# A Cyber Incident Is a Business Emergency

Date: 2026-10-05

At 02:13, an administrator account begins exporting customer data.

This is not “an IT ticket.” It may be a business emergency.

<!--more-->

Not every cyber occurrence is. That distinction is the whole point.

NIST defines a **cybersecurity incident** as an occurrence that actually or imminently jeopardizes the confidentiality, integrity or availability of information or systems, or threatens relevant law or security policy. Notice the threshold: actual or imminent jeopardy—not merely an unusual log entry. A security *event* is any observable occurrence. A contained phishing email and an active privileged-account compromise are not equivalent.

When the incident threatens a critical service, trusted data or the ability to operate, the board should expect a disciplined emergency response—not a queue position in the help desk.

## Why This Crosses Into Emergency

**Emergency** is not a mood. It is a situation that requires immediate, coordinated, non-routine action because a serious threat is actual or imminent.

A material cyber incident often qualifies for reasons boards already understand in other domains:

- The threat may still be active.
- Delay may increase the harm.
- Evidence can disappear.
- Customers, operations and legal obligations may be affected.
- Decisions may be required before all facts are known.
- Technical, legal, communications, operations and executive teams must coordinate.

That is the opposite of a routine client document awaiting signature. The document can be important. It can even be **urgent**. Normal governance can still handle it. The 02:13 export cannot wait for the next committee without making the outcome worse.

**Critical** still matters here. A system can be critical while running normally. The emergency is the situation: actual or imminent jeopardy to that system, its data, or the business it supports. Do not collapse the words. A critical payments platform that is healthy is a resilience problem. A critical payments platform being emptied by a stolen admin account is an emergency.

## What the Board Is For at 02:13

The board’s role is not to direct forensic commands. It is to ensure that authority, escalation, communications and risk decisions work under pressure.

That means, in advance: named people who can isolate a critical system; a path that does not require a quorum at dawn; legal and communications in the same room as technology; a record of decisions; and a clear line between “we do not know yet” and “we are waiting because waiting is comfortable.”

If the only person who can pull the plug is in a meeting on Tuesday, you do not have an incident response plan. You have a calendar.

**Board question:** Who can isolate a critical system at 02:13 without waiting for the next committee meeting?

---

### Relevant Sources

1. **Cybersecurity Incident** — NIST CSRC Glossary — [https://csrc.nist.gov/glossary/term/cybersecurity_incident](https://csrc.nist.gov/glossary/term/cybersecurity_incident)
2. **Event** — NIST CSRC Glossary — [https://csrc.nist.gov/glossary/term/event](https://csrc.nist.gov/glossary/term/event)
3. **Incident Response Recommendations and Considerations for Computer Security Incident Response Teams (CSIRTs)** — NIST SP 800-61 Rev. 3 — [https://csrc.nist.gov/pubs/sp/800/61/r3/final](https://csrc.nist.gov/pubs/sp/800/61/r3/final)
4. **Regulation (EU) 2022/2554 (DORA), Article 17** — EUR-Lex — [https://eur-lex.europa.eu/eli/reg/2022/2554/oj](https://eur-lex.europa.eu/eli/reg/2022/2554/oj)

**I advise boards on incident authority that works at 02:13: escalation, isolation rights, and risk decisions under incomplete facts.** [Contact me](https://goldmanmalka.com/about).
