Insight · 19 August 2026

What is the leader’s role in a breach: step back, or be part of every call and every decision? Here is the break glass answer.

There is confusion from leaders around what their role is during an incident. Should they simply be stepping back, or be part of every call and every decision? I deal with incidents, near misses from people who made mistakes and people who caused harm intentionally every day. I hear a lot of horror stories and I want to stop someone becoming the next victim.

This is a simple walkthrough for the person who carries the risk but doesn’t have a strong cyber or incident response team. An eleventh hour break glass summary. This is not best practice, it is survival.

In a breach situation a leader is there to serve the people around them and keep the business running. Firstly, create a safe and positive environment, supporting those dealing with the uncertainty, long days, nights and fears of losing their job. A leader is looking ahead and listening, ensuring their team receive the support and resources are supplied to them. Empowering them to work at a pace they can sustain, because these things rarely end the same day and trust me, burn out is real.

It will happen at the most inconvenient time, during your business’s busiest period at three AM the night before your most important meeting, or 5pm on a Friday.

Your technical manager is on the line saying, ‘We think we have a problem.’

First, request or find your incident response plan. If there isn’t one already created, it’s not time to panic. Find a template online, not best practice but it will at least contain some standardised steps and it will bring clarity. NIST or NCSC have worked for years to determine the best approaches to incident response. This reduces but does not eliminate the chances that something gets missed along the way.

Gather the clearest picture of the nature of the incident at that current moment and keep track of it. How it originated, what caused it, the quicker you can get the right people on the call and know the impact, the blast radius, the more effective you can be at everything that comes next.

Check the business insurance policy for cyber cover. If you have this in place, contact them as soon as you know the shape of the incident. It is important to start this before any expense is incurred or external support has been identified, so pause the team on that until it is confirmed. Insurers often have a specific firm they need you to work with before engaging your own firm.

If it is an obvious criminal matter, forensics support is then a must, as is contacting the police immediately. Always follow the advice of the insurer and use the included incident management or forensics support to ensure you remain covered. Court cases rely on legal holds and special chains of custody. A prosecution relies on the correct preservation of evidence and the earlier this happens the stronger the case can be.

Containment, or stopping the spread, is usually a technical process and is about speed and can’t always be precise. One essential technical point to remember is it is best to remove the network connection but leave the machine running until further actions can be determined. Remember that powering off a machine can wipe important forensic data, and keeping things running but the network disconnected is the safest method.

The two main misconceptions I find are with ransomware, the most likely cyber incident for mid-market firms. Knowing if and when to pay a ransom: my advice is to rely on legal professionals and take the insurer’s guidance. If it is ransomware, do not let your team communicate or negotiate with the criminals directly until expert support is in place.

The other is data exfiltration. If data left the business, no matter how good the backups are, the situation isn’t resolved until it is clear what data went and where it went. That is the information your data protection counsel needs, and the clock is ticking on regulator and personal data breach notifications, and on service level agreements with breach notifications in them.

From a leadership perspective, do not apportion blame or downplay the incident, especially in the early stages.

In high pressure situations always maintain good communication and a positive momentum, the team need that so they can power through. It is important to maintain a high trust environment at all times and to listen to every member of the team.

A leader is expected to deploy the information at their fingertips and take the senior calls only they can make. Whatever happens, it is always best to act in customers’ and employees’ best interests. Disabling a revenue stream for a short period whilst the team investigate might seem like worst case, but the long term impacts could be far greater.

Ensure there is a central channel set up in, say, Slack or Teams that has every person involved in the incident and keeps a log of every important detail about the incident.

Know exactly:

  • Who is the incident commander: someone who can straddle the technical and the business requirement and keep immaculate paperwork.
  • Who leads the technical response, can understand the detail and translate requirements for the wider team.
  • Who is doing the technical work: is this internal IT or development function, or is there a quick response incident response vendor?
  • Who is communicating with the insurers and legal.
  • Who drafts communication internally and externally.

Work ahead of your team: what will need to be outsourced, and what can your team handle alone?

  • Incident response workload
  • Forensics and chain of custody
  • Data protection counsel
  • Public relations response
  • Tools that technically support eradication and recovery such as SIEM, EDR and MDR

Insurers often cover at least a few of these, so best to double check if you have cyber cover.

As the severity and impact become clear, that will determine exactly which services are required, but best to work ahead of time and, if you don’t have insurance, reach out to potential vendors that work at short notice.

Work with internal or external counsel to determine your regulations and compliance obligations. FCA, PCI DSS, SEC 8-K and NIS2 all have their own incident reporting requirements. People often forget customer contracts, which sometimes have breach notification requirements of their own. If this is a personal data breach, then the GDPR sets different obligations depending on whether you are the controller or the processor. Other privacy laws such as CCPA might apply too. Ensure notices are drafted and sent within the timeframes and comply with the legal guidance.

Work closely with the whole team as they work through eradicating any signs of the compromise, completing infrastructure scanning and testing to ensure that all signs of the incident are removed.

In my experience most people tend to skip the post incident review. The panic subsides and business priority tasks take precedence. I get it.

Book the review in as soon as the final incident calls have been made.

Be the person that asks the five whys to get the root cause analysis. What do we need to do to stop this, or something like it, from happening again? Have we implemented the changes, or is there a roadmap, and who owns that? What training have we rolled out to improve employee awareness?

For 90% that made it this far, this is likely more preparation than live incident response playthrough.

Quick questions to ask yourself right now

Do we have a NIST aligned up to date incident response plan that maps out some common incident scenarios?

Have you recently checked what Service Level Agreement you have in place with your IT provider, website or application development team if outsourced? Will they support you in an incident, how quickly and for how many hours or days?

Have you checked if you have cyber insurance? If you don’t plan to, do you have an idea of the digital forensics teams, incident responders and legal firms you might use, and what their costs and response times are?

Is your company up to date on the regulations that apply to the personal data and the obligations required for each when an incident occurs? This can help prevent fines or investigations following an incident, which is exactly when the cost and additional scrutiny would do the most harm.

Stephen Randles

Founder & Principal · Alvermere

This guide is general information and does not constitute legal or regulatory advice.

This piece as a PDF

All Insight