The document proposes a multi-agent system architecture for incident reaction in telecommunication networks. The architecture has three layers - low level at the network interface, intermediate level to correlate alerts, and high level with a global view. Agents represent components like alert correlation, reaction decision-making, and policy deployment. The reaction decision agent receives alerts and decides if a reaction is needed based on policies, organization knowledge, and specified behavior. It defines new policy rules for the reaction. The policy deployment agent instantiates and sends the new policies to policy enforcement points to change the network security state. A decision support system using ontologies, Bayesian networks, and influence diagrams helps the agents make decisions.