Severity vs. Priority: How to Rank Security Incidents

Severity describes the potential impact and gravity of an incident; Priority determines the actual order and speed of handling. An incident can be severe but not urgent if it's isolated and contained, or of medium severity but high priority if it's active on a critical asset. Professional ranking combines credibility, Scope, asset criticality, identity, business exposure, containment status, and time.
In SOC systems, several scores sometimes appear in parallel: Alert Severity, Incident Severity, Risk Score, Magnitude, or Priority. When the team uses them as if they are the same, the result is an inconsistent work queue: an old, isolated “High” incident pushes aside a “Medium” activity currently occurring on a manager’s account.
Microsoft describes Severity as a measure of the potential impact on assets, while the unified incident queue adds a Priority mechanism that also considers asset criticality, rarity, MITRE techniques, and high-profile threats. In QRadar, the Magnitude of an Offense is calculated from a combination of Severity, Relevance, and Credibility along with other factors. These examples illustrate that no single score fits every decision.
The goal is not to replace the tools' scores, but to create an organizational language that explains why an incident is being handled now, who is handling it, and what will cause a change in ranking.




