## Purpose

This matrix defines who has authority to make important decisions during a cybersecurity incident.

The objective is to avoid delays and confusion when urgent decisions affect systems, money, customers, employees, or legal obligations.

Roles should be adapted to the company.

## Decision Authority

|Decision|Primary Authority|Backup Authority|Technical / Legal Input Required|
|---|---|---|---|
|Activate Incident Response Plan||||
|Declare Critical Incident||||
|Disable user account||||
|Suspend administrator account||||
|Isolate endpoint||||
|Shut down server or service||||
|Block internet access||||
|Disable vendor access||||
|Take website offline||||
|Protect or isolate backups||||
|Engage incident response provider||||
|Notify cyber insurer||||
|Notify legal counsel||||
|Contact bank or payment provider||||
|Approve emergency cybersecurity spending||||
|Contact law enforcement||||
|Notify customers||||
|Notify vendors||||
|Notify regulator||||
|Make public statement||||
|Engage with attacker||||
|Consider ransom or extortion decision||||
|Approve restoration||||
|Return critical system to service||||
|Accept residual risk||||
|Close incident||||

## Emergency Authority

**If the primary decision maker cannot be reached:**

Backup authority: ____________________

Emergency spending limit: ____________________

Emergency technical authority: ____________________

## Important Principles

Technical personnel may need authority to take immediate protective action where delay would materially increase damage.

High-impact business decisions should involve appropriate leadership.

Legal, regulatory, insurance, employment, or privacy decisions should involve appropriate specialists.

Attacker payment or negotiation decisions should never be left solely to technical staff.

## Review

Matrix owner: ____________________

Last reviewed: ____________________

Next review: ____________________

## Practical Rule

Decide who can make difficult incident decisions before the emergency begins.
