The Leadership Layer, Part 9: Deciding Under Pressure
How OT incident response governance determines outcomes before, during, and after industrial cyber disruption
This is the ninth article in The Leadership Layer series, exploring how the OT vCISO builds cyber-resilient industrial organizations. Previous entries covered the vacancy at the top, the accountability gap, building an honest baseline, closing the OT threat intelligence gap, making visibility a funded priority, governing legacy OT risk, owning the vendor relationship, and rejecting the compliance trap.
Two industrial cyber incidents, six years apart, show what governance does and what its absence costs. In March 2019, LockerGoga ransomware froze 22,000 Norsk Hydro computers across 170 locations in 40 countries. Within hours, executives made three decisions: no ransom, bring in Microsoft and external forensics, and communicate openly. The corporate emergency team was led by the CFO, Eivind Kallevik, because authorizing 35,000 employees to switch to manual operations was an operational and financial decision. Total impact was roughly $71M.
In August 2025, the Jaguar Land Rover cyberattack began. The UK Cyber Monitoring Centre now estimates roughly £1.9B in economic damage, and the UK government underwrote a £1.5B emergency loan tied directly to attack consequences. The difference was not only tooling depth. The difference was tested authority: who decides when operations change, and how quickly those decisions execute.
Why OT Incident Response Is a Governance Problem First
OT incident response governance is the decision framework that determines how an organization acts when cyber events threaten physical operations. It comes before tooling because response actions can create safety and production consequences if leadership authority is unclear.
According to the SANS State of ICS/OT Cybersecurity survey published in 2025, only 14% of respondents felt fully prepared for emerging threats. SANS also reported that 21.5% of organizations experienced an incident affecting ICS/OT in the prior year, with 40% causing operational disruption and about 19% taking more than one month to fully remediate.
Dean Parsons and other OT incident leaders consistently note that IT-first playbooks can fail in OT environments. Isolating a controller or shutting down segments without plant context can halt production, damage equipment, or create unsafe operating states. Security teams should monitor and recommend. Final decisions that affect physical process must rest with accountable operations leadership.
The Governance Gaps Most Programs Carry
Most programs are not failing from lack of intent. They are failing from missing governance structure. The same SANS 2025 dataset reports only 57% of organizations have a dedicated ICS/OT incident response plan, leaving 43% without one.
PwC's OT risk analysis describes the structural issue directly: responsibility often sits with security leadership, while accountability spans operations, engineering, legal, and compliance. When that split is not pre-coordinated, incidents trigger decision latency, fragmented communication, and expensive escalation loops.
This is the same accountability problem detailed earlier in The Leadership Layer in The Accountability Gap. Under normal conditions, the gap is inconvenient. Under incident pressure, it is a cost multiplier.
Pre-Authorization Is the Whole Game
Pre-authorization means authority is assigned before an incident, not negotiated during one. This is where ICS4ICS, developed through ISA Global Cybersecurity Alliance and CISA collaboration, provides practical structure that industrial organizations can operationalize immediately.
The ICS4ICS model emphasizes explicit Incident Commander authority, defined decision thresholds, and named executive roles for shutdown approvals, ransomware decisions, legal escalation, and communications control. Norsk Hydro effectively operated this way in 2019. Most organizations still do not.
When organizations pre-authorize incident authority, technical teams can execute under a clear command structure. When they do not, teams debate authority while impact compounds.
The Regulatory Clock Is Tightening
Regulation now assumes governance quality can be demonstrated quickly. NIST SP 800-61 Revision 3, released in April 2025, reframed incident response around CSF 2.0 functions and elevated governance to a core operating requirement. NIST SP 800-82 Revision 3 applies similar posture for industrial environments.
The disclosure windows are converging at the same time: SEC Item 1.05 requires material incident disclosure in four business days, CIRCIA requires covered entities to report substantial incidents within 72 hours and ransomware payments within 24 hours, and TSA surface transportation rulemaking includes 24-hour reporting requirements for defined operators.
These clocks start on materiality judgment and reasonable belief, not on perfect investigative certainty. Attack-path analysis in The Vendor Shadow Current and adversarial movement patterns in How the Red Team Walks In Through the Front Door of OT show why governance has to be operational before any filing clock starts.
Tabletops Are Where Governance Gets Real
Tabletops are the fastest way to reveal whether governance is executable. SANS 2025 reports that organizations including frontline technicians and operators in cybersecurity tabletop exercises rated readiness 1.7x higher than peers that did not.
The value is not theater. The value is discovering the exact scenario moment where someone asks, 'Who decides this now?' and no one can answer quickly. CISA tabletop packages and ICS4ICS exercise scripts are useful because they force this decision clarity test under time pressure.
If authority breaks during an exercise, governance is not mature yet. That signal is actionable, and much cheaper to learn in rehearsal than in production outage conditions.
The vCISO Builds This Before You Need It
The OT vCISO does not replace plant engineering, SOC analysts, or operations leadership. The OT vCISO builds and maintains the governance layer that lets those teams execute under pressure: decision authority maps, IT-OT escalation protocol, OT-safe playbooks, regulatory communication rhythm, and board reporting discipline.
This strategic layer connects directly to companion work in The Fusion Center Blueprint, adversarial validation in What the Red Team Sees, and capability engineering in Build Capability, Deliver Compliance.
Resilience is ultimately measured by what happens after impact begins, specifically how quickly controlled operations are restored. That is the transition point into the next article in this series. Learn more about the OT vCISO role in the Executive Brief, The Missing Leadership Layer in Industrial Cybersecurity, and schedule an OT vCISO Discovery Session.
Sources: SANS Institute; Dragos; Industrial Cyber; Microsoft; DNV; Hydro; CS4CA; UK Cyber Monitoring Centre; Computing; AM Online; CNBC; PwC; Siemens; Packt Publishing; ISA Global Cybersecurity Alliance; CISA; FEMA; NIST; U.S. Securities and Exchange Commission; MetricStream; Federal Register; Transportation Security Administration.
Under pressure, teams do not rise to intention.
They fall to their decision structure.
Governance is that structure.
Norsk Hydro's command structure enabled no-ransom posture, manual continuity, and trusted communications in hours, not days.
Economic consequence can scale dramatically when authority, escalation, and shutdown decisions are not fully rehearsed under stress.
Without a dedicated OT response plan, teams default to IT instincts that can increase physical and operational risk during containment.
Defined Incident Commander authority and role ownership remove decision latency when technical teams need immediate executive direction.
Organizations need pre-built materiality and escalation logic before incidents, because reporting windows start before investigations are complete.
Every OT response program should identify exactly who can authorize manual mode, partial shutdown, external forensics engagement, and executive communications when incident uncertainty is still high.
Pre-authorize incident declaration authority, ransomware decision owners, emergency spending rights, legal trigger points, and board escalation thresholds before any live event.
Run cross-functional exercises with operations, legal, engineering, finance, and communications to expose authority gaps and response friction while consequences are still simulated.
Govern means assigning authority, defining thresholds, and rehearsing command pathways before incident pressure distorts decision quality.
Respond means executing OT-safe containment and communication choices under one command structure with cross-functional coordination.
Recover means restoring controlled operations with speed and discipline, then feeding governance lessons back into the next exercise cycle.
OT incident outcomes depend more on decision authority design than on tooling inventory alone.
Pre-authorization is the mechanism that converts governance theory into operational response speed.
Tabletops are the cheapest place to discover governance failure before real-world incident consequence.
