Model time-to-respond from paging, acknowledgement and escalation hops, and test it against your severity SLA.
Escalation hops are the dominant, most fixable term: each handoff to the next rota, platform team or vendor adds its own acknowledgement wait, so two hops at fifteen minutes cost more than the entire paging chain. The coverage model then adds a fixed penalty representing the wait to get a human engaged out of hours. Severity SLAs are usually written before anyone checks the arithmetic, and a P1 with a sixty-minute response target is unachievable with two escalation hops and a pager rota — that gap is best found on a spreadsheet, not during a ransomware event.
Incident Response Time
Response time = alert-to-page + acknowledgement + out-of-hours penalty + (escalation hops × delay per hop) + first containment action.
SLA margin
SLA margin = severity SLA − response time; a negative margin is a breach, not a near miss.
Response time = alert-to-page + acknowledgement + out-of-hours penalty + (escalation hops × delay per hop) + first containment action. Escalation hops are the dominant, most fixable term: each handoff to the next rota, platform team or vendor adds its own acknowledgement wait, so two hops at fifteen minutes cost more than the entire paging chain. The coverage model then adds a fixed penalty representing the wait to get a human engaged out of hours.
Severity SLAs are usually written before anyone checks the arithmetic, and a P1 with a sixty-minute response target is unachievable with two escalation hops and a pager rota — that gap is best found on a spreadsheet, not during a ransomware event.
This calculator takes 7 inputs: Alert confirmed to page raised, Mean acknowledgement time, Escalation hops before the right responder, Delay per escalation hop, Coverage model, First containment action after engagement, Severity SLA for response. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Pre-authorise containment actions for the responders who receive the page — host isolation, account disable, token revocation — and page the owning team in parallel rather than in sequence. Most escalation delay is permission-seeking, not knowledge transfer.
It depends on the SLA. A pager reliably adds fifteen to thirty minutes before anyone is at a keyboard. If your P1 target is sixty minutes end-to-end, that penalty plus escalation usually consumes it, which is the standard business case for staffed 24×7 coverage.