At 02:13, an administrator account begins exporting customer data.
This is not “an IT ticket.” It may be a business emergency.
Not every cyber occurrence is. That distinction is the whole point.
NIST defines a cybersecurity incident as an occurrence that actually or imminently jeopardizes the confidentiality, integrity or availability of information or systems, or threatens relevant law or security policy. Notice the threshold: actual or imminent jeopardy—not merely an unusual log entry. A security event is any observable occurrence. A contained phishing email and an active privileged-account compromise are not equivalent.
When the incident threatens a critical service, trusted data or the ability to operate, the board should expect a disciplined emergency response—not a queue position in the help desk.
Why This Crosses Into Emergency
Emergency is not a mood. It is a situation that requires immediate, coordinated, non-routine action because a serious threat is actual or imminent.
A material cyber incident often qualifies for reasons boards already understand in other domains:
- The threat may still be active.
- Delay may increase the harm.
- Evidence can disappear.
- Customers, operations and legal obligations may be affected.
- Decisions may be required before all facts are known.
- Technical, legal, communications, operations and executive teams must coordinate.
That is the opposite of a routine client document awaiting signature. The document can be important. It can even be urgent. Normal governance can still handle it. The 02:13 export cannot wait for the next committee without making the outcome worse.
Critical still matters here. A system can be critical while running normally. The emergency is the situation: actual or imminent jeopardy to that system, its data, or the business it supports. Do not collapse the words. A critical payments platform that is healthy is a resilience problem. A critical payments platform being emptied by a stolen admin account is an emergency.
What the Board Is For at 02:13
The board’s role is not to direct forensic commands. It is to ensure that authority, escalation, communications and risk decisions work under pressure.
That means, in advance: named people who can isolate a critical system; a path that does not require a quorum at dawn; legal and communications in the same room as technology; a record of decisions; and a clear line between “we do not know yet” and “we are waiting because waiting is comfortable.”
If the only person who can pull the plug is in a meeting on Tuesday, you do not have an incident response plan. You have a calendar.
Board question: Who can isolate a critical system at 02:13 without waiting for the next committee meeting?
Relevant Sources
- Cybersecurity Incident — NIST CSRC Glossary — https://csrc.nist.gov/glossary/term/cybersecurity_incident
- Event — NIST CSRC Glossary — https://csrc.nist.gov/glossary/term/event
- Incident Response Recommendations and Considerations for Computer Security Incident Response Teams (CSIRTs) — NIST SP 800-61 Rev. 3 — https://csrc.nist.gov/pubs/sp/800/61/r3/final
- Regulation (EU) 2022/2554 (DORA), Article 17 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2022/2554/oj
I advise boards on incident authority that works at 02:13: escalation, isolation rights, and risk decisions under incomplete facts. Contact me.
