| CPC H04L 63/1416 (2013.01) [H04L 41/22 (2013.01); H04L 63/20 (2013.01)] | 20 Claims |

|
1. A method comprising:
at a cybersecurity event detection and response service:
identifying, via one or more processors, a security event associated with a subscribing entity;
automatically determining, via the one or more processors, a threat severity of the security event using (a) one or more context-informed event handling instructions of the cybersecurity event detection and response service and (b) a corpus of computing environment data of the subscribing entity; and
routing, via the one or more processors, the security event to a security event escalation queue or a security event disposal queue based on the threat severity of the security event.
|