Can your leadership team answer these critical questions the same way?

27th August 2026 | Fellsway Can your leadership team answer these critical questions the same way?

When an incident threatens your business, the way your leadership team responds makes all the difference in how quickly you recover.

All on the same page, working collaboratively? You handle the incident cleanly, with everyone knowing how to act.

COO recommending one thing, and CFO another? There’ll be a lot of confusion before any decision is made.


How would your business respond? You can find out now. 

Take the questions a cyber incident will force on your leadership team, put them to your COO, your CFO, and your general counsel in separate rooms, and compare the answers.

Your incident response plan covers the technical response. This is the part typically left to whoever happens to be in the room.

When the three answers line up and the process is validated, the team has settled it and the plan holds under pressure. 

The gaps are the divergences: every question where the leadership team disagrees is a decision no one has made, and an incident is the worst place to make it for the first time.

None of these questions has a single, agreed owner. They cut across operations, finance, and legal at the same moment, which is why three capable executives will answer them three different ways unless they’ve agreed the answers first. 

1. Who can halt operations, and who decides when it can restart?

On paper this is the COO’s call. Ask around and it rarely comes back clean.

Your COO may assume the authority is theirs. But your IT lead, who has already pulled the affected systems offline, may treat that call as effectively made, and a site leader could be holding a critical service open while corporate sorts it out. 

All of them are being reasonable, and while they reconcile who owns the stop, the damage keeps spreading to systems that were still reachable.

The second half of the question splits the room too: how long can each part of the business run before it has to stop? That limit is rarely written down, so you get three guesses where you need one agreed number.

And then, who decides when a system, process or production line can restart (when its integrity may still be in doubt)? 

2. Who can approve emergency spending, and up to what limit?

This one lands on the CFO, and the disagreement shows up in the number.

Ask the CFO what can be authorized for forensics, recovery vendors, and overtime outside the normal chain, and you get a considered figure. 

Put the same question to the COO, framed as who would be committing that money in the first hours, and a different name comes back, or a shrug. 

And what about paying a ransom? Do you? Up to what figure? What is it that drives that decision?

Crisis spending limits are almost never agreed ahead of time, so the CFO ends up approving major spend in real time, on incomplete facts, against a loss estimate that keeps moving.

Set that authority too low and recovery stalls while approvals climb the chain; leave it undefined and the decision freezes at the moment speed counts most.

3. Who decides which notifications are made, to whom, and when?

The general counsel often owns this, and it’s where split knowledge does the most damage.

They can list the regulatory and insurer obligations. But what your counsel may not know is that a major customer’s contract carries a disclosure clause with a deadline that started running the day it was signed, not the day you found the breach. Sales signed that contract. Operations agreed. Legal has to answer for it. Until the two compare notes, the obligation sits unseen.

These questions and more divide teams reliably. You need to know what you’re telling customers, suppliers, contractors, insurers, and regulatory bodies. Who tells them, and by when? 

And does outside counsel or the insurer get the first call? That order carries weight, since reaching counsel first can protect privilege over everything that follows.

4. Who approves the first public word, and is it already drafted?

This is the question with the weakest owner, which is why it goes wrong the most.

Communications may assume they draft and send it. Legal expects to review anything before it leaves the building, and the CEO expects final sign-off to run through them. 

Often no one has drafted a word, so the first thing customers see is either silence or a version that leaked before anyone approved it.

Ask each leader who approves that first statement and you learn quickly whether you have a path or a vacuum.

Different answers are the finding

Because the questions are identical, the divergence means something. When your leaders name different owners, or give different answers to the same question, that disagreement is already sitting in your plan, waiting for an incident to expose it. 

One executive assumes legal owns the disclosure call, legal assumes it’s waiting on the CEO, and the notification goes unmade while the clock runs.

A tested Executive Readiness playbook replaces those splits with one agreed set of answers. 

The leadership team settles decision authority by severity, escalation thresholds, and notification triggers, drafts the holding statements in advance, then runs the whole thing against a realistic scenario to find what still doesn’t hold.

One agreed answer, not four good instincts

Four capable leaders with four reasonable instincts still leave you exposed, because in the moment those instincts pull in different directions. What holds is one answer they all give without hesitating, settled together before the day it counts.

Executive Readiness is how we build that: an executive crisis management and incident response playbook, developed with your leadership team and tested in a facilitated exercise, so the questions above already have answers when they land for real.

You can find out how your own leadership team would answer. 

Book a call and we’ll run the exercise with them.

Latest Cyber and AI Insights

Improve your readiness, combat disruption

Get the latest cyber and AI insights to help your organization stay compliant, resilient and ready for ever-evolving threats and challenges.

Because while risk is constant, ready is a choice.

Can your leadership team answer these critical questions the same way?

Can your leadership team answer these critical questions the same way?

When an incident threatens your business, the way your leadership team responds makes all the difference in how...

Read more
Your incident response plan was written for IT. So what guides your leadership decisions?

Your incident response plan was written for IT. So what guides your leadership decisions?

The ransom note is on the screen and the clock is running. Your IT team knows what the next hour looks like:...

Read more
How to Build an AI Use Case Inventory for Your Manufacturing Operation

How to Build an AI Use Case Inventory for Your Manufacturing Operation

You've been told to get AI governance in place. Sooner or later every manufacturer lands here, the early movers...

Read more