By Ann Marie van den Hurk, Mind The Gap Advisory

 

The first statement is not a communications problem

When a cyber incident hits, most organizations discover something they should have resolved months earlier. Not a technology gap. Not a staffing gap. A decision authority gap.

According to a 2025 Cytactic report on cyber incident response, 41 percent of senior cybersecurity leaders said they have delayed response actions during a crisis due to uncertainty about who had final authority. In the same study, 54 percent reported that who makes decisions often changes mid-incident — even when plans clearly define responsibilities on paper.

This is not a preparedness failure. It is a governance failure. And it shows up at the worst possible moment.

 

What minute fifteen actually reveals

Every cyber incident has a moment when silence stops being an option. The people outside the room — customers, regulators, journalists, board members — are already drawing their own conclusions. Something has to be said.

Not because the organization is ready. Not because the picture is complete. Because waiting has become more dangerous than speaking.

This is minute fifteen. And what happens in that moment is not determined by the quality of the communications team or the speed of the technical response. It is determined by whether someone has the defined authority to say: this statement goes out now, in this form.

In most organizations, that authority has never been explicitly assigned. It has been assumed. And assumption collapses under speed.

What comes out of that collapse is not a statement. It is whatever survived the room. Hedged. Passive. Written to satisfy every concern inside the four walls — Legal comfortable, leadership protected, every claim qualified until nothing is actually being claimed. Legally defensible. And completely illegible to the people outside who needed to hear from someone in charge.

Vagueness does not protect you. It answers the question the audience is actually asking — is someone in control of this situation — and it answers it wrong.

 

What the M&S breach showed the world

In April 2025, Marks & Spencer found themselves behind one of the most documented cyber incidents in recent retail history. The technical response was activated within days. External experts were engaged immediately. Leadership was visible.

And still the communications track broke down.

After two official statements — the last on April 25 — external communication stalled while the incident ran for weeks. Internally, official systems were so disrupted that employees were coordinating response on personal WhatsApp. Staff reported they did not know what they were supposed to do or say.

The ransomware did not cause that. The absence of defined decision authority did.

£750 million (approximately $1 billion / €865 million) was wiped from market value. Online orders were halted for 46 days. Roughly £300 million (approximately $405 million / €345 million) in lost operating profit followed.

M&S is not an outlier. It is a pattern. The pattern of what happens when the technical and communications tracks are not running in parallel — with equal governance — from the moment of discovery.

 

The anchor effect no one plans for

Here is what makes the first statement uniquely consequential. It is not just the first thing you say. It becomes the standard everything that follows is measured against.

If the situation evolves — and it will — every subsequent statement will be compared to the first one. Regulators will ask why your position changed. Journalists will ask what you knew and when. Board members will ask why the initial statement did not reflect the full picture.

The first statement sets the anchor. And the anchor is set the moment it goes out, whether you are ready or not.

This is why three decisions have to exist before minute fifteen forces them.

Who has final authority to approve the statement — not draft it, not review it, but say it goes out now, in this form. This is a single named individual with a named backup. Not a committee. Not a consensus process. A person.

What posture the organization is taking. Acknowledging, investigating, or containing. Each one sends a different signal and requires different language. Choosing the wrong posture under pressure is not a communications error. It is a leadership signal.

What the organization is willing to be held to. Because the first statement is not just communication. It is a commitment. And commitments made under pressure without prior authority design become liabilities.

 

This is a governance decision, not a communications decision

The permission loop — Legal reviewing, Communications drafting, the CISO waiting, the CEO waiting — does not resolve itself under speed. It hardens. And what comes out is the statement that survived the process, not the one the moment required.

Decision authority under speed is not a function of having the right people in the room. It is a function of having defined, in advance, exactly who has the authority to act — and under what conditions.

Most organizations have not done that work. They have communications plans, incident response playbooks, and legal review protocols. What they do not have is a singular internal reality about who is in charge of the communications track when the pressure hits.

That gap is invisible until minute fifteen makes it visible to everyone — including the people outside the room who stopped waiting and started drawing their own conclusions.

Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com

_________________

Cytactic 2025 State of Cyber Incident Response Management Report, as reported by ASIS Online, October 2025

Marks & Spencer cyber incident timeline and financial impact — BlackFog, October 2025

Marks & Spencer communications response — Al Jazeera, May 2025

Marks & Spencer internal communications breakdown — ID Agent, May 2025

Share This