openskills.info
Course Preview

Cyber Crisis Management

Cyber crisis management is the executive-led practice of governing a major security incident as an enterprise event: who decides, what is said, which obligations trigger, and how the organization returns to operation. It sits above technical incident response, which contains the compromise, and turns it into decisions the board, regulators, customers, and staff can act on.

itCybersecurity fundamentals and governance

Don't Panic — Cyber Crisis Management

Cyber crisis management is what you do when a security incident stops being a technology problem and starts being an enterprise event. Incident response contains the compromise. Crisis management decides who is accountable, what is said, which obligations trigger, and how the organization keeps running while the bytes are still being cleaned up. The two run at the same time, and they fail independently. A perfectly contained incident paired with a missed notification deadline is still a crisis, just a different one.

The thing that catches people is that a crisis is declared against criteria, not against alarm. Material impact, a legal or regulatory obligation, external visibility, or scope you cannot bound — these are triggers set in advance, not feelings you have during the event. The declaration is a handoff from the response pillar to the governance pillar, where authority moves upward. An organization that waits until it is alarmed to decide who is in charge has already lost the first twenty minutes.

The load-bearing idea is separation. A crisis lead holds executive accountability. An incident commander runs the technical response. These are different people, because one person doing both loses either the decisions or the containment. The same goes for the legal lead, the communications lead, and the board liaison. A plan that names a role and no person fails on the first handoff, which is the handoff you cannot afford to fail.

The second idea is parallelism. Four layers run at once: technical response, executive command, external obligations, and business continuity. Disclosure is not a downstream add-on after containment. For US public companies, the SEC clock starts at the materiality determination — a governance act made with legal and finance — not at discovery, and it does not pause while you find the root cause. Running that assessment in parallel with containment is the discipline. The determination is documented and dated, and it may be examined.

The surprise is that preparedness is the controllable phase, not response. The work happens before the incident: scenario playbooks, asset inventory, pre-drafted holding statements, tabletop exercises, and retainers for the specialists you will need at three in the morning. An unexercised plan is an untested claim. A tabletop that surfaces a role vacuum on a Tuesday is cheaper than a ransomware event that surfaces it on a Sunday.

The holding statement is the artifact most people get wrong by overusing it. It acknowledges awareness, states that an investigation is underway, names a spokesperson, and commits to an update time. It does not confirm or deny what is not yet known. Each correction erodes trust; stated uncertainty is the one thing that ages well.

Read the Intro for the four-layer architecture and the disclosure discipline. Keep the Cheatsheet beside a live draft. The Practice Reference carries the declaration one-pager, the holding statement template, and the board escalation brief. The Exercise tests whether another reader can run the first two hours from your plan alone. Field Notes carries the costly mistakes that a polished plan can hide.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources