When Healthcare Systems Go Dark: The Stakes That Keep CISOs Up at Night
When a cyber incident happens, everyone knows what needs to be done.
Security analysts begin investigating alerts. IT teams work to contain affected systems. Executives want updates. Legal reviews obligations. Communications prepares messaging. Business leaders worry about operational disruption.
But amid all that activity, one question often goes unanswered:
Who's actually leading the response?
Many organizations assume the answer is obvious. Surely it's the CISO, the SOC manager, or whoever has the deepest technical expertise.
In reality, that's often where incidents begin to unravel.
The people best equipped to investigate an attack aren't necessarily the people best positioned to coordinate dozens of stakeholders, make business decisions under pressure, and keep the entire organization aligned.
That's why more organizations are adopting an Incident Command model for cyber response.
Who Should Lead a Cyber Incident?
A cyber incident should be led by an Incident Commander—a person responsible for coordinating the organization's response across technical, operational and business teams while security specialists investigate and contain the threat.
Depending on the organization, that person may be the CISO, Security Director, IT leader, Business Continuity Manager, or another trained incident leader. The title matters less than the responsibility.
The Incident Commander isn't expected to perform forensic analysis or remove malware.
Their job is to ensure the entire response stays coordinated, organized and focused on business outcomes.
Why This Question Matters More Than Ever
Cyber incidents have changed.
Ten years ago, most security events were largely technical problems handled within IT.
Today's attacks are different.
A ransomware attack might disrupt manufacturing operations. A compromised identity system can prevent employees from accessing critical applications. A cloud outage may interrupt customer services. A supply chain attack can quickly become a regulatory, legal and reputational issue.
Responding now requires coordination across multiple teams simultaneously:
- Security Operations
- IT Infrastructure
- Executive Leadership
- Legal
- Human Resources
- Communications
- Customer Success
- Business Operations
- Third-party partners
- Incident response firms
- Cyber insurance providers
Without someone coordinating these moving pieces, organizations often find themselves working hard—but not necessarily working together.
The Biggest Mistake Organizations Make
One of the most common mistakes during a cyber incident is assuming the organization's best technical expert should also run the response.
It sounds logical.
After all, if someone understands the attack better than anyone else, shouldn't they lead it?
Not necessarily.
During a serious incident, security teams need to stay focused on questions like:
- How did the attacker get in?
- Is the threat contained?
- What systems are affected?
- What evidence needs to be preserved?
- Is lateral movement still occurring?
At the same time, someone else needs to answer a completely different set of questions:
- Who needs to be informed?
- Which teams should be activated?
- What decisions need executive approval?
- What tasks are falling behind?
- What happens next?
Those are fundamentally different jobs.
Asking one person to do both often means neither gets the attention it deserves.
What Does an Incident Commander Actually Do?
Think of the Incident Commander as the person responsible for keeping the entire organization moving in the same direction.
While technical teams investigate the attack, the Incident Commander manages the response itself.
| Incident Commander | Technical Response Team |
|---|---|
| Sets priorities | Investigates the attack |
| Coordinates teams | Contains affected systems |
| Assigns responsibilities | Collects forensic evidence |
| Tracks decisions | Removes malicious activity |
| Runs response meetings | Restores infrastructure |
| Updates executives | Validates recovery |
This separation allows technical experts to stay focused on technical work while ensuring the broader response doesn't lose momentum.
Who Should Fill the Incident Commander Role?
The answer depends on the size and maturity of the organization.
Small Organizations
Many smaller businesses don't have dedicated incident response teams.
The Incident Commander might be:
- IT Director
- Head of Technology
- Managed Security Provider
- External Incident Response Partner
The key is assigning someone who has the authority to coordinate people and make decisions—not just solve technical problems.
Mid-Sized Organizations
As organizations grow, the role often shifts to someone with dedicated security leadership responsibilities, such as:
- Security Manager
- Director of Information Security
- CISO
- Incident Response Manager
These leaders typically have both technical understanding and organizational visibility.
Enterprise Organizations
Larger enterprises increasingly establish formal Incident Command structures.
Leadership may include:
- Dedicated Incident Commander
- Cyber Crisis Manager
- Operational Resilience Leader
- Business Continuity Lead
- Enterprise Incident Management Office
These organizations recognize that coordinating a major cyber event has become a full-time responsibility during a crisis.
What Makes a Good Incident Commander?
The best Incident Commanders aren't necessarily the most technical people in the room.
They're the people who can create clarity when everyone else is operating under pressure.
Strong Incident Commanders typically:
- Communicate clearly
- Stay calm during uncertainty
- Prioritize business impact
- Make timely decisions
- Keep stakeholders aligned
- Delegate effectively
- Understand escalation paths
- Maintain accurate documentation
- Adapt as new information emerges
Technical expertise certainly helps.
But leadership, communication and coordination are what make Incident Command successful.
Cyber Incidents Have Become Operational Resilience Events
One reason Incident Command has become so important is that cyber incidents rarely stay confined to cybersecurity.
Modern attacks affect the entire business.
An incident may interrupt manufacturing, delay customer orders, impact patient care, disrupt financial transactions or prevent employees from accessing essential systems.
As organizations become more digitally connected, cyber resilience and operational resilience have become closely intertwined.
That's why leading organizations no longer think solely about "incident response."
They think about maintaining business operations while managing the incident.
This broader perspective ensures decisions aren't made based only on technical priorities, but also on customer impact, regulatory obligations and business continuity.
Building an Effective Incident Command Structure
Incident leadership shouldn't be decided after an attack begins. The most resilient organizations define roles well before an incident occurs. A typical Incident Command structure might include:
Executive Sponsor
↓
Incident Commander
↓
- Technical Lead
- Communications Lead
- Legal Lead
- Human Resources
- Business Operations
- Recovery Lead
- Vendor Management
- Compliance
Everyone understands their responsibilities before the first alert arrives. That preparation eliminates confusion when time matters most.
Technology Should Support Incident Command—Not Create More Complexity
Many organizations still rely on email threads, spreadsheets, conference calls and chat applications to coordinate incident response.
Those tools work—until they don't.
As incidents grow more complex, information becomes fragmented. Tasks are missed. Decisions are difficult to track. Teams lose visibility into what has already been done and what still needs attention.
Purpose-built incident management platforms help Incident Commanders maintain a shared operational picture by centralizing:
- Response playbooks
- Task ownership
- Secure communications
- Decision logs
- Executive updates
- Status tracking
- Documentation
- Audit trails
The goal isn't to replace incident responders.
It's to give Incident Commanders the visibility and coordination tools they need to lead effectively.
Frequently Asked Questions
Is the CISO always the Incident Commander?
No. While many organizations assign the role to the CISO, others designate a Security Director, Business Continuity Leader or dedicated Incident Commander. The most important factor is that the individual has the authority and training to coordinate the organization's response.
Can the SOC Manager lead a cyber incident?
Yes, but organizations should avoid assigning someone to both lead the incident and conduct the technical investigation. Separating coordination from investigation usually leads to faster, more organized responses.
Who owns communications during a cyber incident?
The Incident Commander coordinates communications across stakeholders, while communications teams, executives and legal counsel develop and deliver approved messaging.
What's the difference between an Incident Commander and the Incident Response Team?
The Incident Response Team investigates, contains and remediates the cyber threat. The Incident Commander coordinates the people, decisions, communications and overall response needed to keep the organization aligned.
Does Incident Command improve cyber resilience?
Yes. Organizations with clearly defined leadership roles generally make faster decisions, improve cross-functional coordination and recover more effectively from cyber incidents.
Incident Leadership Is About More Than Technical Expertise
When organizations ask, "Who should lead a cyber incident?" they're often looking for a job title.
The better question is:
Who can keep the entire organization moving in the same direction when everything else is moving at once?
Technical expertise is essential, but successful incident response depends just as much on coordination, communication and decisive leadership.
As cyber incidents continue to impact business operations—not just IT systems—the role of the Incident Commander is becoming a cornerstone of cyber resilience.
Organizations that define this role before an incident occurs are better prepared to respond confidently, minimize disruption and recover faster when every minute counts.
How ShadowHQ Helps
Cyber incidents don't fail because organizations lack talented responders. They fail because coordination breaks down when systems are disrupted, communications become fragmented and multiple teams are trying to make decisions under pressure.
ShadowHQ is built to support modern Incident Command. It provides a secure, out-of-band environment where Incident Commanders can activate response plans, assign tasks, communicate with stakeholders and maintain visibility across the entire incident—even if core business systems are unavailable.
Whether you're building your first Incident Command capability or maturing your cyber resilience program, ShadowHQ helps organizations coordinate response with greater confidence, clarity and control.