Configure alerts so findings reach the right people
Quiet alerts for lows, paging for criticals, and one team-wide digest. A minimal config that scales.
The fastest way to drown a team in noise is to route every finding to every channel. A good baseline: tiered routing by severity, one weekly digest, and one quarterly review to prune rules that no-one reads.
A minimal routing config
- Critical & High: page on-call via email or Slack, within minutes.
- Medium: create a Jira ticket automatically, assigned to the asset owner.
- Low & Info: include in a Monday weekly digest, no per-finding alert.
Business-hours vs always-on
Outside of core hours, only Critical should page. Everything else can wait for morning. If you're finding Medium-severity alerts waking people up, your severity mapping needs tightening — not your paging rules.
Quarterly pruning
Set a calendar reminder. Every quarter, review which alerts were actioned vs ignored. If a whole class of alert has been ignored for three months, either remediate the underlying finding type at source or change the routing. Stale alerts are alert fatigue in slow motion.
