# Critical Means No Pause Button

Date: 2026-09-29

Consider an airport control tower.

Controllers cannot tell every aircraft: “Please hold your positions while we schedule a steering committee.” The systems supporting aircraft separation, communication and situational awareness operate in an environment where delay, unavailable information or incorrect information may have immediate consequences.

<!--more-->

That is the practical meaning of **critical**: there is no pause button that still keeps people, money, or the licence safe.

Now consider a train protection or anti-collision system. Its value is not measured by how many emails it sends or how attractive its dashboard looks. It exists to prevent an unacceptable outcome. If it fails, the organisation cannot simply continue as normal.

A board paper can wait for the next meeting. A client signature can wait for working hours. Those things can be important, even urgent. They are not in the same class as a capability whose failure starts harm on a clock you do not control.

## Five Questions That Belong on a Critical System

Use these in the pack. Do not accept a label without them.

**Consequence.** What happens if the capability fails? Name the harm in operational language: people, essential service, regulated obligation, core operations, survival. “It would be bad” is not an answer.

**Time.** How long can it be unavailable before serious harm begins? Minutes, hours, a business day? If management cannot give a window, they have not finished the work. They have guessed.

**Integrity.** Could incorrect information be more dangerous than no information? A silent, wrong answer can keep the business moving in the wrong direction. A visible stop at least tells you to stop.

**Substitution.** Is there a safe manual or alternative process? “We would figure it out” is not a workaround. A workaround is named, owned, and tested.

**Dependency.** Which suppliers, identities, networks and people keep it functioning? Criticality is not a property of a logo on a slide. It is a chain. The chain is where boards get surprised.

## The Label Must Change the Money

“Critical” is not a compliment for the team that owns a system. It is a statement about consequences and dependencies.

Once a capability is classified as critical, that decision should change investment: stronger resilience, tested recovery, clearer escalation, and fewer unknown dependencies. If the label does not change controls, budget, testing cadence or who can act at 02:13, it is stationery.

Boards see this failure constantly. Everything in the register is “critical.” Nothing gets the treatment the word implies. Then an incident arrives and the organisation discovers, in real time, that the spreadsheet was a wish list.

**Board question:** Do our criticality labels actually change controls and investment—or are they just labels in a spreadsheet?

---

### Relevant Sources

1. **Cybersecurity Incident** — NIST CSRC Glossary — [https://csrc.nist.gov/glossary/term/cybersecurity_incident](https://csrc.nist.gov/glossary/term/cybersecurity_incident)
2. **Emergency Preparedness and Response: Getting Started** — OSHA — [https://www.osha.gov/emergency-preparedness](https://www.osha.gov/emergency-preparedness)
3. **Regulation (EU) 2022/2554 (DORA)** — EUR-Lex — [https://eur-lex.europa.eu/eli/reg/2022/2554/oj](https://eur-lex.europa.eu/eli/reg/2022/2554/oj)

**If a capability is critical, the investment, the tests and the escalation rights should be visibly different from everything else.** That is a board design job, not a colour on a heat map. [Contact me](https://goldmanmalka.com/about).
