By Ann Marie van den Hurk, Mind The Gap Advisory
Most cyber crisis response plans are well constructed. They define roles, assign responsibilities, map notification paths, and outline communication protocols.
Almost none of them name a person.
That gap is where cyber crisis decision authority breaks down. And after 30 years in crisis, it is the single most consistent failure point I see across organizations of every size and sector.
The permission loop and why it stalls even capable teams
In the first minutes of a cyber crisis, something predictable happens in organizations that have not defined decision authority in advance.
Security is waiting for Legal’s read before recommending a path forward. Legal is waiting for Security’s confirmation before assessing liability. Communications is waiting for both before saying anything publicly.
Every function is doing exactly what its training and professional instincts demand. Nobody is being careless. Nobody is failing at their job.
And no one is deciding.
I call this the permission loop. It is not dysfunction. It is three functions operating correctly inside a structure that was never designed to produce a decision under pressure. Each function is protecting its own domain, each is being professionally responsible, and collectively they are producing paralysis at the moment the organization needs clarity most.
The permission loop does not mean your team lacks capability. It means your organization has not answered one specific question in advance: who is explicitly authorized to break it?
Why a function cannot break the permission loop — only a person can
Most crisis plans address the permission loop by defining clearer roles. Security owns threat assessment. Legal owns exposure. Communications owns narrative. Those definitions are useful. They do not solve the problem.
When Security, Legal, and Communications are each waiting for the others, the issue is not unclear roles. It is the absence of a named individual with explicit pre-authorization to move before the group reaches consensus.
A function cannot make that call. A function is a category. Only a person, with a name, a title, and pre-established authority, can look at an incomplete picture and say: we escalate now. We hold. We acknowledge. We stay silent.
That is what cyber crisis decision authority actually means in practice. Not a chart. Not a matrix. A named decision owner who is explicitly authorized before the crisis to act without waiting for alignment.
The title does not have to be CISO. It could be General Counsel. It could be the COO. What matters is not the role. It is the pre-authorization.
What happens when no one is named
When a named decision owner does not exist, one of two things happens.
The most capable person in the room fills the gap informally. They read the situation, push for escalation, and set the direction. This often works in the moment. It is also not a decision structure. It is one person compensating for a system that was never designed to produce a decision under pressure. That person may not always be available. The next incident will not wait for them.
Alternatively, no one fills the gap and the incident remains in an interim state. Teams continue to investigate. Functions continue to wait for each other. Leadership continues to be briefed incrementally. The permission loop runs while the clock runs with it.
Both outcomes have the same root cause. Cyber crisis decision authority was defined at the function level, not the person level.
Why CIRCIA makes this urgent now
The Cyber Incident Reporting for Critical Infrastructure Act — CIRCIA — is expected to take effect in 2026. Once in force, organizations across 16 critical infrastructure sectors, including financial services, healthcare, energy, and information technology, will be required to report significant cyber incidents to CISA within 72 hours.
The 72-hour clock does not start when your investigation confirms what happened. It starts when you reasonably believe a covered incident has occurred.
That distinction makes the named decision owner a compliance requirement, not just a crisis readiness best practice. Someone in your organization must be authorized to make the determination that you reasonably believe an incident has occurred, before the investigation is complete, under regulatory deadline.
A function cannot make that determination. A permission loop cannot survive a 72-hour window. Only a named, pre-authorized individual can.
What designed cyber crisis decision authority looks like
Organizations that hold control through cyber crises share one characteristic that distinguishes them from those that do not. They answered the following question before the incident: who is the named individual, explicitly pre-authorized, accountable for making the call that cannot wait for consensus?
That person has a clear mandate. They know in advance which decisions are theirs to make and which require escalation. Legal, Security, and Communications know who that person is and what their authority covers. And when the permission loop starts, there is no ambiguity about who breaks it.
This does not eliminate tension between functions. It resolves it in advance by design.
Decision authority under speed is not a mindset. It is architecture. And it has to be built before the crisis, not discovered during it.
In your organization, is there a named person, not a function, explicitly authorized to make the call that cannot wait?
If that question does not have a clear answer, the Crisis Decision Authority Diagnostic is designed to work through it before an incident forces the question.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
