By Ann Marie van den Hurk, Mind The Gap Advisory

 

In the first ten minutes of a cyber crisis, two completely different conversations start happening simultaneously inside most organizations.

Legal is asking: what can we say safely? What creates exposure? What should we avoid until the investigation is complete?

Communications is asking: what does silence look like to the people already watching? What story fills the vacuum if we say nothing?

Both questions are legitimate. Both functions are doing exactly what they should be doing. And they want different things.

This is the crisis communications decision authority problem. And after 30 years in crisis, it is one of the most consistent failure points I see across organizations of every size and sector.

 

Why Legal wins by default — and what that costs

When Legal and Communications disagree in a cyber crisis, Legal almost always wins. Not because anyone decided in advance that Legal should lead on communications. Because Legal is usually more senior in the room, more certain in their position, and the consequences of speaking too early feel more concrete than the consequences of speaking too late.

So the organization goes quiet. Internally, it feels like the responsible choice.

Externally, it is a signal.

Once something is visible outside the organization — a post, a customer question, a screenshot circulating in a channel you do not control — silence communicates something. It communicates that the organization does not yet have its response together. That creates a narrative vacuum. And narrative vacuums get filled, usually by sources the organization would not choose.

A recent after-action report from Health-ISAC, examining cyber resilience exercises across the healthcare sector, found a pattern that applies across industries. Communications teams are consistently being brought in after key decisions have already been made. Technical resilience has improved significantly over the past decade. Crisis communications decision authority has lagged behind.

That is not a communications failure. It is a structural one.

 

The two risk calculations organizations fail to separate

Legal risk and reputational risk are not the same risk. They operate on different timelines, affect different stakeholders, and require different decisions.

Legal risk is concerned with what the organization says becoming a liability — admissions, commitments, statements that create exposure before the facts are confirmed. The instinct to protect against this is correct.

Reputational risk is concerned with what the organization’s silence communicates — the narrative that forms while the organization is still aligning internally. This risk is just as real and, in many cases, harder to recover from than a legal exposure.

When one risk calculus consistently wins by default, the other goes unmanaged. Organizations that default to Legal silence may protect themselves from early liability while simultaneously creating a reputational gap that takes far longer to close.

Most organizations never examine which outcome they actually experienced. They do not do the post-incident analysis that would tell them whether the decision to stay silent protected them or cost them. So the default persists. Legal wins the next time too. Not because it was right. Because it was never examined.

 

What crisis communications decision authority actually requires

The question most organizations ask in a crisis is: do we say anything?

That is the wrong question. It is a real-time negotiation between Legal and Communications under pressure, with incomplete information, while the narrative outside is already forming.

The right question is: what are we willing to acknowledge before we have full confirmation — and who is authorized to make that call?

That is a design decision. It defines the threshold for early acknowledgment. It names the person or function authorized to approve an early holding statement. And it exists before the crisis, so that when pressure arrives, the negotiation has already happened.

Crisis communications decision authority means knowing in advance whose risk calculus leads at which moments. It does not mean Legal always wins. It does not mean Communications always wins. It means the organization has made a deliberate, pre-designed determination about how to balance two legitimate and competing risk perspectives — and has named the person authorized to execute that determination under pressure.

 

Building crisis communications decision authority before the incident

Organizations that hold control through cyber crises have answered three questions before the incident begins.

What is the threshold for early acknowledgment? At what level of external visibility does the organization issue a statement before the investigation is complete? This threshold should be specific — not a general guideline, but a defined answer that tells leadership exactly when a holding statement is warranted.

Who approves the holding statement? Not a function. A person. Someone explicitly authorized to say: we acknowledge this exists, here is what we know, here is what we are doing, here is when we will update you. That authorization has to exist before the crisis, not be negotiated during it.

What does acceptable early acknowledgment look like? Pre-drafted holding statement language, reviewed and approved by both Legal and Communications in advance, that can be adapted and deployed quickly without requiring real-time negotiation between functions under pressure.

When these three things are in place, the question do we say anything becomes operational rather than political. The answer exists. Someone is authorized to execute it. And the narrative does not fill with silence while Legal and Communications find their way to agreement.

That is what crisis communications decision authority looks like before the first ten minutes force the question.

The First-Hour Response Design is built to define exactly this structure for your organization — before an incident makes the negotiation visible.

Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com

Share This