Who approves the first move in a cyber incident?
By Ann Marie van den Hurk, Mind The Gap Advisory
When a cyber incident begins, the first decisions are not technical. They happen before the security team has a complete picture. Before legal has reviewed anything.
The first decisions are operational. Isolate the system. Notify stakeholders. Call outside counsel now or wait.
Those decisions require authority. Not general authority. Specific authority. The kind that can be exercised by one person, on the spot, without a meeting.
Most organizations discover in that moment that authority was assumed, not assigned.
Why cyber incident response decision authority breaks down
Organizations with clear governance structures, clear reporting lines, and well-documented incident response plans still freeze in the first twenty minutes.
The reason is straightforward. Governance designed for normal operating conditions was not designed for compressed timelines.
Under speed, ambiguity does not resolve. It compounds. Every person waiting for approval is watching the clock. Every minute without a decision is a minute the incident moves forward without a response.
This is not a failure of expertise. The people in the room are highly capable. It is a failure of designed authority. Nobody was explicitly designated to make this call, in this condition, under this level of uncertainty.
The pattern is consistent across organizations. A review of major 2025 cyber incidents by Sygnia, a globally recognized incident response firm, found that incident response plans defined notification paths but consistently stopped short of assigning decision authority. Leadership teams were familiar with the framework. They were not prepared for the pace.
A 2025 survey of 480 senior cybersecurity executives by Cytactic found that 70% believed internal misalignment created more chaos during an incident than the attackers themselves.
The threat inside the room outpaced the threat outside it.
What designed authority actually looks like
Most incident response plans document who needs to be notified. Very few document who can act.
Those are not the same thing.
Designed authority means one person has explicit authorization to make a specific class of decisions, under defined conditions, without waiting for consensus. It is named before the incident. It is tested before pressure arrives. It is understood by everyone in the room before the clock starts running.
The organizations that move cleanly in the first twenty minutes are not the ones with the most comprehensive incident response plans. They are the ones that did the uncomfortable governance work in advance. They named the person. They defined the condition. They tested it when the stakes were low enough to get it wrong.
That work does not appear in most incident response plans. It does not appear on most risk registers. It is a governance decision that most leadership teams have not made explicitly because the gap is invisible until the moment it becomes a delay.
The cost of the authority gap
The delay is not visible from outside the organization in the first twenty minutes. It becomes visible later.
When the response timeline is reconstructed in a regulatory filing, a board debrief, or press coverage, the gap between detection and first action is documented. That gap is the cost of ambiguity.
In a regulatory environment where incident notification windows are measured in hours, not days, the authority gap is not an abstract governance problem. It is a documented liability.
The question every leadership team needs to answer
Ask this before the next incident: who can approve the first move right now?
Not who is responsible. Not who is in the room. Who can say yes, right now, and make it stick.
If the answer is not immediate, the delay is already built into the response.
The Crisis Decision Authority Diagnostic is a 90-minute structured session that surfaces exactly where authority breaks in your organization and delivers a written finding within three business days.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com
