The teams that handle cyber incidents badly are rarely incompetent. They are usually capable, senior, well-intentioned people who, put in a room together under time pressure with incomplete information, produce decisions that none of them would have made alone.
This is not a character flaw. It is a predictable property of how groups decide under stress, and it has been studied for decades in aviation, medicine and emergency response. Cyber incidents happen to combine almost every condition known to degrade group decision-making.
Understanding which failures are likely is what lets you design against them.
Why cyber incidents are unusually hard
Most crisis research concerns events that announce themselves. A fire is obviously a fire. Cyber incidents are different in four specific ways.
They begin ambiguously. There is rarely a moment when a system says you have been breached. There is a slow accumulation of oddities, each individually explicable. The first decision is not what to do; it is whether anything is actually happening.
The evidence changes underneath you. What you believed at 10am is often wrong by noon, not because anyone lied but because investigation revealed more. Groups are poor at revising a shared picture once they have formed one.
Nobody in the room owns the whole problem. Technical, legal, commercial and reputational consequences all matter, and they sit with different people, none of whom can assess the others' domain.
The clock is regulatory as well as operational. UK GDPR gives 72 hours from becoming aware of a personal data breach. That creates a decision, when did we become aware, that is simultaneously technical, legal and consequential, and it is frequently nobody's explicit job.
Six ways capable teams go wrong
1. Nobody declares the incident
The most common and most expensive failure. Everyone in the room is behaving reasonably, investigating, gathering information, waiting for confirmation, and hours pass without anyone saying: this is an incident, we are now in response mode, I am in charge.
The cause is usually that declaration feels like an escalation with career consequences. Declaring is visible, and if it turns out to be nothing, the person who declared looks alarmist. So the group hovers, and hovering feels like prudence.
Design against it: make declaration cheap and explicitly reversible. Give it a named owner by role, not by seniority, and write down that a stood-down incident is a good outcome rather than a false alarm to be embarrassed about. The measure worth tracking in an exercise is time from first indicator to declaration.
2. The most senior person speaks first
Once a chief executive offers a view, the range of opinions in the room narrows sharply. Junior participants revise their assessments toward the senior one, and the group mistakes that convergence for agreement.
This is well documented in aviation, where it contributed to crashes serious enough to produce an entire discipline, Crew Resource Management, built largely to make it safe for a first officer to contradict a captain. Cyber incident rooms have no equivalent discipline and frequently more deference.
Design against it: the person chairing should ask for assessments before giving one, and should ask the most junior technical person first. If you do one thing from this article, do this one.
3. Everybody assumes somebody else is acting
Diffusion of responsibility scales with the size of the room. In a call with fifteen people, the probability that any given action has an owner falls, because each participant reasonably assumes someone better placed is handling it. Regulatory assessment is the classic victim: everyone believes legal is on it, and legal believes they will be told when there is something to assess.
Design against it: keep the decision-making group under about twelve, and close every action with an explicit name and time said out loud. "Someone should check whether this is notifiable" is not an action. "Priya, by 3pm" is.
4. The group defends its first theory
Once a group commits to an explanation, contradicting evidence tends to be absorbed rather than allowed to overturn it. If the working theory is a phishing compromise, indicators pointing at a supplier get filed as secondary rather than treated as a reason to reconsider.
This costs most when the initial theory is nearly right, because near-misses are the hardest to dislodge.
Design against it: schedule a deliberate challenge. Twenty or thirty minutes in, someone is assigned to argue that the current theory is wrong. Making it a role rather than a personality means the person doing it is performing a duty rather than being difficult.
5. Sunk cost keeps a failing plan alive
Two hours into a recovery attempt that is not working, the group has invested effort, reported progress to a board, and possibly told customers a timescale. Abandoning it means admitting the two hours were wasted, in public.
So the plan continues past the point where a fresh observer would stop it.
Design against it: set decision points in advance. "If we have not restored by 4pm, we switch to the alternative approach" is a commitment made while thinking clearly, and it protects the group from having to make the humiliating call in the moment.
6. Communications wait for certainty that never arrives
The instinct to say nothing until the facts are established is honourable and usually wrong. Certainty arrives days later. Customers, staff and journalists fill the silence long before that.
Worse, the delay is often framed as a communications decision when it is really a decision about whether the organisation can tolerate saying "we do not yet know".
Design against it: pre-agree what can be said at low confidence, and give someone explicit authority to say it without waiting for a full picture. Draft the holding statement before you need it.
The two questions that reveal everything
If you want to know how a team will perform, you do not need a full exercise to start with. Two questions asked around a table will tell you a great deal.
"Who declares an incident, by name, and what happens at 11pm on a Friday?" Hesitation here predicts hours of hovering in a real event.
"Who decides we tell customers, and can they do it without the chief executive?" If the answer is that it goes to the chief executive, ask what happens when the chief executive is on a flight.
Why this is exercised rather than trained
None of these failures respond to being explained. Everyone reading this already agrees that nobody should defer to the most senior voice, and will do it anyway at 9pm with a regulator's clock running.
The reason is that these are not knowledge failures. They are what people do under load, when the cost of being wrong is personal and the information is incomplete. You cannot read your way out of them; you can only build the habits that interrupt them, and habits need rehearsal.
That is the entire argument for exercising rather than briefing. An exercise puts a real group under artificial pressure and lets them discover, safely, that nobody declared the incident for forty minutes. Being told that groups are slow to declare changes nothing. Watching your own team take forty minutes changes a great deal.
What to measure
If the failures above are the target, the measures follow directly:
- Time to declaration. First indicator to someone formally saying this is an incident.
- Time to first material decision. Not a decision to gather more information; a decision that changed what happened next.
- Decisions with named owners. What proportion closed with a name and a time rather than a general intention.
- Time to regulatory assessment. Did anyone ask whether the 72-hour clock had started, and when.
- Challenge events. Did anyone contradict the prevailing theory, and was it acted on.
These are properties of a group, not of individuals, which matters for how you report them. The finding is never that a person performed poorly. It is that the room had no mechanism to interrupt a predictable failure.
The uncomfortable conclusion
A team that has rehearsed these decisions is not smarter than one that has not. It is simply a team where somebody has already discovered, in a room where nothing was at stake, that declaring an incident felt awkward and nobody wanted to do it.
That discovery is most of the value. Everything after it is process.