Crisis Management
Internal approvals for cyber incidents: decision-making authority, alternates, and review records
There are situations in which decisions cannot wait, even when the full picture is not clear. Who decides, what is recorded, and under what conditions are decisions reviewed? This article examines the initial response to a cyber incident from the perspectives of decision-making authority and recordkeeping. Specific decisions, such as commissioning an investigation, providing explanations to business partners, and bearing costs, are each addressed in separate articles.
Reviewed by Keishi Yoshikawa, Attorney at Law and Patent Attorney (Dai-Ichi Tokyo Bar Association)
Contents
- Checking which decisions have stalled and what authority already exists
- Distinguishing decisions by operational staff, management approvals, and reconsideration
- Designating responsible staff, approvers, and alternates to act when approvers are absent
- Recording reasons for decisions and conditions for review as a basis for consultation
The following is a fictional scenario. Company A (a manufacturer preparing for a stock exchange listing, with 300 employees, two legal staff members, and an information systems department) is experiencing a problem with its order and inventory system that is disrupting shipments. Company B, the vendor to which operation and maintenance are outsourced, has also reported suspected unauthorized access to the environment used for its work. It is not yet known whether any information has leaked or whether the system problem and the suspected unauthorized access are related. This article addresses who within Company A decides what at this stage.
Company A, Company B, and the other elements of the scenario in this article are fictional and used for explanatory purposes. They do not describe actual matters handled by our firm.
How we can helpYou can consult us on clarifying internal decision-making authority and arrangements for alternates.
Contact FormThis form is not an emergency contact point, and we may not be able to review or reply to your message immediately after it is sent.
Checking which decisions have stalled and what authority already exists
The matters requiring decisions in the early stages of an incident generally include the following: measures to prevent damage from spreading; whether to shut down a system or keep it running; whether to commission an investigation by outside experts; when and what to tell business partners and customers; whether reporting to the authorities or notifying the individuals concerned is required; and whether to continue operations using alternative means.
All of these differ in nature from day-to-day decision-making. This is because decisions must be made before all the information needed for a decision is available and, moreover, there are situations in which failing to decide itself increases the damage.
Under internal authority rules that focus on monetary thresholds, it may not be possible to identify an authorized approver for decisions that cannot be measured in monetary terms, such as shutting down a system, or decisions for which the amount is finalized only afterward, such as commissioning an investigation.
When departmental roles or approval responsibilities are unclear, each department may see the matter as a decision for another department, delaying a decision. In Company A's example, the information systems department prepares the proposal to shut down the system, but the business department assesses the impact on shipments, while Legal assesses, from a legal perspective, whether explanations can be given to business partners.
The first task is to distinguish between matters for which an authorized approver can be identified under existing rules and those for which one cannot. If there are matters in the latter category, those are precisely the points at which the incident response first stalls.
Distinguishing decisions by operational staff, management approvals, and reconsideration
It is easier to organize decisions by considering them in three categories with different characteristics.
The first consists of measures implemented immediately and reported afterward. For isolation and disconnection to prevent damage from spreading, a distinction is made, based on the characteristics of the systems, the impact on operations, and existing authority, between measures that operational staff can implement immediately under their own authority and measures that require approval. If everything is made subject to management approval without this distinction, damage that could have been prevented may spread because management cannot be reached at night or on nonworking days.
The second consists of matters for management to decide. These include shutting down or restarting systems where this affects the business, external communications, substantial expenditures, and decisions involving legal liability. These decisions should be made and documented as management decisions, even where there is technical urgency.
The third consists of matters decided provisionally and reviewed later. Many decisions made in the early stages of an incident are made with insufficient information. When a decision is made, it is designated as "provisional", and the time for review is set in advance. Setting the conditions for reconsideration at the same time as the decision, such as "reconsidering when an interim investigation report is received" or "checking the situation after a specified period and deciding whether to continue", makes it easier to revise the decision when circumstances change.
→ Deciding on investigation scope, deliverables, and orders for additional work
→ Managing responses and updates to business partners
Designating responsible staff, approvers, and alternates to act when approvers are absent
Incident response approvals involve more roles than day-to-day approvals: the department preparing a proposal, the person responsible for technical fact-finding, the person conducting the legal assessment, the authorized approver, and an alternate when that approver is absent.
In a company with separate departmental functions, such as Company A, these roles can be organized as follows.
| Matter for decision | Proposal preparation | Technical assessment | Legal assessment | Approver | Alternate | Recipient of subsequent report |
|---|---|---|---|---|---|---|
| Network isolation | Information systems | Information systems | — | Head of Information Systems (subsequent report) | Section manager | CISO |
| Commissioning an external investigation | Information systems | Information systems | Legal | CISO | Head of Administration | Board of directors |
| Initial report to business partners | Legal | Information systems | Legal | Head of Administration | Head of Legal | President |
| Suspension and resumption of operations | Business department | Information systems | Legal | President | Vice president | Board of directors |
| Compensation and expenditures | Legal and Accounting | — | Legal | President | — | Board of directors |
Note: These are illustrative entries for a fictional scenario. The authority, responsibilities, and timing are specific to this scenario and are not requirements under laws or regulations. For companies in which staff hold multiple roles, one approach is to consolidate them into three roles: "management decision-making", "technical response", and "communication and recordkeeping".
When alternates are designated, the maximum time to wait if someone cannot be reached is set in advance, as well as their order of priority. If only the order of priority is set, and there is uncertainty over "whether to keep waiting for a response", having alternates serves no purpose.
In addition, structure reporting to the board of directors, company auditors, and others (including audit and supervisory committees and internal audit departments) as a channel separate from approvals. Whether approval has been granted and whether a report has reached the bodies that should receive it are separate questions. In a company with a board of directors, the development of systems for the proper conduct of business is a matter for the board to decide (Article 362, paragraph (4), item (vi) of the Companies Act; in a large company with a board of directors, such a decision is mandatory under paragraph (5) of the same Article). The arrangements for incident response authority and reporting are treated as part of those systems.
→ Obtaining the necessary incident information from a vendor
→ Response structure and allocation of roles
Recording reasons for decisions and conditions for review as a basis for consultation
The term "incident response records" brings to mind a factual record of what happened and when. However, what is often needed later is a record of why a decision was made.
The following are the items to keep on record.
- Matter decided
- Facts known at the time of the decision (and facts not known at that time)
- Alternatives considered
- Reasons for choosing that option
- Proposer and approver
- Conditions for review and the time for review
In addition, the date and time when a decision was made or an event occurred are recorded separately from the date and time when the record was created. When additions or corrections are made later, the original record is retained, and the date and time of the change, the person who made it, and the reason for the change are recorded. Even a well-organized record cannot be used to explain the course of events if it does not show what was known at the time. Do not blend facts discovered in a later investigation into the record made at the time.
These records may later be referred to when questions arise as to whether officers fulfilled their duty to exercise the care of a prudent manager, or when the allocation of liability between the company and a vendor is considered. The materials requested when an insurance claim is assessed for payment vary depending on the applicable policy terms and endorsements.
However, keeping records does not, by itself, mean that liability is avoided. This is because records provide material for examining whether a decision was appropriate; they do not justify the substance of the decision.
In situations such as the following, we recommend considering the matter together with an analysis of the legal issues.
- When it is necessary to decide who will approve a matter not covered by the internal authority rules
- When technical and legal assessments differ and departments reach different conclusions
- When planning what should be recorded as management decisions
There are aspects with which lawyers can assist once it becomes necessary to clarify who within the company decides what, with that clarification informed by the assessments of providers responsible for the technical response and providers supporting incident response.
→ Substantiating compensation and recovery costs by cost category
→ Checking reporting and notification obligations and the overall response
Contact
Making an inquiry
Please let us know, as far as you are able, the matters requiring decisions and their deadlines; the current allocation of responsibilities and approval structure; and the points you would like to clarify about approvals or arrangements for alternates.
Contact FormIn your first message, please tell us the name of your company, the names of the parties involved and an outline of the matter. We will let you know whether we can advise after checking for conflicts of interest and similar matters. This form is not an emergency contact point, and we may not be able to review or reply to your message immediately after it is sent.
This article is provided for general informational purposes only and does not constitute legal advice on any specific matter. Please consult us regarding your specific situation. The content is based on the laws and regulations in effect as of the date of the last update.
