By Ann Marie van den Hurk, Mind The Gap Advisory
The hack was on the screen for less than an hour. The decision problem it exposed is still there.
On July 27, 2026, a public works operator in Braham, Minnesota noticed the town’s water tower level falling. The well that should have replenished it wasn’t responding. Officials didn’t yet know it was a cyberattack. They knew residents needed to conserve water, and they said so.
Water quality was never affected. Service was restored within roughly 90 minutes. By most measures, this is what a good response looks like.
It’s also exactly why it’s worth studying.
The gap nobody names
Most continuity plans are built around a technical sequence. Detect. Investigate. Confirm. Escalate. Respond.
Braham didn’t have that luxury, and neither will most organizations running physical infrastructure. The tower was losing water while the investigation was still forming an opinion about what was happening.
That’s the Anomaly-to-Authority Gap. It’s the space between when a physical system starts behaving wrong and when the right person has both the classification and the standing to act on it. Not the technical ability to act. The standing. The confirmed, communicated authority to make the call.
The uncomfortable version
A utility can have excellent engineers, a well-rehearsed manual fallback, and a documented emergency plan, and still lose the first 20 minutes of a serious incident because nobody was sure who could authorize the next move.
That is not an engineering failure. It is a governance failure.
Attribution is a luxury operations doesn’t have
Weeks after the Minnesota attacks, investigators pointed to Iranian-linked actors as the likely source. That timeline is normal for attribution. It is also irrelevant to the decision Braham had to make that morning.
Attribution matters to investigators. It is rarely the first requirement for operational decision-making. Leadership needs predefined authority to act on operational impact alone, using the information available in the moment, not the information investigators may establish days or weeks later.
The World Economic Forum’s Global Cybersecurity Outlook 2026 found that among highly resilient organizations, 99% report board involvement in cybersecurity, with regular updates and a clearly defined oversight role. That is not a technology finding. It is a governance finding, and it points at the same gap Braham exposed: resilience shows up long before the incident, in whether authority has already been assigned.
A continuity plan that says “switch to manual operations” describes an action. It does not establish who is authorized to order it, who backs them up, or what happens at 2:00 a.m. when the usual person can’t be reached.
This is bigger than one small town
Braham was one of more than 30 Minnesota water systems hit in a single coordinated weekend. The FBI has since reported similar activity in at least seven states, a number that has grown to 12 in the weeks since. CIRCIA’s incident reporting rules for critical infrastructure are expected to be finalized in September 2026, which means utilities will soon carry a regulatory reporting clock alongside the operational one.
For organizations working toward CMMC or similar compliance frameworks, this isn’t a new category of work. Documented authority, communicated roles, and an accountable decision trail are already baseline requirements. The Braham incident just shows what happens when those requirements meet a live physical crisis instead of an audit checklist.
The compliance and crisis readiness intersection
The same authority map that satisfies an assessor is the one that has to hold in the first 20 minutes of a serious incident. Building it for the audit and building it for the crisis is the same work, done once.
Where to start
Ask your leadership team a version of the question Braham answers by accident: if a physical process you depend on started failing right now, would the right person know they had the authority to act before anyone confirmed why it was failing?
Most organizations can’t answer that cleanly. That’s not a criticism. It’s a gap that’s invisible until the moment it isn’t.
The cost of finding the gap before a crisis is always lower than finding it during one.
If you want to find your organization’s Anomaly-to-Authority Gap
Governance Gap Map
A 90-minute structured session that surfaces where governance drift has created decision authority gaps, and what that exposure looks like before a mandate, deadline, or incident forces it into view. Written finding delivered within 48 hours.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations across New England, nationally, and globally. mindthegapcyber.com
