Overview
This matrix helps individuals and organizations understand the seriousness of a suspected or confirmed digital compromise. It provides a structured way to evaluate symptoms, determine urgency, and decide whether to escalate to professional support.
Navigation
- Have I Been Hacked?
- Compromise Response Guide
- Incident Response & Vendor Directory
Severity Levels
Level 1 — Low Severity: Likely Benign or Non‑Security Issue
Indicators
- Slow device performance
- App crashes
- Browser pop‑ups from legitimate sites
- Forgotten password lockouts
- Wi‑Fi drops or connectivity issues
Recommended Action
Use the Have I Been Hacked? Checker to confirm. If symptoms persist, follow the Compromise Response Guide.
Level 2 — Moderate Severity: Suspicious Activity
Indicators
- Unexpected password resets
- Unknown logins
- New browser extensions
- Unrecognized devices on accounts
- Social media messages you didn’t send
Recommended Action
Follow the Compromise Response Guide. If multiple symptoms appear together, consider contacting a specialist via the Vendor Directory.
Level 3 — High Severity: Likely Compromise
Indicators
- Unauthorized financial activity
- Email forwarding rules you didn’t create
- Files deleted or altered
- MFA disabled without your action
- Suspicious OAuth apps connected to accounts
Recommended Action
Immediately follow the Compromise Response Guide. Escalate to a specialist through the Vendor Directory.
Level 4 — Critical Severity: Confirmed Compromise
Indicators
- Ransomware lockout
- Encrypted files
- Fraudulent wire attempts
- Evidence of targeted attack
- Cloud resources modified or deleted
Recommended Action
Isolate affected systems. Follow the Compromise Response Guide. Immediately contact a specialist via the Vendor Directory.
Note
This matrix is informational and does not replace professional assessment.
About Sonoran Desert Security (SDSUG)
Sonoran Desert Security (SDSUG) is Arizona’s longest‑running cybersecurity community and a central institution in the region’s security ecosystem. Established in 2001 and operating continuously for more than 25 years, Sonoran Desert Security (SDSUG) provides practitioner‑led leadership, vendor‑neutral governance, and trusted peer collaboration across the Southwest. Through its annual research, ecosystem mapping, and community programs, Sonoran Desert Security (SDSUG) strengthens regional resilience and serves as a stable anchor for Arizona’s cybersecurity practitioners, organizations, and critical infrastructure partners. Sonoran Desert Security (SDSUG) also publishes independent research used by organizations and policymakers across Arizona, the broader Southwest, and national and international security, technology, and governance communities.
Explore Sonoran Desert Security (SDSUG)
Start Here
Guided introduction to SDSUG.
Membership
Join SDSUG for trusted peer collaboration and professional networking.
Leadership
Meet the team guiding SDSUG’s direction.
About SDSUG
Our mission, history, and values.
Events & Meetings
Upcoming topics, speakers, certification prep, and education.
Sponsors
Organizations supporting SDSUG’s.
At a Glance
Overview and orientation FAQ.
Safety & Incident Response
Standards, trained officers, and incident‑response protocols.
Site Index
A full directory of SDSUG web pages and resources.
Last Updated: September 2026
