Define: High Severity

In a contract, High Severity describes an incident, such as an external loss or exposure of confidential or organizational information, that causes significant impact to mission-critical IT systems, including large-scale outages. It typically triggers the shortest notification deadlines, highest escalation priority, and most stringent remediation obligations among defined severity tiers.

Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI

What High Severity Means in a Contract

High Severity is a defined term used in agreements, particularly those governing information technology, data handling, and security, to classify the most serious category of incident that a party can experience or cause. When a contract labels an event as High Severity, it usually means the incident has caused, or is likely to cause, substantial disruption to systems that are essential to running the business, or has resulted in unauthorized external access to sensitive information.

The purpose of the classification is practical rather than decorative. Parties negotiate tiered severity levels, often Low, Medium, High, and sometimes Critical, so that both sides know exactly what response is expected without having to argue about the seriousness of an incident after it has already happened. High Severity sits near the top of that scale, just below or alongside Critical, and it is the trigger point at which contractual obligations become most demanding.

Because the consequences of misclassifying an incident can be significant, from missed notification deadlines to reputational damage, contracts increasingly spell out High Severity with specific, measurable criteria rather than leaving it to subjective judgment.

How High Severity Is Defined or Measured

Most agreements define High Severity by reference to two overlapping factors: the scope of the information involved and the operational impact on systems. A typical clause will describe High Severity as external loss or exposure of protected information causing significant impact to mission-critical information technology systems, including large-scale outages. Each element of that phrase does work:.

Relevant Circumstances

  • When implementing new software systems within an organisation
  • When a business aims to mitigate potential financial losses caused by system errors or malfunctions
  • When an organisation is planning for potential cyber threats or system malfunctions

Looking for a quick legal answer?

Draft, review and negotiate legal documents empowered by the market-leading contracting AI.

No credit card required - 30-second signup