When a cyber incident hits, most organizations discover something uncomfortable: the structure they assumed was in place doesn’t quite hold. Security is waiting for IT to apply system and network changes. The CISO is fielding board calls while simultaneously trying to understand what the security team is learning on the ground. Legal wants to determine what to disclose. Communications Manager asks questions about what to say when. The missing piece? A formally designated Incident Commander.
This is the reality of our current incident response paradigm, which is strained by unclear roles, competing priorities, and uneven organizational design. Incident commander is a role that in some companies is a primary responsibility, and in others is an additional job for the CISO or a security team member.
The traditional approach has leaned on the assumption that incident response is primarily a technical problem: contain the threat and mitigate its spread, restore systems, and write the post-mortem. That worked for an earlier era when threats were more discrete, infrequent, and less consequential outside the security team.
But that’s not the world today’s teams operate in. When an organization learns about a cyber incident, there is much broader awareness. That understanding demands cross-organizational technical collaboration, business coordination, and clear accountability for how decisions get made. From there, the clock starts ticking on regulatory and customer notification timelines. Boards, now more attuned to the reputational and financial stakes of a high-impact incident, start pressuring C-level executives. This applies broadly; even smaller incidents can force complex decisions. The world is more aware of the stakes, a net positive, but it also means that security teams face more scrutiny than ever before.
While the scope has expanded, the organizational structures surrounding IR have started to lag behind. Even well-sourced, highly-trained security teams find themselves improvising their coordination model when it’s go time.
The Missing Role in Your Response
What’s absent from many incident response programs is a formally designated Incident Commander – someone whose explicit job is to coordinate the response across every function involved, keep the right people informed without pulling them into the operational weeds, and maintain accountability when things move fast.
This is a different role than the CISO, and conflating the two creates problems. The CISO owns the incident for the organization and is accountable to the board, regulators, and executives. The incident leader orchestrates the incident—tracking what each team is doing, ensuring each has what they need, and protecting the response from constant interruption. Holding teams accountable while shielding them from status request overload are two of the most underappreciated functions this role serves.
The CISO, DCISO, or a senior security leader often ends up doing both jobs. That puts one person at the center of too many competing demands when clarity matters most, creating predictable outcomes. They include slower decisions, gaps in coordination, and executive leadership not getting enough information or becoming too involved in the operational response.
Build the Role Before You Need It
Most organizations do not have a formally-designated Incident Commander, but the idea is gaining traction, particularly in larger organizations. What we’re seeing work: companies that identify the role early, staff it intentionally, and build credibility through practice before it’s needed.
Some look within the security team to assign the role, including senior incident responders who naturally coordinate across teams and communicate clearly under pressure. Other organizations look outside security entirely, identifying people with strong program management and cross-functional communication skills. One CISO I know went to their customer success team to find someone with these skills to successfully run incidents in their organization.
The technical depth requirement is often overstated. An incident lead needs to follow what’s happening technically, not execute it. Most important is the ability to coordinate across teams speaking different functional languages, hold people accountable without direct authority, and maintain a clear picture of the whole incident when everyone else is heads-down. Communication skills are critical, as is the ability to work under pressure with competing stakeholders. A successful Incident Commander must keep their relationships when tensions are high.
Institutionalizing this role requires work done before any incident occurs. Leadership and executives should know who runs incidents, not just who owns them. Exercises are essential to building that foundation. Running realistic scenarios that require coordination across different business functions builds both credibility and relationships that make the role effective when it counts.
The current approach to incident response needs to change. Organizations do not need a massive restructuring to improve incident command. They need to define who serves in that role, what authority that person has during a crisis, and how the role interfaces with the CISO, IT, engineering, compliance, legal, communications, and leadership. It’s foundational work that pays off the moment an incident hits.
About the Author
Matt Hartley is co-founder and chief product officer of BreachRx. He is a 20+ year innovator in cyber security, threat intelligence, cyber warfare, and information operations. Prior to BreachRx, he was a Senior Vice President of Engineering at FireEye and Vice President of Product at iSIGHT Partners, where he held a variety of other leadership roles. Matt previously served in the US Air Force in the Air Intelligence Agency and Air Force Information Warfare Center. After leaving the military, he led research and development teams creating disruptive and next generation cyber and information security, cyber warfare, and information operations technologies at Sytex Inc. and Lockheed Martin’s Advanced Technology Labs. Matt holds a CISSP and both Bachelors and Masters degrees in Computer & Systems Engineering from Rensselaer Polytechnic Institute.
Matt can be reached online at [email protected] and at our company website https://www.breachrx.com/.

