Contenttrailcore

Charting · 18 May 2026

Severity colours that survive a meeting

Practical rules for colouring cybersecurity event charts so severity bands stay readable in print and on a projector.

Printed line charts and figures spread across a desk

Severity is a label your detectors already own. Colour is only a way to keep that label visible when the chart leaves the SOC. The mistake we see most often is borrowing a traffic-light set and then using green for ‘closed’ as well as for ‘low’. By the time the figure reaches a projector in a sunlit room, closed and low look the same.

Pick one job for colour: severity, or status, not both. If severity is the job, keep status as a mark — a hollow point for open, a filled point for closed — or as a second small table. Print the figure in greyscale once. If the bands collapse, they will also collapse for anyone who is colour-blind or who receives the pack as a photocopy.

We keep a short palette for Contenttrailcore packs: a deep ink for axes, a clay red for high, a dry ochre for medium, a slate for low, and a pale wash for informational noise. We do not use neon. Projectors in council buildings and hospital seminar rooms wash neon out.

Name the detector’s own words in the legend. If your SIEM says ‘Priority 1’ rather than ‘Critical’, the legend should say ‘Priority 1’. Translating labels in the chart is how two teams end up arguing about a count that never changed.

Back to the journal