Incident Decision Authority Matrix

Purpose

This matrix defines who has authority to make important decisions during a cybersecurity incident.

The objective is to avoid delays and confusion when urgent decisions affect systems, money, customers, employees, or legal obligations.

Roles should be adapted to the company.

Decision Authority

Decision Primary Authority Backup Authority Technical / Legal Input Required
Activate Incident Response Plan      
Declare Critical Incident      
Disable user account      
Suspend administrator account      
Isolate endpoint      
Shut down server or service      
Block internet access      
Disable vendor access      
Take website offline      
Protect or isolate backups      
Engage incident response provider      
Notify cyber insurer      
Notify legal counsel      
Contact bank or payment provider      
Approve emergency cybersecurity spending      
Contact law enforcement      
Notify customers      
Notify vendors      
Notify regulator      
Make public statement      
Engage with attacker      
Consider ransom or extortion decision      
Approve restoration      
Return critical system to service      
Accept residual risk      
Close incident      

Emergency Authority

If the primary decision maker cannot be reached:

Backup authority: ____________________

Emergency spending limit: ____________________

Emergency technical authority: ____________________

Important Principles

Technical personnel may need authority to take immediate protective action where delay would materially increase damage.

High-impact business decisions should involve appropriate leadership.

Legal, regulatory, insurance, employment, or privacy decisions should involve appropriate specialists.

Attacker payment or negotiation decisions should never be left solely to technical staff.

Review

Matrix owner: ____________________

Last reviewed: ____________________

Next review: ____________________

Practical Rule

Decide who can make difficult incident decisions before the emergency begins.