The Accountability and Authority Asymmetry: Navigating Governance Challenges in Incident Response
In the landscape of modern enterprises, a significant governance challenge often surfaces during incidents affecting business services. Individuals in executive positions, such as the heads of payments, trading, or clinical systems, frequently find themselves accountable for the availability of their respective services but lack the authority to prevent those services from being taken offline during critical events. This disconnect between accountability and authority can lead to operational inefficiencies and prolonged downtimes, ultimately affecting business continuity.
The Security Operations Center (SOC) typically holds the decision-making power regarding incident response protocols, which creates a divide between the accountability of business owners and the authority of security personnel. This disparity only becomes apparent when a service is shut down, exposing flaws in the traditional incident response framework. In April 2025, the National Institute of Standards and Technology (NIST) released Special Publication 800-61 Revision 3, spearheaded by experts including Amy Nelson, Shanée Rekhi, Murugiah Souppaya, and Karen Scarfone. This updated document restructures the incident response model to align more closely with the NIST Cybersecurity Framework 2.0, shifting focus from tactical execution to strategic risk management.
This paradigm shift underscores the necessity for incident response to be regarded not merely as a function of the SOC but as an integral part of the broader organizational framework for managing risk. Under this new doctrine, business owners are recognized as key participants in the incident response process. Thus, the need for clearer delineation of roles and responsibilities becomes paramount.
The issues arising from this authority-accountability asymmetry are not merely resolved through training programs for SOC staff. Rather, they represent a fundamental governance challenge. The existing incident response (IR) playbooks often reflect the perspectives of the security function without undergoing adequate operational and legal reviews. This oversight may lead to flawed assumptions about who should make critical decisions during incidents. For example, relying on a SOC analyst working late at night to determine whether to halt payment processing to minimize attacker dwell time is unrealistic. Such significant decisions should rest with designated operational leaders who can provide informed insights on specific business needs and risks.
To improve incident response efficacy, playbooks should clearly outline protocols to be followed if an operational owner cannot be contacted immediately. In these cases, pre-agreed safe-state actions would prevent analysts from improvising solutions that may not align with broader business objectives. This structured approach not only clarifies responsibilities but also enhances the effectiveness of incident response teams during high-pressure scenarios.
The No-Touch Register: Reassessing the Crown Jewels Inventory
In conjunction with the necessity for an updated approach to governance in incident response, most organizations already maintain a "crown jewels" register. This document is critical, cataloging systems whose potential loss could pose existential threats to the organization. Traditionally, this inventory drives important decisions around investment, patch management, backup frequency, and monitoring depth—functions that are undeniably vital for safeguarding organizational assets.
However, the crown jewels register serves a dual purpose that is equally essential: it acts as a safeguard against unauthorized changes by the SOC without proper authorization from appointed business owners. This second function emphasizes the increasing need for cross-functional collaboration within organizations, ensuring that security measures do not inadvertently compromise vital business operations.
Adopting a no-touch policy for this register means that any action concerning these critical systems must receive explicit confirmation from the business owner. This policy not only reinforces the accountability of business leaders but also integrates their insights into security strategies, ultimately leading to a more cohesive approach to risk management.
In summary, the reinvigoration of accountability and authority roles in incident response and the reevaluation of the crown jewels register reflect a broader trend towards more integrated risk management within organizations. These changes aim to bridge existing gaps in governance, ensuring that both security and business priorities are respected and addressed collaboratively. As enterprises continue to navigate the complexities of digital transformation and cyber threats, adopting such frameworks will be crucial in ensuring resilience and sustainability.

