Editorial

An Incident Management Plan is One Thing

Until it leads you to the point of getting a punch in the face :  Guest Author, Stuart Seymour

Wednesday, April 01, 2026 | 5 MINS

Guest Author:  Stuart Seymour I CISO and CSO, Group Security I VirginMedia O2

I  have a favourite philosopher. I know that some of my friends are partial to the ancient greats, while others are partial to the mystics and spiritualists. Some the more contemporary ones, like Borges. 

But for me it has to be Tyson. Iron Mike Tyson. Mike quite rightly said:  “Everyone has a plan until they get punched in the face”

So here are the times in incident and crisis management when I have had a punch to the face and, of course, what I learned.

But before that, an analogy. Whenever I keynote on crisis management, I compare the event to a hydra. As the event progresses, new heads of the hydra form due to unforeseen circumstances such as what the company says in the media, what employees say on social media, how the executive might react and so on. This is over and above the main head itself, which is of course the incident. As the incident lead, it is critical that you are mindful of all of these potential hydra heads and that they are cut before they outgrow the incident itself.

The Tysonian Philosophy

At the very root of Tysonian philosophy is that, in essence, plans change; indeed.  In the Army, we used to say that no plan survives contact, and so it is critical to be adaptable. In the majority of the major cybersecurity incidents I have been involved in, our original (nailed-on and certain) hypothesis never ended up being what we thought as more data became available. 

Adaptability is critical, as is language and temperament. Your job is to prove or disprove. To deal only in fact. There should be no adjectives in any report writing. Any hypothesis dressed in categorical terms (and which inevitably changes) will lead to a loss of trust and even create another crisis of its own. Or another head to the Hydra.

When the building blocks to incident management go wrong

The first building block to incident management has to be tried and tested processes and plans. That are rehearsed. And rehearsed. At all levels of the organisation, including senior management. It was not raining when Noah built the Ark. Cyber Crisis Management exercises have to be achievable and realistic.


The first hours of the incident are critical. Sadly, in my experience, a lot of time is often wasted in trying to apportion blame (or trying to) rabbit holes, “why didn’t we…..” The answer, simply put, is we didn’t. And now we have a fire. And we need to put it out. Leave the why to the lessons learned. And if the Director of hindsight manages to make their way into the room – get rid of them.

I learned the following from a friend in SEAL Team Six. When confronted with a problem, they would often say: “Good (acknowledges the problem positively), what’s next (forward-looking to problem-solve)”

Once this mindset is established and the right teams are where they need to be, incident management can begin.

From experience, during an incident you should focus on the kill chain and its stages. There are two specific aspects which I always try and look out for (and which, once blocked and mitigated, will mitigate most of the attack).   Lateral movement and Command and Control (C2).

Watch out for the punch in the face

Once detected, the focus has to be on containment and eradication, but be careful – there is a punch to the face coming. You must understand your systems, what part of the business they serve and their level of criticality. In shutting down a server or blocking x DNS, you might inadvertently do more harm than the attack itself.


After containment and eradication, you are into the recovery phase. Again, testing here is critical. Business Impact Analyses are not the same as business continuity plans, and these are no good if they have not been tested or put through a disaster recovery process.


Now all of this is all well and good and contained with the singular – though rather sizable original head of the hydra – but there are others, and this is where cyber incident management dovetails into Crisis Management. This is where the rehearsed crisis management plan with its clear escalation criteria comes into play.

Crisis management territory

Once you are in crisis management territory, the focus shifts away from the technical incident to legal risk management and communications. And here comes another punch to the face. In terms of legal risk management, it is critical to bring your legal team in as early as possible. The incident must now be driven at their direction. The problem must be understood in lay terms and not communicated in IT speak. 


In terms of communications, internal should, as a rule, be the same as external. And must be limited to facts. Without conjecture or supposition, or as I mentioned above, adjectives. The relevant executives must be briefed so that they are on the same page. Further, there must be a singular source of truth that all are party to. There are many incidents I recall where the CEO was getting 11:00 hrs news at 11:00 but then also 0930Hrs news at 11:00 as folk cannot resist their moment in the sun. A lot of this can of course, be ironed out via exercising.

Directors of Hindsight

And finally, lessons learned from an incident must be held – in a psychologically safe place. And definitely without the aforementioned Director of Hindsight and their pal, the Director of Well, We Should Have. Learnings must lead to a concrete action and remediation plan, and of course feed into the incident and crisis management plans themselves.

Iron Mike's values

Coming back to Iron Mike, being in an incident is not too dissimilar to being in the ring. Look after your team. Ensure that alternates are planned well in advance. That families are looked after and that different aspects are considered (childcare, food, accommodation, rest, logistics, to name a few).

And if you get punched in the face, learn from it and share the experience with others so that they are not knocked out in the first round.

So, in distilling this for leaders:

1.   Plan and rehearse
2.   No plan survives contact, and very few hypotheses stay as true at the start as at the end of the 
       incident.
3.   Deal only in facts
4.   Don’t look back – look forward positively, ready to solve
5.   Think kill chain to prove or disprove. Focus on C2 and Lateral movement
6.   Think of the other Hydra's heads
7.   Learn – without judgement, nor as the Director of Hindsight
8.   Look after your team

Interested in joining a community that talks about this and many more subjects that are important to CISOs and CIOs?


The 2AM Club

The 2AM Club was founded by Stuart Seymour to bridge with a two-fold mission:  To grow and develop the community to support talent in making the next step, and to bridge the gap between what's really bothering s CIOs and CISOs at night with what technology vendors think they need. 

By aligning the mismatch, it creates the opportunity for greater understanding on both sides; it brings peers and providers closer to the outcome everyone wants: better decisions, stronger security and trusted relationships. 

CTA HEADER

CTA SUB HEADING

Linkedin

Other topics