By Ann Marie van den Hurk, Mind The Gap Advisory
Yes. But not the kind most organizations are looking for.
When executives, CISOs, and board members search for an executive decision-making framework for cyber and AI crises, they typically find one of three things: government policy frameworks designed for national-level threat response, academic research on cybersecurity investment decision theory, or compliance frameworks like NIST and the EU AI Act that govern how AI systems are built and audited. All of it is valuable. None of it answers the operational question that leadership teams are actually asking.
The question is not how to govern AI systems or comply with cyber regulations. The question is who decides what, in what order, in the first 20 minutes of a live AI-driven or cyber crisis — before facts are confirmed, before Legal has completed its review, and before the executive team has formally convened.
That is a different problem. And it has a different answer.
What the existing frameworks actually cover
The frameworks that dominate the search results for this question fall into two categories.
The first is policy and regulatory frameworks. The EU AI Act, the NIST AI Risk Management Framework, the OECD AI Principles, RAND’s work on government AI cyber decision-making, and the US Treasury’s Financial Services AI Risk Management Framework are all serious, carefully constructed frameworks. They address risk classification, lifecycle governance, compliance obligations, and responsible AI deployment. They were built for deliberative governance — for the work of designing, auditing, and overseeing AI systems across planning cycles and regulatory windows.
They were not built for the 20-minute window in which a leadership team must decide whether to escalate, contain, communicate, or hold when a cyber or AI-driven incident is already moving.
The second category is academic and government decision theory — research on how executives make cybersecurity investment decisions, how cognitive biases affect security resource allocation, and how government agencies should structure cyber policy responses. This work is intellectually rigorous and occasionally useful. It is not an operational framework for executive decision authority during a live incident.
Both categories answer important questions. Neither answers the one that leadership teams are searching for when they ask whether an executive decision-making framework for cyber and AI exists.
The gap that neither category fills
Between compliance-time governance and academic theory, there is a practitioner gap at the crisis layer. It is the gap where executive decision authority during a live AI-driven or cyber incident should sit — and where, for most organizations, nothing has been formally built.
That gap has specific characteristics. It is the absence of a named individual with pre-established authority to declare executive activation before technical investigation is complete. It is the missing definition of the specific conditions — not just technical severity thresholds — that move an incident from security management to executive crisis. It is the lack of pre-authorized holding language that allows leadership to communicate before facts are confirmed. And it is the untested assumption that Security, Legal, Communications, and Operations will maintain a shared operating picture under the time compression that AI-era crises create.
Organizations that have not filled this gap have compliance frameworks without crisis governance. They can demonstrate regulatory adherence and describe their governance structure in a board presentation. What they cannot demonstrate is whether leadership authority holds when a visible incident is moving faster than internal verification.
What CrisisOS5™ addresses
CrisisOS5™ is the executive crisis readiness framework I developed after 30 years at the intersection of crisis communications, executive decision-making, and high-visibility incidents. It is designed specifically to fill the practitioner gap — to govern how executive leadership makes decisions during AI-driven and cyber crises, not how AI systems are built or how compliance obligations are met.
The framework structures executive crisis readiness across five pillars: Risk Intelligence, Rapid Response, Crisis Communication, Simulation Readiness, and Leadership Resilience. But its operational core is decision authority — the pre-established, explicitly assigned right of a named individual to make specific decisions before the group has reached consensus.
From a CrisisOS5™ perspective, an executive decision-making framework for cyber and AI crises must answer five questions that no compliance or policy framework addresses.
Who is the named individual authorized to declare that a cyber or AI incident has crossed the threshold requiring executive activation? What specific conditions — not just technical severity — trigger that threshold? Who is authorized to approve external communication before Legal has completed its review? How does the cross-functional operating picture across Security, Legal, Communications, and Operations get established and maintained under time compression? And what decisions can leadership make in the first 20 minutes before verification is complete?
These are not compliance questions. They are operational governance questions. And they require answers that are specific to your organization’s structure, regulatory environment, and leadership model — not generic frameworks that apply equally to every organization regardless of sector or governance maturity.
Why the search for a framework matters
The fact that executives, CISOs, and board members are searching for an executive decision-making framework for cyber and AI crises is itself a significant signal. It reflects a governance awareness that the existing frameworks — as valuable as they are — do not cover the crisis decision layer. Organizations know something is missing. They are looking for the practitioner answer.
The organizations that find it before an incident requires it are the ones that will maintain leadership authority in the first 20 minutes of the next AI-driven cyber crisis. The organizations that discover the gap during a live event will spend the weeks that follow explaining to boards, regulators, and stakeholders why leadership response was slower and less coherent than it should have been.
Building the decision authority layer is not a documentation exercise. It requires a structured assessment of where your organization’s current governance structure breaks under speed, followed by deliberate construction of the decision authority infrastructure that fills those gaps.
The Crisis Decision Authority Diagnostic is where that work begins. In 90 minutes, it surfaces exactly where your organization’s executive decision authority for cyber and AI crises is unclear, assumed, or absent — and delivers a written finding within three business days that tells you specifically what needs to be built.
If you have been searching for an executive decision-making framework for cyber and AI crises and have not found a practitioner answer, that is what the Diagnostic is designed to provide.
