How to Create a Cyber Crisis Management Plan Before an Attack Happens
When a cyber incident begins, the first few minutes are often the most chaotic.
The security team is investigating alerts. IT is checking backups. Executives want updates. Legal is asking about regulatory obligations. Communications is preparing holding statements. Customer support is fielding questions. Someone has started a Microsoft Teams call with 40 people talking over each other.
Everyone is working. But is anyone actually coordinating?
This is where many organizations discover they don't have an Incident Commander. Contrary to popular belief, the Incident Commander isn't necessarily the most technical person in the room. They're the person responsible for bringing order to the chaos—keeping teams aligned, decisions moving, and the organization focused on the priorities that matter most.
As cyber incidents become increasingly complex and business-wide, Incident Command is quickly becoming one of the most important disciplines in modern cyber resilience.
What Is an Incident Commander?
An Incident Commander is the individual responsible for coordinating an organization's response to a cyber incident from beginning to end.
Their primary responsibility isn't performing forensic investigations, restoring servers, or hunting for malware.
Instead, they ensure the right people are working on the right priorities, decisions are made quickly, and everyone has a shared understanding of what's happening.
Think of the Incident Commander as the conductor of an orchestra. They don't play every instrument. They ensure every musician is working together to perform as one.
During a cyber incident, that orchestra may include:
- Security Operations (SOC)
- Incident Response
- IT Operations
- Cloud Infrastructure
- Legal
- Human Resources
- Executive Leadership
- Communications
- Compliance
- Customer Success
- Third-party responders
Without someone coordinating these groups, even highly skilled teams can become fragmented, duplicate work, or miss critical decisions.
Where Incident Command Comes From
The concept of Incident Command didn't originate in cybersecurity.
It was developed decades ago by emergency response organizations—including fire services, emergency management agencies, and disaster response teams—to coordinate large, complex events involving multiple organizations and stakeholders.
Their challenge was remarkably similar to today's cyber incidents:
- Multiple teams responding simultaneously
- Information changing rapidly
- Critical decisions needing immediate attention
- Resources requiring coordination
- Clear leadership essential for success
The Incident Command System (ICS) introduced a standardized approach for organizing people, assigning responsibilities, and maintaining situational awareness during emergencies.
As cyber attacks evolved from isolated technical problems into business-wide crises, many organizations adopted these same principles. Today, Incident Command has become a cybersecurity best practice because it recognizes an important reality:
A cyber incident isn't just an IT problem. It's an organizational event that requires coordinated leadership across the entire business.
Why Traditional Incident Response Often Breaks Down
Most organizations have an incident response plan. Far fewer have a defined command structure.
Without Incident Command, responses often become reactive instead of coordinated. It usually starts innocently enough.
Someone creates a Teams meeting…. Thirty people join.
Technical investigators are explaining malware behavior while executives ask about customer impact. Legal needs information for regulators. Communications wants approval on a draft statement. Someone is updating a spreadsheet. Others are sending direct messages trying to clarify conflicting information.
The more people involved, the harder it becomes to maintain focus.
Common challenges include:
- Multiple conversations happening simultaneously
- Conflicting priorities across teams
- No clear decision-making authority
- Duplicate or forgotten tasks
- Confusion around ownership
- Inconsistent status updates
- Difficulty maintaining an accurate operational picture
The result isn't a lack of effort. It's a lack of coordination. Incident Command introduces structure without slowing the response.
The Core Responsibilities of an Incident Commander
So what does an Incident Commander actually do during a cyber incident? While responsibilities vary by organization, most Incident Commanders focus on six core functions.
1. Establish Incident Objectives
Every response begins with a clear understanding of the organization's immediate priorities. Those objectives may include:
- Containing the attack
- Protecting critical systems
- Restoring business operations
- Preserving evidence
- Meeting regulatory obligations
- Protecting customers
Rather than allowing dozens of independent priorities to emerge, the Incident Commander helps align the entire response around shared objectives.
2. Coordinate Technical Response Teams
Modern cyber incidents involve specialists across multiple disciplines.
- Security analysts investigate.
- Infrastructure teams restore systems.
- Cloud engineers evaluate environments.
- Identity teams review compromised accounts.
- External incident response partners may join the effort.
The Incident Commander isn't directing their technical work—they're ensuring those teams remain coordinated, informed, and working toward common goals.
3. Coordinate Business Stakeholders
A cyber incident affects far more than IT. Executive leaders need timely updates. Legal may need to assess disclosure obligations. Communications prepares internal and external messaging. HR supports employees. Customer-facing teams manage inbound inquiries.
The Incident Commander acts as the central point of coordination, ensuring every stakeholder receives the information they need without overwhelming technical responders.
4. Manage Communications
One of the Incident Commander's most important responsibilities is ensuring communication remains clear, accurate, and consistent. This includes:
- Executive updates
- Internal team coordination
- Customer communications
- Regulatory notifications
- Board reporting
- Third-party coordination
Communication isn't just about sharing information—it's about ensuring everyone is working from the same understanding of the situation.
If you're developing your organization's communications strategy, our Cyber Crisis Communications Playbook explores how to prepare messaging before an incident occurs.
5. Facilitate Decisions
Contrary to popular belief, Incident Commanders don't make every decision. Instead, they ensure decisions are made by the appropriate people—and made quickly. Questions like:
- Should affected systems be disconnected?
- Do we activate business continuity plans?
- When do we notify customers?
- Should external responders be engaged?
- Do we declare a business crisis?
The Incident Commander keeps these decisions moving while documenting outcomes and ensuring accountability.
6. Maintain Situational Awareness
Perhaps the Incident Commander's most valuable responsibility is maintaining a complete picture of the incident. They continually ask questions like:
- What do we know?
- What don't we know?
- What has changed?
- What are the biggest risks?
- What actions remain open?
- What happens next?
This shared operational picture helps prevent confusion and keeps every team aligned as the incident evolves.
Why Out-of-Band Communications Matter
An Incident Commander can't coordinate a response if the organization's communication systems are unavailable. Unfortunately, that's exactly what happens during many significant cyber incidents. Attackers increasingly target the systems organizations rely on every day:
- Microsoft 365
- Active Directory
- Microsoft Teams
- Slack
- VPN infrastructure
- Corporate email
When these services become unavailable—or can't be trusted—coordination quickly becomes much more difficult. That's why many organizations now incorporate out-of-band communications into their cyber resilience strategy.
Out-of-band communication platforms operate independently from an organization's primary IT environment, allowing Incident Commanders to continue coordinating teams even when corporate systems are offline or compromised.
It's not simply a backup communication tool. It's a way to preserve command and control throughout the response.
If you'd like to learn more, explore our guide on Out-of-Band Communication: Secure Channels During a Crisis, or compare today's leading Best Out-of-Band Communication Tools to understand what capabilities organizations should look for.
Incident Commander vs. Incident Manager
These terms are often used interchangeably, but some organizations make an important distinction.
An Incident Manager typically oversees the operational process—tracking tasks, coordinating activities, and managing workflows.
An Incident Commander provides overall leadership, establishes priorities, coordinates stakeholders, and maintains strategic oversight throughout the response.
In smaller organizations, one person may perform both roles. Larger enterprises often separate these responsibilities to improve focus and scalability. Regardless of the title, the objective remains the same: ensuring the response stays coordinated from beginning to end.
Skills Every Incident Commander Needs
The best Incident Commanders aren't necessarily the most technically experienced people in the organization. They're exceptional coordinators.
Key skills include:
- Clear communication
- Calm decision-making under pressure
- Leadership
- Prioritization
- Delegation
- Executive presence
- Adaptability
- Situational awareness
- Conflict resolution
- Strong organizational skills
Technical expertise is valuable. But coordination, communication, and leadership are what ultimately determine whether an Incident Commander is successful.
Common Mistakes Organizations Make
Many organizations unintentionally set Incident Commanders up for failure. Common mistakes include:
- Assuming the most technical person should lead the response
- Expecting one individual to both investigate and coordinate simultaneously
- Failing to define authority before an incident occurs
- Not identifying backup Incident Commanders
- Relying entirely on primary communication platforms
- Never practicing Incident Command during tabletop exercises
Fortunately, each of these issues can be addressed through planning and regular training.
How to Prepare Incident Command Before an Attack
Effective Incident Command doesn't begin when ransomware appears on a screen. It begins months earlier.
Organizations should:
- Designate primary and alternate Incident Commanders
- Clearly define decision-making authority
- Document roles and responsibilities
- Develop response playbooks
- Establish secure out-of-band communications
- Conduct regular tabletop exercises
- Review lessons learned after every exercise and real-world incident
Preparation creates confidence. And confidence leads to faster, more coordinated responses when the unexpected happens.
Frequently Asked Questions
Who should be the Incident Commander during a cyber attack?
The Incident Commander should be someone with strong leadership, communication, and decision-making skills who can coordinate both technical and business teams. Depending on the organization, this may be a CISO, security leader, IT director, or another trained crisis leader.
Does the Incident Commander investigate the cyber attack?
Typically, no. Technical investigation is handled by security analysts, incident responders, and forensic specialists. The Incident Commander focuses on coordinating people, priorities, communications, and decisions.
Can the CISO serve as the Incident Commander?
Yes, but not always. In some organizations the CISO leads Incident Command directly. In others, the CISO provides executive oversight while another leader coordinates day-to-day response activities.
Why do Incident Commanders need out-of-band communications?
If email, Microsoft Teams, Slack, or other collaboration tools become unavailable during an attack, Incident Commanders still need a trusted way to communicate with response teams. Out-of-band communication platforms provide an independent channel for maintaining coordination throughout the incident.
What's the difference between an Incident Commander and an Incident Manager?
The titles are often used interchangeably. Generally, an Incident Commander provides overall leadership and strategic coordination, while an Incident Manager focuses on operational execution and task management. Larger organizations may separate the two roles, while smaller teams often combine them.
How ShadowHQ Helps
An Incident Commander is only as effective as the information, communication, and coordination tools available to them.
ShadowHQ is purpose-built to support Incident Command during cyber incidents by bringing secure out-of-band communications, playbook management, task coordination, role-based collaboration, and real-time operational visibility together in a single platform. Instead of relying on compromised communication channels or disconnected tools, organizations can maintain command, coordinate response teams, and execute their cyber crisis management plans with confidence—even when primary systems are unavailable.
Whether you're establishing Incident Command for the first time or maturing an existing cyber resilience program, ShadowHQ helps transform incident response from a collection of individual efforts into a coordinated, business-wide operation.