By Ann Marie van den Hurk, Mind The Gap Advisory

 

PwC’s Global Crisis and Resilience Survey found that a majority of executives expect their organizations to face a significant crisis within the next two years. Far fewer feel fully prepared to respond.

The gap between those two numbers is not primarily a technology problem. It is a cyber crisis internal alignment problem. And after 30 years in crisis, I can tell you it shows up the same way every time.

 

How internal misalignment goes public — and why nobody sees it coming

In the first twelve minutes of a cyber or AI-driven crisis, the room is full. Everyone is moving. Security is working the problem. Legal is assessing exposure. Communications is standing by. Leadership is being briefed.

And nobody is working from the same version of events. Not because anyone is uninformed. Because the situation is still forming and each function is interpreting it through their own lens, at their own pace, with the information available to them in that moment.

Here is what happens when those versions do not align.

The misalignment does not announce itself. It seeps.

Not through press conferences or deliberate disclosures. Through the quieter channels. A briefing note forwarded one step further than intended. A hallway conversation overheard by the wrong person. An executive who receives one version of events, acts on what they understood to be true, and mentions something to someone outside the response structure.

Not a statement. Just what they understood. And now there are two versions of reality in circulation. The one inside the room. And the one that just left it.

Nobody broke protocol. Nobody was careless. Trusted people with different versions of the truth caused the damage. That is how cyber crisis internal alignment fails.

 

Why this is a structure problem, not a people problem

Kroll’s State of Cyber Resilience report, surveying 1,000 cybersecurity decision-makers across 10 countries, found that persistent misalignment remains between what cybersecurity teams need and what the business prioritizes. The gap is structural, not personal.

This is consistent with what I see consistently in crisis rooms. The functions are not failing. They are doing exactly what their training and professional instincts demand. Security is protecting accuracy. Legal is protecting exposure. Communications is protecting credibility. Leadership is synthesizing summaries from all three.

The problem is that nobody has defined which version of events is the official one before the briefings start. Without that definition, every briefing becomes a variation of the last one. Every update introduces small degrees of drift. And drift, under pressure, compounds until it is visible externally.

Cyber crisis internal alignment is not about getting everyone to agree in real time. Under pressure, with incomplete information and a situation that is still forming, real-time consensus is not achievable. The alignment has to be structural. It has to be designed before the crisis arrives.

 

The question that determines whether internal alignment holds

Most organizations have defined who owns the technical response to a cyber incident. Who runs the investigation. Who contains the threat. Who manages the forensics.

Almost none have defined who owns the official version of reality.

Not who contributes to it. Every function contributes — Security, Legal, Communications, and Leadership each bring a legitimate perspective. Not who reviews it. Every senior stakeholder reviews something before it moves.

Who declares it. Who says: this is what we know, this is what we do not know, and this is the position we are taking right now — before the briefings start, before the drafts circulate, before the updates begin moving through the organization.

Without a named person authorized to make that declaration, every briefing creates a new variation. Every variation introduces the possibility that a version of events exits the room before the official version has been established.

Your internal reality has to be singular before it can be coherent to anyone outside the room.

 

What designed cyber crisis internal alignment looks like

Organizations that hold control through cyber crises have answered three questions in advance.

Who owns the official version of events? Not a function. A person. Named, explicitly authorized, and known to every function in the response structure before the crisis begins.

When does that person declare it? The threshold for declaring the official version has to be defined in advance. At what point in the situation — what level of visibility, what stage of the investigation — does the official position get locked and all briefings align to it?

What does the official version include? A pre-agreed framework for what the official version covers — what is confirmed, what is still under investigation, what the organization’s position is — so that the declaration is operationally useful rather than a vague holding statement.

When those three things exist before minute twelve, cyber crisis internal alignment holds. When they do not, trusted people with different versions of the truth will cause more damage than the attacker.

PwC found that most executives expect a crisis within two years. The Crisis Decision Authority Diagnostic is designed to surface exactly where your organization’s internal alignment breaks down before that crisis arrives.

 

Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com

 

Share This