A security incident becomes a crisis when it outgrows the incident team’s mandate: enterprise-wide outage, regulated disclosure, safety impact, or reputational threat. Crisis management convenes executives, legal, communications, and operations to make decisions — shutdown, disclosure, payment, public statements — that responders cannot make alone.
Key points
Predefined decision authorityCrisis roles, escalation thresholds, decision authority, and communication approval belong in the plan before the crisis, not negotiated during it.
Whole-structure exerciseTabletop the executive and communication path, not just the technical response — crises fail at interfaces between teams, not inside them.
Important limitationPlans choreograph response; they do not make the decisions. Under real pressure, authority gaps, legal exposure, and incomplete information still force judgment — the structure exists to make that judgment informed and accountable.