A Cyber Incident Is a Business Emergency

·

At 02:13, an administrator account begins exporting customer data.

This is not “an IT ticket.” It may be a business emergency.

Not every cyber occurrence is. That distinction is the whole point.

NIST defines a cybersecurity incident as an occurrence that actually or imminently jeopardizes the confidentiality, integrity or availability of information or systems, or threatens relevant law or security policy. Notice the threshold: actual or imminent jeopardy—not merely an unusual log entry. A security event is any observable occurrence. A contained phishing email and an active privileged-account compromise are not equivalent.

When the incident threatens a critical service, trusted data or the ability to operate, the board should expect a disciplined emergency response—not a queue position in the help desk.

Why This Crosses Into Emergency

Emergency is not a mood. It is a situation that requires immediate, coordinated, non-routine action because a serious threat is actual or imminent.

A material cyber incident often qualifies for reasons boards already understand in other domains:

  • The threat may still be active.
  • Delay may increase the harm.
  • Evidence can disappear.
  • Customers, operations and legal obligations may be affected.
  • Decisions may be required before all facts are known.
  • Technical, legal, communications, operations and executive teams must coordinate.

That is the opposite of a routine client document awaiting signature. The document can be important. It can even be urgent. Normal governance can still handle it. The 02:13 export cannot wait for the next committee without making the outcome worse.

Critical still matters here. A system can be critical while running normally. The emergency is the situation: actual or imminent jeopardy to that system, its data, or the business it supports. Do not collapse the words. A critical payments platform that is healthy is a resilience problem. A critical payments platform being emptied by a stolen admin account is an emergency.

What the Board Is For at 02:13

The board’s role is not to direct forensic commands. It is to ensure that authority, escalation, communications and risk decisions work under pressure.

That means, in advance: named people who can isolate a critical system; a path that does not require a quorum at dawn; legal and communications in the same room as technology; a record of decisions; and a clear line between “we do not know yet” and “we are waiting because waiting is comfortable.”

If the only person who can pull the plug is in a meeting on Tuesday, you do not have an incident response plan. You have a calendar.

Board question: Who can isolate a critical system at 02:13 without waiting for the next committee meeting?


Relevant Sources

  1. Cybersecurity Incident — NIST CSRC Glossary — https://csrc.nist.gov/glossary/term/cybersecurity_incident
  2. Event — NIST CSRC Glossary — https://csrc.nist.gov/glossary/term/event
  3. Incident Response Recommendations and Considerations for Computer Security Incident Response Teams (CSIRTs) — NIST SP 800-61 Rev. 3 — https://csrc.nist.gov/pubs/sp/800/61/r3/final
  4. Regulation (EU) 2022/2554 (DORA), Article 17 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2022/2554/oj

I advise boards on incident authority that works at 02:13: escalation, isolation rights, and risk decisions under incomplete facts. Contact me.