Cyber Crisis Management
Cyber crisis management is the executive-led practice of governing a major security incident as an enterprise event: who decides, what is said, which obligations trigger, and how the organization returns to operation. It sits above technical incident response, which contains the compromise, and turns it into decisions the board, regulators, customers, and staff can act on.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Cyber Crisis Management
Cyber crisis management is what you do when a security incident stops being a technology problem and starts being an enterprise event. Incident response contains the compromise. Crisis management decides who is accountable, what is said, which obligations trigger, and how the organization keeps running while the bytes are still being cleaned up. The two run at the same time, and they fail independently. A perfectly contained incident paired with a missed notification deadline is still a crisis, just a different one.
The thing that catches people is that a crisis is declared against criteria, not against alarm. Material impact, a legal or regulatory obligation, external visibility, or scope you cannot bound — these are triggers set in advance, not feelings you have during the event. The declaration is a handoff from the response pillar to the governance pillar, where authority moves upward. An organization that waits until it is alarmed to decide who is in charge has already lost the first twenty minutes.
The load-bearing idea is separation. A crisis lead holds executive accountability. An incident commander runs the technical response. These are different people, because one person doing both loses either the decisions or the containment. The same goes for the legal lead, the communications lead, and the board liaison. A plan that names a role and no person fails on the first handoff, which is the handoff you cannot afford to fail.
The second idea is parallelism. Four layers run at once: technical response, executive command, external obligations, and business continuity. Disclosure is not a downstream add-on after containment. For US public companies, the SEC clock starts at the materiality determination — a governance act made with legal and finance — not at discovery, and it does not pause while you find the root cause. Running that assessment in parallel with containment is the discipline. The determination is documented and dated, and it may be examined.
The surprise is that preparedness is the controllable phase, not response. The work happens before the incident: scenario playbooks, asset inventory, pre-drafted holding statements, tabletop exercises, and retainers for the specialists you will need at three in the morning. An unexercised plan is an untested claim. A tabletop that surfaces a role vacuum on a Tuesday is cheaper than a ransomware event that surfaces it on a Sunday.
The holding statement is the artifact most people get wrong by overusing it. It acknowledges awareness, states that an investigation is underway, names a spokesperson, and commits to an update time. It does not confirm or deny what is not yet known. Each correction erodes trust; stated uncertainty is the one thing that ages well.
Read the Intro for the four-layer architecture and the disclosure discipline. Keep the Cheatsheet beside a live draft. The Practice Reference carries the declaration one-pager, the holding statement template, and the board escalation brief. The Exercise tests whether another reader can run the first two hours from your plan alone. Field Notes carries the costly mistakes that a polished plan can hide.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.nist.gov/publications/incident-response-recommendations-and-considerations-cybersecurity-risk-management-csf
Supports
- Incident response integrated throughout Cybersecurity Framework 2.0 risk management
- Iterative response activities under incomplete information
- Response roles for leadership, handlers, technology professionals, legal, privacy, and public affairs
- Common language for internal and external incident response communication
- Current publication identity and April 2025 release
- https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r3.pdf
Supports
- Analysis, prioritization, mitigation, root-cause work, restoration, and resilience improvement
- Incident response recommendations across Govern, Identify, Protect, Detect, Respond, and Recover
- Coordination, information sharing, evidence, recovery, and continuous improvement considerations
- Continuous improvement as part of the response cycle rather than a separate ceremony
- https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20
Supports
- CSF 2.0 supports understanding, assessment, prioritization, and communication of cybersecurity risk
- Govern connects organizational context, expectations, roles, risk strategy, and executive communication
- Cybersecurity risk management integrates with enterprise risk management
- February 2024 release of Cybersecurity Framework 2.0 and the addition of Govern
- https://www.cisa.gov/topics/cybersecurity-best-practices/executive-order-improving-nations-cybersecurity
Supports
- Standardized procedures for identifying, coordinating, remediating, recovering, and tracking mitigations
- Shared practices for coordinated communication, analysis, discovery, and response
- Usefulness of the federal playbook's broader practices outside federal agencies
- https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf
Supports
- Operational incident response phases, checklists, action tracking, and coordination
- Preparation, detection and analysis, containment, eradication, recovery, and post-incident activities
- Incident documentation, evidence preservation, communications, remediation, and closure
- Communications as a coordinated activity alongside analysis and containment
- https://www.cisa.gov/sites/default/files/2023-01/8_-_ctep_aar-ip_template_2020_final_508.pdf
Supports
- Discussion-based tabletop exercises with defined scope, scenario modules, objectives, and improvement planning
- https://www.sec.gov/rules-regulations/2023/07/s7-09-22
Supports
- Public-company disclosure requirements connect material cybersecurity incidents, risk processes, management roles, and board oversight
- Materiality and disclosure are governance concerns alongside technical incident handling
- Disclosure within four business days of the materiality determination
- https://www.nacdonline.org/all-governance/governance-resources/governance-research/director-handbooks/2026-cyber-risk-oversight/cyber-risk-handbook-toolkit-2026/boards-role-cyber-incident-response/
Supports
- Four pillars of effective cyber incident response: governance, preparedness, response, and recovery
- Program ownership under a senior executive with cross-functional authority
- Board review of IR plans annually and briefings on regulatory obligations and liabilities
- Preparedness as the most controllable phase, including playbooks, inventory, communications protocols, tabletops, and retainers
- Contact and communication obligations running concurrently with containment
- Information that is known frequently changes during an incident
- Recovery as restoration of critical functions, transparent communications, root cause analysis, and playbook updates
- Board escalation thresholds based on financial, legal, or reputational impact
- Sample board responses on tabletop frequency, disclosure obligations, and lessons learned
- https://www.nacdonline.org/all-governance/governance-resources/governance-research/director-handbooks/2026-cyber-risk-oversight/cyber-risk-handbook-toolkit-2026/building-a-relationship-between-board-and-ciso/
Supports
- Boards cannot oversee cyber risk effectively if they only interact with the CISO during annual presentations or after a crisis
- Sustained, structured engagement with the CISO helps directors view cybersecurity as an enterprise-wide strategic concern
- Reporting should use business metrics rather than purely technical jargon
- Regular non-crisis communication and cross-functional integration support cyber-risk oversight
- Transparency includes prompt reporting of incidents, near misses, vulnerabilities, and residual risk
- https://sre.google/sre-book/managing-incidents/
Supports
- Living incident state documents, explicit command handoff, and a recognized coordination post
- Authority that is not pre-assigned is authority that is negotiated
- https://sre.google/workbook/postmortem-culture/
Supports
- Action-item ownership, timely postmortems, operational data capture, and organizational learning
- Blameless postmortems as the mechanism that turns an incident into a stronger plan
- Repeating incidents as a signal that action items are not closing or the faulty service is overdue for a refactor
- https://github.com/sindresorhus/awesome
Supports
- Discovery of curated community lists relevant to incident response, security operations, and crisis communications
- https://www.first.org/resources/guides
Supports
- FIRST incident response guidance on coordinated disclosure, CSIRT establishment, and incident communication practices
- https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
Supports
- Common protections that reduce the likelihood and impact of known risks and adversary techniques
- https://www.weforum.org/publications/principles-for-board-governance-of-cyber-risk/
Supports
- Principles for board governance of cyber risk connecting oversight, strategy, and resilience
- https://www.splunk.com/en_us/products/splunk-enterprise-security-features.html
Supports
- Analyst queue, investigation, case management, threat topology, response plans, and automation capabilities
- https://learn.microsoft.com/en-us/azure/sentinel/automation/automation
Supports
- Incident handling automation rules, playbooks, triage tasks, investigation support, and response automation
- https://www.crowdstrike.com/platform/
Supports
- Endpoint telemetry and remote response actions for containment and eradication
- https://www.paloaltonetworks.com/cortex/cortex-xsiam
Supports
- Incident timelines, alert enrichment, inline playbooks, endpoint remediation, and investigation context
- https://www.servicenow.com/docs/r/security-management/security-incident-response/sir-landing-page.html
Supports
- Security incident tracking from analysis through containment, eradication, recovery, review, and closure
- https://www.ibm.com/products/qradar-siem
Supports
- Log aggregation and detections that rapid triage relies on to bound scope, and evidence preservation
- https://www.mandiant.com/services/incident-response
Supports
- Incident response retainers, DFIR specialists, breach counsel coordination, and dark web intelligence
- https://www.areteir.com/services/incident-response
Supports
- Combined technical response, ransom negotiation, and recovery services for ransomware scenarios
- https://coveware.com/
Supports
- Ransomware response platform structuring negotiation and payment decisions with recovery validation
- https://www.breachquest.com/
Supports
- Pre-incident readiness and post-incident response including playbook authoring and tabletop support
- https://www.onetrust.com/products/breach-resolution/
Supports
- Breach notification workflows tracking jurisdiction-specific clocks and customer notification obligations
- https://www.pagerduty.com/platform/incident-management/
Supports
- Responder mobilization and escalation cadence with an audit trail of who was paged, when, and with what severity
- https://www.everbridge.com/products/crisis-management/
Supports
- Mass notification and stakeholder communication workflows with templated, legally reviewed content
- https://www.diligent.com/products/boards
Supports
- Board pack distribution, annotations, approvals, and action tracking for crisis and non-crisis reporting
