Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do organisations get wrong about preparing communication…
Governance, Ownership & Risk

What do organisations get wrong about preparing communication and decision-making before a cyber crisis?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

A common mistake is assuming crisis decisions can be improvised from the top once an incident starts. In practice, slow, unclear authority paths create delay and confusion, especially when technical teams must act quickly. Organisations need pre-established communication channels, clear roles, and exercised decision paths so response is coordinated before pressure rises and stakes escalate.

Where organisations misread crisis communication and decision-making

The failure is usually not a lack of incident response documents, it is a lack of pre-agreed decision structure. When pressure rises, teams do not need a generic communications plan as much as they need a tested way to decide who can authorise containment, who speaks externally, and how technical facts become executive action fast enough to matter.

This is where organisations often confuse information flow with decision flow. An incident can be well reported and still badly managed if no one has authority to approve isolation, customer notification, regulatory escalation, or service trade-offs without waiting for ad hoc approval chains.

What good preparation actually puts in place

Prepared organisations define the minimum set of roles, channels, and triggers before the crisis, not during it. That means named decision owners, backup approvers, a clear escalation ladder, and communication paths that work when email, collaboration tools, or normal business hours are unavailable.

They also separate the questions that need executive judgement from the questions that need technical judgement. For example, security teams may determine scope and containment options, while leadership decides on risk acceptance, public messaging, or whether to take a customer-facing system offline.

Good preparation also means rehearsing messy handoffs. The point of an exercise is not to prove people can follow a script, but to expose where the script is too slow, too vague, or too dependent on a single person being reachable.

Why delay and ambiguity become the real crisis

Once an incident is active, uncertainty compounds. If teams do not already know who can approve action, they spend the first critical minutes negotiating authority instead of reducing impact. That delay matters because containment, comms, and business decisions often have to be made under partial information.

Decision ambiguity also creates inconsistent messaging. Technical staff may communicate one set of facts to responders, executives may communicate a different level of certainty externally, and neither may match what customers or regulators need. The result is not just confusion, but loss of trust in the organisation’s handling of the event.

When crisis authority is improvised, organisations tend to centralise too late or too broadly. Either the technical team is blocked by too many approvers, or leadership tries to direct tactical response without enough context. Both patterns slow remediation and increase the chance of avoidable damage.

Risk and Threat Considerations

Weak pre-crisis communication and decision design creates operational exposure because the organisation loses time at the exact point when time is most valuable. It also creates a trust problem: if internal roles are unclear, external messaging is usually inconsistent, and that inconsistency can magnify the business and regulatory consequences of the incident.

Failure mechanism: No one has a rehearsed path for rapid decisions, so containment, disclosure, and escalation are delayed while people seek approval or interpret authority in real time.

Impact: The incident lasts longer, the blast radius grows, and the organisation is more likely to send conflicting messages, miss obligations, or make a poor trade-off under pressure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RR-02 — Cybersecurity Roles, Responsibilities, and AuthoritiesClear crisis decision rights depend on assigned roles and authorities.
RS.CO-02 — Incidents are reported consistent with established criteriaPrepared crisis communication requires predefined reporting and escalation paths.
RS.CO-03 — Information is shared consistent with response plansThe question is about coordinating who communicates what, when, and through which channel.
Recommendation — Define crisis decision authorities so containment and communications do not wait on ad hoc escalation. Set incident reporting criteria and channels before an event begins. Align crisis communications to the response plan rather than improvising messaging under pressure.
NIST SP 800-53 Rev 5IR-8 — Incident Response PlanThe subject is preplanned incident communication and decision-making.
CP-2 — Contingency PlanCrisis coordination depends on tested continuity and recovery decision paths.
Recommendation — Document and exercise incident response decision paths before a cyber crisis occurs. Maintain contingency decision paths for degraded communication and service conditions.

Practitioner Guidance

What to prioritise: Define who can make which decision before the incident, especially for containment, communications, and service degradation choices. If the answer depends on reaching a single executive, the process is not resilient enough for a crisis.

What to verify: Test whether the communication path still works when normal collaboration tools are degraded and whether the decision owner can act without a chain of reinterpretation. The useful test is not whether the plan exists, but whether the right person can make the right call within minutes.

Common mistake: Treating a response plan as a documentation exercise instead of an authority design exercise. Teams often overinvest in templates and underinvest in decision rights, which is why the first live incident feels improvised even when the paperwork looks complete.

Practitioner takeaway: The objective is not to predict every crisis decision in advance, it is to remove ambiguity from the decisions that must happen fastest and under the least amount of certainty.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org