SECURETHEORY Advisors
AVAILABLE FOR ENGAGEMENT Book a briefing
security culture / incident_management.txt
04
/ key lessons of incident management

What dozens of board-reported incidents taught me

I've led incident response across dozens of board-reported incidents. The technical response matters — but these are the lessons that actually preserve trust when something goes wrong.

lesson_01_communications.log
01

Cadence matters as much as the technical response

Enterprise customers can absorb a security incident. They do not want to be surprised, misled, or managed with generic PR language. Transparency, frequency, and accuracy are the things that preserve trust when something goes wrong.

lesson_02_alignment.log
02

Align leaders and the board before the incident

The responsibilities of leaders should be established clearly, and alignment between management and the board built before an incident — not during it.

The best board meeting I ever ran was one where I said no more than 20 words. I introduced two leading experts on malware incidents, and a 30-minute session ran for 90 minutes. The issue: the board did not agree with management's theory of handling ransomware.

lesson_03_psych_safety.log
03

Bad news travels fast only when experts trust the execs to let them work

Psychological safety is the most important marker of a high-performing team, and it shows up in spades during a security incident.

The proudest moment of my CISO life was when my lead responder kicked the CTO out of an incident room because he was confusing people by tasking them. Did I pay a penance for that? Absolutely — but it was so worth it. And we managed the incident beautifully.

← [03] · PREV
Prioritizing Investments & Speed
NEXT · [05] →
Success Metrics & KPIs