Navigation Path:  Home > Resources > Compromise Severity Matrix
Site Search: 
Next Meeting:  TBD Published:  September 22, 2026 Last Updated:  September 22, 2026 Author:  Hunter Storm

Compromise Severity Matrix

Overview

This matrix helps individuals and organizations understand the seriousness of a suspected or confirmed digital compromise. It provides a structured way to evaluate symptoms, determine urgency, and decide whether to escalate to professional support.

Navigation

  • Have I Been Hacked?
  • Compromise Response Guide
  • Incident Response & Vendor Directory

Severity Levels

Level 1 — Low Severity: Likely Benign or Non‑Security Issue

Indicators

  • Slow device performance
  • App crashes
  • Browser pop‑ups from legitimate sites
  • Forgotten password lockouts
  • Wi‑Fi drops or connectivity issues

Recommended Action

Use the Have I Been Hacked? Checker to confirm. If symptoms persist, follow the Compromise Response Guide.


Level 2 — Moderate Severity: Suspicious Activity

Indicators

  • Unexpected password resets
  • Unknown logins
  • New browser extensions
  • Unrecognized devices on accounts
  • Social media messages you didn’t send

Recommended Action

Follow the Compromise Response Guide. If multiple symptoms appear together, consider contacting a specialist via the Vendor Directory.


Level 3 — High Severity: Likely Compromise

Indicators

  • Unauthorized financial activity
  • Email forwarding rules you didn’t create
  • Files deleted or altered
  • MFA disabled without your action
  • Suspicious OAuth apps connected to accounts

Recommended Action

Immediately follow the Compromise Response Guide. Escalate to a specialist through the Vendor Directory.


Level 4 — Critical Severity: Confirmed Compromise

Indicators

  • Ransomware lockout
  • Encrypted files
  • Fraudulent wire attempts
  • Evidence of targeted attack
  • Cloud resources modified or deleted

Recommended Action

Isolate affected systems. Follow the Compromise Response Guide. Immediately contact a specialist via the Vendor Directory.


Note

This matrix is informational and does not replace professional assessment.


About Sonoran Desert Security (SDSUG)

Sonoran Desert Security (SDSUG) is Arizona’s longest‑running cybersecurity community and a central institution in the region’s security ecosystem. Established in 2001 and operating continuously for more than 25 years, Sonoran Desert Security (SDSUG) provides practitioner‑led leadership, vendor‑neutral governance, and trusted peer collaboration across the Southwest. Through its annual research, ecosystem mapping, and community programs, Sonoran Desert Security (SDSUG) strengthens regional resilience and serves as a stable anchor for Arizona’s cybersecurity practitioners, organizations, and critical infrastructure partners. Sonoran Desert Security (SDSUG) also publishes independent research used by organizations and policymakers across Arizona, the broader Southwest, and national and international security, technology, and governance communities.




Last Updated: September 2026

error: Content protection is enabled to prevent unauthorized copying.