Skip to content

Incident Management

Incident Management handles disruptions, failures, and security events affecting IT and OT infrastructure. In OT environments, incidents may affect production processes or safety systems — rapid response and full traceability are critical.

New → Acknowledged → Investigating → Mitigation in Progress → Resolved → Closed

Optional states: Escalated, Waiting for Vendor, Waiting for Maintenance Window

SeverityDescriptionExample
CriticalProduction stopped or safety riskPLC unresponsive on production line
HighMajor degradation, partial impactSCADA server unreachable
MediumLimited impact, workaround availableSwitch port flapping
LowMinor issue, no immediate impactFailed backup job
  1. Go to Incidents → New Incident

  2. Fill in the required fields:

    • Title — short, descriptive
    • Severity — Critical / High / Medium / Low
    • Category — IT / OT / Security / Network / Safety
    • Site — affected location
    • Description — full context of the issue
  3. Link affected assets — search and attach the relevant PLCs, servers, or network devices. This enables impact analysis and incident history per device.

  4. Save. The incident is created with status New and SLA timers start.

When the category is OT or Safety, additional fields become available:

  • Production impact — is production affected?
  • Safety impact — is there a safety risk?
  • Operational criticality — criticality of the affected system

From an incident you can:

  • Create a Change Request — if remediation requires infrastructure changes
  • Create a Problem — if this is a recurring pattern
  • Link a Vulnerability — if the incident relates to a known CVE
  • Reference Knowledge articles — attach runbooks or procedures

Service level agreements help teams meet first-response and resolution targets for incidents.

  1. Open Settings → SLA Policies.

  2. Create or edit a policy. Typical fields:

    • Name — e.g. Critical OT — 15m / 4h
    • First response (minutes) — time to acknowledge or begin work
    • Resolution (minutes) — time to reach Resolved
    • Pause on waiting — whether timers pause in states like Waiting for Vendor (when enabled for your tenant)
  3. Associate the policy with severity, category, or site rules as your tenant UI allows.

  4. Save. New and updated incidents matching the policy start SLA clocks automatically.

  • SLA due times appear on the incident detail page when a policy applies.
  • Approaching breach may show visual flags in the UI.
  • Responsible users receive notifications when Settings → Notifications includes Incident SLA — see Notification Settings.

When a target is missed or nearly missed, Monozu may notify assignees and managers per your notification configuration. Tune policies and notifications together to avoid noise — see Troubleshooting — Incident SLA.