The most expensive sentence in a cyber crisis is often: “We need more information.”
Sometimes that sentence is responsible. Often, it is where trusttime begins to bleed: the critical window between discovering an incident and demonstrating to stakeholders that leadership is in control. Leaders wait for certainty, legal for scope, security for confirmation, communications for approved language and the board for assurance. Customers, regulators and journalists, however, do not wait at all.
This blog post gives business leaders three practical ways to shorten trusttime before a crisis forces the issue: map the decisions that matter, preauthorize predictable actions and audit where decision speed breaks down.
Consider Change Healthcare. In February 2024, a ransomware attack disrupted one of the most important payment and claims-processing networks in the US health care system. Andrew Witty, then chief executive of parent company UnitedHealth Group, told Congress the attack caused “incredible disruption” across the healthcare system, including pharmacists having to submit claims manually and a rural family medicine practice struggling to make payroll.
The picture worsened as the investigation unfolded. On 12 February, attackers used compromised credentials on a Change Healthcare Citrix remote-access portal that did not have multifactor authentication; nine days later, ransomware was deployed. UnitedHealth disconnected affected systems, worked to restore payment flows and Witty later said the decision to pay a ransom was his. Press reporting put the payment at US$22 million.
The scale kept growing as Change Healthcare later notified the US Department of Health and Human Services that approximately 192.7 million individuals had been impacted. Witty also told Congress that, as of 26 April, 2024, UnitedHealth had advanced more than US$6.5 billion in accelerated payments and no-interest, no-fee loans to thousands of providers.
This is the leadership problem hidden inside many cyber incidents: the first crisis is technical; the second is decisional.
I introduced trusttime in an earlier ISACA blog post as the speed at which organizations reassure people when systems bend and applied it to crisis readiness in the first part of this series. In a cyber crisis, leaders protect that window through decisions made before certainty arrives. IBM’s 2026 Cost of a Data Breach Report gives that point a sharper edge: global breach costs reached a record high, with the increase driven by higher detection, escalation and lost business costs.
That pressure is compounded by regulatory clocks. In the US, public companies must disclose material cybersecurity incidents within four business days after determining materiality. In the EU, NIS2 can require an early warning within 24 hours for significant incidents where the regime applies.
The practical implication is simple: leaders shorten trusttime by designing decisions before pressure arrives. So, how organizations achieve this?
Step 1: Map your crisis decision architecture
Crisis readiness tells you whether leaders know their roles. Decision architecture goes one layer deeper: it defines the operational, legal, financial and communications decisions that must move in the first 24 to 72 hours of a serious cyber incident.
Bring together the CEO, CISO, General Counsel, COO, CFO and Communications Lead. Start with the practical calls that determine whether the organization creates visible control or loses another hour in debate, not only the headline decisions a regulator or board will eventually force.
Use a decision architecture map:
| Decision | Owner | Trigger | Evidence threshold | Maximum decision time | Escalation path |
|---|---|---|---|---|---|
|
Disconnect a compromised system or supplier |
COO / CISO |
Active compromise or containment need |
Threat status, operational impact, recovery path |
Immediate decision window |
CEO |
|
Engage law enforcement |
General Counsel |
Confirmed extortion, criminal access or data theft |
Known facts, indicators, legal risk |
Within agreed hours |
CEO |
|
Approve emergency cyber spend |
CFO / CEO |
Response need exceeds existing authority |
Vendor estimate, urgency, business impact |
Same day |
Board if threshold exceeded |
|
Set ransom negotiation posture |
CEO / General Counsel |
Extortion demand received |
Legal advice, data exposure, operational impact, law-enforcement input |
Within agreed hours |
Board or crisis committee |
By the end of the session, leaders should have one page that answers three questions:
- Who decides?
- What evidence is enough?
- When does delay become escalation?
The map forces difficult conversations before the crisis asks them in public. Who can disconnect a supplier if the service is still generating revenue? Who can approve emergency spend at 2 a.m.? Who sets the ransom negotiation posture if operations is under pressure and legal is still assessing risk? These questions may be uncomfortable in a workshop, but they are brutal during a live incident.
A decision map earns its place only if it removes ambiguity before ambiguity becomes visible. Once ownership, evidence and escalation thresholds are clear, the next task is to remove predictable approval delays.
Step 2: Preauthorize high-frequency crisis decisions
Some crisis decisions are predictable and should not need fresh permission during the first hour.
Build a standing authority register for actions that repeatedly appear in serious incidents, including:
- Engaging breach counsel and activating forensic support
- Notifying the board chair and contacting law enforcement
- Issuing a holding statement and opening a customer support channel
- Suspending a supplier connection or authorizing emergency spend
Use this structure:
| Action | Preauthorized trigger | Who may act | Boundary | Who must be informed |
|---|---|---|---|---|
|
Engage external counsel |
Suspected material breach |
General Counsel |
Approved panel / agreed budget |
CEO |
|
Activate forensic support |
Confirmed compromise indicators |
CISO |
Approved provider list |
COO/Legal |
|
Issue holding statement |
Public inquiry or material service impact |
Communications Lead |
Preapproved language only |
CEO / Legal |
|
Notify board chair |
Potential material impact |
CEO |
Initial briefing only |
Full board if confirmed |
|
Open provider or customer support channel |
Service disruption affecting users |
COO / Communications Lead |
Approved scripts and escalation route |
CEO/Legal |
The output is not a policy document. It is a permission structure.
Preauthorization prevents leaders from spending the first critical hours asking whether they are allowed to do the things everyone already knows will be necessary. It protects judgment from being trapped in approval chains while the clock is already running.
This is where many organizations lose trusttime: the team is active and people are working hard but the work is stuck behind authority questions that should have been settled months earlier.
By the end of this step, the leadership team should know which actions can begin immediately, which require escalation and which boundaries cannot be crossed without executive approval. Once that authority is clear, the next question is whether those decisions actually move at the speed the crisis demands.
Step 3: Run a decision-speed audit
After every serious incident, near miss or executive tabletop, audit the speed of decisions, not only the quality of technical response.
The US Cybersecurity and Infrastructure Security Agency (CISA) frames exercises as practical mechanisms to examine plans and procedures, identify improvement areas and inform future planning. NIST’s updated incident-response guidance, SP 800-61 Revision 3, also places incident response inside broader cybersecurity risk management, rather than treating it as an isolated technical ritual.
For executives, that leads to a sharper question: where did decision-making slow down?
Use a trusttime loss register. The examples below are illustrative and should be tailored to your regulatory obligations, operating model and risk profile.
| Decision point | Expected time | Actual time | Delay cause | Trusttime lost | Structural fix |
|---|---|---|---|---|---|
|
Escalate to CEO |
1 hour |
4 hours |
Unclear threshold |
3 hours |
Define trigger |
|
Notify board chair |
2 hours |
8 hours |
Owner unavailable |
6 hours |
Name deputy |
|
Issue holding statement |
2 hours |
7 hours |
Legal / Comms disagreement |
5 hours |
Preapproved language |
|
Activate forensics |
Immediate |
Next day |
Budget approval |
1 day |
Standing authority |
|
Decide supplier disconnection |
Immediate window |
3 hours |
Unclear business owner |
3 hours |
Assign COO/CISO trigger |
This turns the usual post-incident question from “Did we respond?” into “Where did trusttime disappear?”
The output should be a short decision-speed report covering:
- The slowest decisions
- The cause of delay
- The executive owner
- The structural fix
- The retest date
If the same delay appears twice, it is no longer a lesson learned. It is a governance weakness.
That audit also changes the quality of board reporting. Instead of telling directors that the incident response plan was activated, management can show where decisions moved, where they stalled and what changed before the next test.
Trusttime is protected before the breach, in the quiet decisions leaders make about authority, evidence and speed.