Escalate a security incident
If an escalation path exists for a security incident, the Escalate button is available in the security incident header.
Before you begin
Role required: sn_si.admin
You must have an escalation group created to see this button. See Create a Security Operations user-defined escalation group for more information.
Procedure
Navigate to All > Security Incident > Show Open Incidents.
Open the incident you want to escalate.
Select the Escalate button.
Choose an escalation group.
Enter a reason for the escalation.
Select Submit.
Updates Assignment Group and Assigned to on the security incident.