Ticket Prioritisation:
Managed Services: Service Desk Specific Prioritisation Definitions
Galtec operate a ticket prioritisation system that enables us to allocate appropriate response times to different priority levels. The priority level assigned to each ticket determines the urgency and impact of the issue, which in turn dictates the speed of our response. Our SLA response times are tailored to ensure that critical issues receive immediate attention while providing timely assistance for lower-priority matters. SLA responses are detailed within Customer Statement of Services Document in Appendix 2: Service Levels.
The following prioritisation matrix applies:
Tickets raised by any users identified as VIP users are dealt with as Priority 1.
Priority 1 - High Urgency High Impact:
For Priority 1 tickets, representing critical issues with high urgency and significant impact on your operations, we are committed to providing the fastest response times. Our team will respond promptly within the allotted SLA response time, ensuring that immediate action is taken to address the situation and restore Customer business functionality. Priority 1 incidents must be logged by telephone for SLA timers to apply due to the urgency of the incident.
Priority 2 - High Urgency Medium Impact / Medium Urgency, High Impact:
Tickets classified as Priority 2 are urgent and demand timely resolution. They may have a medium-level impact on your operations or are of high impact but with a lower level of urgency. Our team will promptly address these tickets after Priority 1 cases, ensuring their timely resolution.
Priority 3 - High Urgency Low Impact / Medium Urgency, Medium Impact / Low Urgency, High Impact:
Tickets categorised as Priority 3 require attention due to their urgency but may have a lower impact on your day-to-day operations. These tickets will be addressed after Priority 1 and 2 cases, with appropriate attention to their resolution based on their respective impact and urgency as defined within your Statement of Services.
Priority 4 - Medium Urgency, Low Impact / Low Urgency, Medium Impact / Low Urgency, Low Impact:
For Priority 4 tickets, representing matters with medium to low urgency and minimal impact on your operations, our SLA response time is defined in your Statement of Services. While these issues are important, they will be addressed after higher-priority cases, allowing us to efficiently manage resources while still providing diligent support.
Security Operations Managed Service: Security Specific Priority Definitions
This section defines the priority and criticality levels used for security-related alerts and incidents originating from our Security Information Events Management (SIEM) and SOC response service, as well as for support requests related to the health and functionality of these platforms.
P1 – Critical/Urgent:
Definition: Active, widespread, or imminent threats that pose an immediate and severe risk to Customer critical assets or data. Examples include but are NOT limited to:
Confirmed active ransomware or malware outbreaks.
Active lateral movement.
Unauthorized access to critical systems or sensitive data.
Large-scale denial-of-service (DoS) attacks.
Compromised domain administrator accounts.
Confirmed Data exfiltration.
Response: On initial analysis of the threat, response actions taken in the relevant platform, a call to the designated call contact and escalation via Email/Ticket will be made.
P2 - High:
Definition: Significant threats that could potentially impact critical systems or data if not addressed promptly. Examples include but are NOT limited to:
Suspicious activity indicating potential malware infection.
Multiple failed login attempts to privileged accounts.
Detection of known vulnerabilities being actively exploited.
Unusual network traffic patterns indicating potential reconnaissance.
Response: On initial analysis of the threat, response actions taken in the relevant platform, a call to the designated call contact and escalation via Email/Ticket will be made.
P3 - Medium:
Definition: Potential security concerns that require investigation and monitoring. Examples include but are NOT limited to:
Detection of potentially unwanted programs (PUPs).
Suspicious file modifications.
Unusual application behaviour.
EDR Application out of date
Anomalous user activity
Response: On initial analysis of the threat, if needed, response actions taken in the relevant platform. Escalation via Email/Ticket will be made if listed as actionable (unless otherwise requested). Generally the recommended action will include a request for verification of activities with an offer to add a whitelist/exclusion or other recommendations.
P4 - Low:
Definition: Informational alerts or low-risk security events that require review and documentation. Examples include but are NOT limited to:
Common false positives related to installed software (Endpoint Protection, Backup, Line of Business applications)
Fully mitigated Alerts.
Activity from known applications.
Policy violations that do not pose immediate risk.
Response: On initial analysis of the threat, if needed, response actions taken in the relevant platform. Escalation via Email/Ticket will be made if listed as actionable (unless otherwise requested). Generally, the recommended action will include a request for verification of activities with an offer to add a whitelist/exclusion or other recommendations.