By Ann Marie van den Hurk, Mind The Gap Advisory

Most executives hear “key-person risk” and think retirement.

Succession committees. Leadership pipelines. Carefully managed announcements.

That is the least likely version of the problem.

The version that actually happens is quieter. A flight delay that stretches into a day. A family emergency that pulls someone out without warning. A conference with back-to-back sessions and a phone that stays in a bag. A bad day where someone simply is not available the way they usually are.

These are not edge cases. They happen every quarter. Some of them happen every month.

And every single one of them is a test of whether your governance structure actually holds — or whether it only works when the right people are in the room.

How authority concentrates without anyone planning it

 

Here is what happens inside most organizations.

Authority concentrates around individuals not because anyone planned it that way but because those individuals are good, reliable, and always available. Decisions route to them. Dependencies build quietly. Documentation does not happen because it does not feel necessary — the person is always there.

Until they are not.

And then everything that was invisible becomes visible all at once.

 

Governance drift in slow motion

Authority migrates away from documented roles and toward whoever shows up consistently. It does not announce itself. It accumulates.

And by the time it surfaces, it is usually because something went wrong.

What CMMC is actually asking

 

CMMC‘s final rule is now in effect. Contract eligibility is tied to demonstrated cybersecurity maturity. Not stated maturity. Demonstrated maturity. And inaccurate certifications now carry risk under the False Claims Act.

Most organizations focused on the technical controls. Very few asked the harder question.

What happens when the person who owns those controls is unavailable?

Not retired. Not resigned. On a plane. At a conference. Out sick on the day an assessor asks who is responsible for documented access authority and backup procedures.

Assessors are not looking for the person who handles it. They are looking for evidence that the organization can handle it regardless of who is in the room.

 

It is not a control. It is a dependency. CMMC knows the difference.

 

That distinction is key-person risk in compliance terms. And it surfaces in assessments before it surfaces in incidents — if the organization is fortunate.

Most are not that fortunate. They discover the gap when the pressure is already on and the decisions are already expensive.

The crisis readiness dimension

 

The first 20 minutes of a serious incident require fast, clear decisions.

A cybersecurity breach. An AI-generated deepfake of your leadership. A regulatory action that lands without warning. In those first 20 minutes the people who need to act have to know they can act — and they have to know what they are authorized to do.

If the person who holds that authority is on a plane, you have already lost time you cannot recover.

Why this cannot wait

Key-person risk is not a succession problem. It is a today problem. The gap shows up in assessments before it shows up in incidents — if the organization is fortunate. The first 20 minutes will not wait for the right person to become available.

What the governance question actually requires

 

The governance question CMMC is asking is the same one every serious incident asks.

Who is authorized to act when the right person is unavailable? Is that written down? Has it been tested?

If the answer lives in someone’s memory, it is not a control. It is a dependency.

Designed authority is explicit. It names who decides. Under what conditions. Without having to ask. It does not depend on any individual being available, willing, or reachable. It is documented, tested, and understood by the people who need to use it before the pressure arrives.

 

The organizations that hold together under pressure are not the ones with the most capable individuals. They are the ones whose governance structure does not depend on any one individual being in the room.

 

Key-person risk is not a succession problem. It is a today problem. And the answer is not a better hero. It is a better structure.

 

If your governance structure depends on the right person being available

Governance Gap Map

A 90-minute structured session that surfaces where governance drift has created decision authority gaps — and what that exposure looks like before a mandate, deadline, or incident forces it into view. Written finding delivered within 48 hours.

Book a Discovery Call →


Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations across New England, nationally, and globally. mindthegapcyber.com

Share This