By Ann Marie van den Hurk, Mind The Gap Advisory
Sygnia, one of the world’s leading incident response firms, reviewed the major cyber incidents of 2025 and identified a recurring pattern.
Incident response plans defined notification paths. But they consistently stopped short of clearly assigning decision authority until an incident reached a material risk threshold. Incidents frequently remained in an interim state. Leadership waited for confirmation on scope, intent, or impact. Legal, communications, and security each evaluated risk from their own perspective, each reasonably cautious about acting too early. While teams worked to align, response timelines extended, operational impact increased, and external obligations accumulated.
After 30 years in crisis, this pattern is familiar to me.
And it comes down to one thing every time. The escalation threshold no one defines.
Why the escalation threshold is the real gap
Most organizations have invested heavily in detection. Monitoring systems. Alert protocols. Trained analysts who know how to spot anomalies. What almost none of them have defined is the precise point at which a signal requires escalation before the investigation is complete, before the facts are confirmed, before anyone fully understands what they are looking at.
That is where the first 20 minutes starts to break.
When a signal appears that looks off but is not yet confirmed, the person who sees it makes a judgment call. They do not want to escalate prematurely. They do not want to interrupt senior leadership for something that turns out to be noise. So they watch it a little longer.
That is a responsible professional doing the responsible thing. It is also exactly how control slips away quietly, before anything is confirmed, in the space between visibility and understanding.
What feels like due diligence in the first few minutes becomes the delay that costs an organization its response window. By the time the investigation has enough to feel certain, leadership is brought in late. The best decisions are no longer available.
Investigation and escalation are not the same action
This is the distinction most incident response plans get wrong.
Investigation is: let’s understand what this is.
Escalation is: someone with decision authority needs to know this exists right now, before we fully understand it.
Most organizations treat these as sequential. First investigate. Then, once there is enough to feel certain, escalate. That sequence is exactly what puts organizations behind the incident.
Investigation and escalation should run as parallel tracks. The existence of a signal at a defined threshold triggers escalation. The investigation continues running alongside it. Leadership is informed early, with incomplete information, and prepared to authorize action before full clarity is available.
Sygnia’s analysis confirms what I have observed consistently across 30 years in crisis. Legal, communications, and security teams each evaluated risk from their own perspective, each reasonably cautious about acting too early. The result was friction at precisely the wrong moment. While teams worked to align, response timelines extended and external obligations accumulated.
That is not a failure of capability. It is a failure of designed authority.
What a defined escalation threshold actually looks like
An escalation threshold answers one specific question: at what point does this signal require someone with decision authority to know it exists, regardless of whether the investigation is complete?
It is not a general guideline. It is a precise, pre-defined answer that tells anyone in the organization, in the moment, under uncertainty, that this goes up now.
The threshold needs to be specific enough to be actionable. It needs to distinguish between signals that warrant investigation only and signals that warrant parallel escalation. And it needs to be designed into the structure before the signal appears, not discovered during the incident.
In 2026, with AI-driven incidents compressing timelines further, boards are increasingly being required to authorize action before attribution clarity exists. The tension between accelerated operational impact and delayed certainty is the governance challenge right now. Organizations that have not defined their escalation threshold are navigating that tension with judgment alone. And judgment, under uncertainty, defaults to caution.
The question your organization needs to answer now
The organizations that found themselves behind the incident in 2025 were not operating without plans or without capable people. They were operating without a precise, pre-designed answer to this question: at what point does a signal require someone with decision authority to know it exists, before the investigation is complete?
In your organization, right now, what is that threshold?
Not what your incident response plan says. In practice. In the moment. When someone is sitting with uncertainty and a signal that looks off, what tells them this goes up now?
If that question does not have a clear answer, that is the gap. And it is exactly where the first 20 minutes breaks.
The Crisis Decision Authority Diagnostic is designed to surface that gap before an incident forces the question.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
