlow, DNS logs, IDS/IPS events, ISP tickets.Block IP/domain/port, disable risky VPN account, roll back bad config, segment affected network.Validate routing/VPN/firewall policies, test connectivity, review logs for repeat traffic, monitor bandwidth.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Physical cable paths and redundancy matter.Secondary ISP, LTE/5G failover, documented carrier contacts.15 minutesRelated serviceNew
94Building access system outagePhysical / FacilitiesPhysical accessMediumP2 – UrgentOffice facilityBadge/access system offlineFacilities/Power Coordinator1 Confirm safety and scope; 2 notify facilities/ISP/vendor; 3 check UPS/generator; 4 protect systems from improper shutdown; 5 document downtime; 6 restore power/connectivity; 7 validate services; 8 communicate status; 9 review redundancy; 10 document.UPS/generator logs, circuit/ISP status, environmental alerts, outage timeline, vendor tickets.Shift to UPS/generator/failover, shut down gracefully, reroute connectivity, protect critical equipment.Verify power/cooling/connectivity stable, systems online, monitoring green, users notified.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Physical and IT access systems are linked.Backup access procedures, vendor support, battery backup, audit logs.1 hourRelated serviceNew
95Emergency evacuation affects IT operationsPhysical / FacilitiesBusiness continuityHighP2 – UrgentOffice operationsFire alarm/emergency closureIncident Commander1 Confirm safety and scope; 2 notify facilities/ISP/vendor; 3 check UPS/generator; 4 protect systems from improper shutdown; 5 document downtime; 6 restore power/connectivity; 7 validate services; 8 communicate status; 9 review redundancy; 10 document.UPS/generator logs, circuit/ISP status, environmental alerts, outage timeline, vendor tickets.Shift to UPS/generator/failover, shut down gracefully, reroute connectivity, protect critical equipment.Verify power/cooling/connectivity stable, systems online, monitoring green, users notified.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.BCP must include people and access constraints.Remote work readiness, cloud access, alternate site plan, communication tree.30 minutesRelated serviceNew
96Sensitive data exposed publiclyCompliance & Data ProtectionData exposureCriticalP1 – ImmediateFile share / Cloud storagePublic link or exposed repository foundCompliance/Privacy Lead1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Data exposure requires fast scope and reporting review.Data classification, DLP, access reviews, public sharing restrictions.ImmediateRelated serviceNew
97HIPAA ePHI access concernCompliance & Data ProtectionRegulated dataCriticalP1 – ImmediateHealthcare data systemsUnusual PHI access or disclosure reportCompliance/Privacy Lead1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Regulated data incidents require documented investigation.HIPAA risk assessment, minimum necessary access, audit logs, workforce training.ImmediateRelated serviceNew
98PCI cardholder data mishandledCompliance & Data ProtectionRegulated dataCriticalP1 – ImmediatePayment systemsCard data stored/shared improperlyCompliance/Privacy Lead1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Payment data must remain in controlled systems.PCI scope reduction, tokenization, DLP, access control, vendor validation.ImmediateRelated serviceNew
99Audit log retention gapCompliance & Data ProtectionLogging gapHighP2 – UrgentSIEM / LogsLogs missing or retention too shortSOC Analyst1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Investigations fail without logs.Centralized logging, retention policy, time sync, alert on log source failure.4 hoursRelated serviceNew
100Unauthorized access to confidential folderCompliance & Data ProtectionAccess violationHighP2 – UrgentFile server / SharePointUser accesses restricted folder unexpectedlyCompliance/Privacy Lead1 Identify data involved; 2 preserve access logs; 3 restrict access; 4 notify privacy/compliance lead; 5 determine exposure; 6 collect evidence; 7 remediate permissions; 8 prepare reporting if required; 9 monitor; 10 lessons learned.File access logs, DLP alerts, audit trails, object permissions, data classification, affected records.Remove excessive access, stop sharing links, quarantine exposed data set, apply legal hold if required.Validate permissions, confirm exposure scope, complete reporting, monitor access, verify DLP controls.IT Manager, affected business owner, security lead; add legal/privacy/insurance if regulated data may be involved.Permissions drift over time without review.Least privilege, access recertification, sensitivity labels, DLP alerts.1 hourRelated serviceNew