Major Incident Classification
Major incident classification is the process of deciding whether a disruption is serious enough to be treated as a 'major incident' that requires a formal, coordinated response rather than routine handling. Organizations apply predefined criteria, such as how severely business operations are disrupted or how widely the impact spreads, to sort incidents into severity levels. What counts as 'major' varies by organization and by regulatory regime.
Major incident classification is the application of defined criteria and severity scales to determine whether an incident qualifies as 'major,' triggering escalated, coordinated response procedures. In some operational frameworks, incidents rated at the highest severity tiers (for example, SEV-1 or SEV-2) are typically designated major incidents, while lower tiers are handled through standard processes; classification is often performed by a designated role (such as an Incident Response Manager) using a documented classification matrix. Under the EU's DORA regime, Regulatory Technical Standards specify criteria for classifying major ICT-related incidents, with a major incident generally understood as one that significantly disrupts operational continuity or affects the broader financial system. Note that classification schemes and thresholds are not standardized across organizations or jurisdictions: the distinction between 'major' and 'critical' incidents differs by scheme (in some usages major incidents are confined to specific systems or processes while critical incidents pose broader threats), and regulatory definitions such as DORA's apply to specific sectors and geographies rather than universally. The classification captured here addresses incident severity and escalation triggers; it does not itself specify remediation, reporting timelines, or the underlying detection controls.
Why it matters
Major incident classification determines whether a disruption receives an escalated, coordinated response or is handled through routine processes. This threshold decision matters because it governs who is mobilized, how quickly, and with what authority. Misclassifying a serious event as routine can delay coordinated response, while over-classifying can strain response resources. In third-party and supply chain contexts, the classification a vendor or service provider applies to an incident on their side directly shapes whether, and how urgently, it is communicated to dependent organizations, making consistent classification a factor in downstream visibility.
The practical difficulty is that classification schemes and thresholds are not standardized across organizations or jurisdictions. What one organization treats as a 'major' incident, another may treat as merely 'critical' or routine, and the distinction between 'major' and 'critical' itself differs by scheme, in some usages major incidents are confined to specific systems or processes while critical incidents pose broader threats. This variation complicates efforts to align incident expectations across contractual relationships, where different parties may operate under incompatible severity definitions.
Regulatory regimes add a further layer. Under the EU's DORA framework, Regulatory Technical Standards specify criteria for classifying major ICT-related incidents, with a major incident generally understood as one that significantly disrupts operational continuity or affects the broader financial system. However, such regulatory definitions apply to specific sectors and geographies rather than universally, so organizations operating across regions or serving multiple sectors may need to reconcile a regulatory classification standard with their own internal severity scales.
Who it's relevant to
Inside Major Incident Classification
Common questions
Answers to the questions practitioners most commonly ask about Major Incident Classification.