Incident Decision Authority Matrix
Purpose
This matrix defines who has authority to make important decisions during a cybersecurity incident.
The objective is to avoid delays and confusion when urgent decisions affect systems, money, customers, employees, or legal obligations.
Roles should be adapted to the company.
Decision Authority
Emergency Authority
If the primary decision maker cannot be reached:
Backup authority: ____________________
Emergency spending limit: ____________________
Emergency technical authority: ____________________
Important Principles
Technical personnel may need authority to take immediate protective action where delay would materially increase damage.
High-impact business decisions should involve appropriate leadership.
Legal, regulatory, insurance, employment, or privacy decisions should involve appropriate specialists.
Attacker payment or negotiation decisions should never be left solely to technical staff.
Review
Matrix owner: ____________________
Last reviewed: ____________________
Next review: ____________________
Practical Rule
Decide who can make difficult incident decisions before the emergency begins.