By Ann Marie van den Hurk, Mind The Gap Advisory
Three questions. Answer them honestly.
What decisions stop when you are unavailable?
Who has authority to make them in your absence?
Do they know they have that authority?
Most executives can answer the first two with reasonable confidence. They know what decisions flow through them. They have thought about who would step in.
The third question is where it gets uncomfortable.
The gap between delegated and known
There is a significant difference between delegating authority and communicating delegation. Between assuming someone knows they can decide and actually telling them — clearly, formally, in writing — that they can.
That gap between delegated authority and known authority is where organizations freeze.
A situation develops while a key executive is unavailable. The team knows roughly who should handle it. But no one is certain they are actually authorized to act. So they wait. They send messages. They try to reach the person who is supposed to be unreachable.
In that delay — whether it is an operational decision, a vendor contract, a regulatory response, or the first moments of a security incident — the cost of the governance gap becomes real.
Undocumented delegation is not delegation. If your team does not know they can decide, they will wait. And waiting in a crisis is itself a decision — one with consequences no one chose.
What the data shows
Palo Alto Networks’ Unit 42 responded to more than 750 major cyber incidents in 2025. Their finding on what slows organizations down is direct.
Delays in containment stem from unclear ownership. Teams waiting for validation that cannot keep pace with the speed of the attack. Response stalling not because people lack capability but because no one has been explicitly told they can act.
Their recommendation is unambiguous. Assign explicit authority for containment actions before an incident so that execution can proceed without hesitation.
Without hesitation.
That is the whole governance argument in three words.
Most organizations have not assigned that authority explicitly. They have assumed it. They have delegated it informally. They have trusted that the right people will know what they are allowed to do when the moment comes.
Assumption is not assignment. And in the first 20 minutes of a serious incident, the team that is waiting to confirm they are authorized to act is losing time they cannot recover.
What CMMC requires and why it matters beyond compliance
For organizations working through CMMC, this is not a soft concern.
The standard requires that roles and responsibilities are assigned and communicated. Not assumed. Not informally understood. Assigned and communicated. “I assumed they knew” will not satisfy an assessor. What satisfies an assessor is documentation — who is authorized to do what, under what circumstances, and how that authority was communicated.
But the compliance dimension is only part of the argument.
The first 20 minutes of a serious incident should never include the question “who is in charge right now?” That question should already be answered. In writing. In your governance structure. In the understanding your team carries with them before anything happens.
If you are making governance decisions in the middle of an operational crisis, you are doing it at the worst possible time. The question of who is in charge should be answered before the crisis exists — not during it.
What designed authority actually requires
Designed authority is explicit. It names who decides. Under what conditions. Without having to ask.
It is not an informal understanding. It is not an assumption based on someone’s seniority or availability. It is documented, communicated, and understood by the people who need to use it — before the pressure arrives.
The organizations that move through crises without freezing are not the ones with the most capable individuals. They are the ones whose authority structure does not depend on anyone having to ask first.
The question who is in charge right now should never have to be asked in a crisis. It should be answered before the crisis exists.
Go back to the three questions.
What decisions stop when you are unavailable? Who has authority to make them? Do they know they have it?
If you cannot answer all three with confidence, that is where the work starts.
If your team would hesitate before acting in your absence
Governance Gap Map
A 90-minute structured session that surfaces where governance drift has created decision authority gaps — and what that exposure looks like before a mandate, deadline, or incident forces it into view. Written finding delivered within 48 hours.
Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations across New England, nationally, and globally. mindthegapcyber.com
