Back to Insights
Leadership·SG/NL/AE

Incident Response as Leadership Diagnostic: What a Breach Reveals About Your CISO

Every organisation will face a breach. The question is whether your response architecture was built before or after the event. Using the IMPACT framework to assess incident response as a leadership signal — not a technical exercise.

Harald H.R. AgterhuisHarald H.R. Agterhuis·March 3, 2026
Contents · 5 sections+

The most revealing assessment of a CISO's capability is not their security architecture, their team structure, or their budget management. It's how they behaved during a breach.⁠‌‌​​​​‌​‍‌​‌​‌​​‌‍​‌​‌​​‌‌‍​‌​​​‌​‌‍​‌​‌​​‌​‍​‌​​​​‌‌‍​‌​‌‌​​​‍​‌​​‌​​‌‍​​‌​‌‌‌‌‍​‌‌​‌​​‌‍​‌‌​‌‌‌​‍​‌‌​​​‌‌‍​‌‌​‌​​‌‍​‌‌​​‌​​‍​‌‌​​‌​‌‍​‌‌​‌‌‌​‍​‌‌‌​‌​​‍​​‌​‌‌​‌‍​‌‌‌​​‌​‍​‌‌​​‌​‌‍​‌‌‌​​‌‌‍​‌‌‌​​​​‍​‌‌​‌‌‌‌‍​‌‌​‌‌‌​‍​‌‌‌​​‌‌‍​‌‌​​‌​‌‍​​‌​‌‌​‌‍​‌‌​‌‌​​‍​‌‌​​‌​‌‍​‌‌​​​​‌‍​‌‌​​‌​​‍​‌‌​​‌​‌‍​‌‌‌​​‌​‍​‌‌‌​​‌‌‍​‌‌​‌​​​‍​‌‌​‌​​‌‍​‌‌‌​​​​‍​​‌​‌‌​‌‍​‌‌​​‌​​‍​‌‌​‌​​‌‍​‌‌​​​​‌‍​‌‌​​‌‌‌‍​‌‌​‌‌‌​‍​‌‌​‌‌‌‌‍​‌‌‌​​‌‌‍​‌‌‌​‌​​‍​‌‌​‌​​‌‍​‌‌​​​‌‌‍​​‌​‌‌​‌‍​‌‌​​​‌​‍​‌‌‌​​‌​‍​‌‌​​‌​‌‍​‌‌​​​​‌‍​‌‌​​​‌‌‍​‌‌​‌​​​‍​​‌​‌‌​‌‍​‌‌‌​​‌​‍​‌‌​​‌​‌‍​‌‌‌​‌‌​‍​‌‌​​‌​‌‍​‌‌​​​​‌‍​‌‌​‌‌​​‍​‌‌‌​​‌‌‍​​‌​‌‌​‌‍​‌‌​​​‌‌‍​‌‌​​​​‌‍​‌‌‌​​​​‍​‌‌​​​​‌‍​‌‌​​​‌​‍​‌‌​‌​​‌‍​‌‌​‌‌​​‍​‌‌​‌​​‌‍​‌‌‌​‌​​‍​‌‌‌‌​​‌⁠

Not a tabletop exercise. Not a simulated incident. An actual breach — with actual data exposure, actual regulatory notification obligations, actual customer impact, and actual board scrutiny. The leaders who have navigated this crucible carry a form of operational intelligence that no certification, no training programme, and no simulation can replicate.

This is why we use incident response history as a primary assessment signal when evaluating CISO candidates for our mandates.

I.What Incident Response Reveals

A breach compresses every leadership capability into a single, high-pressure timeline. Within hours, the CISO must:

**Assess scope and impact** — with incomplete information, under time pressure, while the attack may still be in progress. This requires technical judgment (what systems are affected, what data is exposed) combined with business judgment (what's the financial impact, what are the regulatory implications, what's the customer exposure).

**Coordinate cross-functional response** — security operations, legal, communications, customer service, executive leadership, and potentially law enforcement. Each function has different priorities, different timelines, and different risk tolerances. The CISO must hold the coherence of the response while allowing each function to operate effectively.

**Make regulatory notification decisions** — SEC disclosure (4 business days for material incidents), GDPR breach notification (72 hours), MAS incident reporting (as soon as feasible), DIFC notification requirements. Each jurisdiction has different thresholds, different notification formats, and different regulatory expectations about the level of detail provided. The CISO must make parallel decisions across multiple regulatory frameworks while the facts are still emerging.

**Communicate with the board** — often within hours of discovery, before the full scope is understood. The board wants certainty. The CISO has ambiguity. The communication must be honest about what is known, clear about what is not known, and confident about the response architecture — without overpromising or understating.

**Manage team resilience** — incident response is exhausting. Teams work extended hours under extreme pressure. The CISO must manage burnout, maintain team effectiveness, and make resourcing decisions (bringing in external support, rotating personnel) while personally operating under the same pressure.

II.The IMPACT Framework Applied to Incident Response

Each IMPACT dimension maps directly to incident response behaviour:

**Integration**: Did the CISO maintain coherence across all response functions? Or did the response fragment into isolated workstreams that duplicated effort and created communication gaps? Integration under pressure is the highest-fidelity test of this capability.

**Motivational Archaeology**: What kept the CISO — and their team — performing during an extended incident? Was it fear (regulatory penalty, career risk) or conviction (protecting the organisation, protecting customers)? The motivational foundation predicts not just incident response performance but post-incident resilience.

**Precision Under Ambiguity**: Every decision during a breach is made with incomplete information. The CISO who waits for certainty before acting is the CISO who responds too late. The CISO who acts without sufficient analysis creates secondary damage. Precision under ambiguity is the ability to calibrate — to know how much information is enough to act, and to communicate the confidence level of each decision.

**Accountability Architecture**: Did the CISO build incident response frameworks before the breach? Or were they improvised during the event? The quality of pre-built frameworks — playbooks, communication templates, regulatory notification procedures, escalation paths — reveals the CISO's approach to accountability. Leaders who build these frameworks before they're needed demonstrate anticipatory governance.

**Conviction Depth**: Did the CISO tell the board the truth? Including the uncomfortable parts — scope uncertainty, potential regulatory exposure, remediation timelines that were longer than anyone wanted to hear? Conviction under board pressure during a breach is the ultimate test of this dimension.

**Trust Mechanics**: Did the CISO maintain trust with external stakeholders — customers, regulators, partners — during the breach? Trust during crisis is different from trust during normal operations. It requires a specific communication register: transparency without panic, accountability without blame, confidence without arrogance.

**Pattern Recognition Under Novelty**: Every breach is unique. But the patterns — attack vectors, escalation paths, attacker behaviour — share structural similarities. The CISO who can recognise these patterns while acknowledging the novel elements of each incident makes faster, better-calibrated decisions.

III.How We Use This in Assessment

When evaluating CISO candidates, we systematically explore their incident response history:

We don't ask "describe your incident response process." We ask "tell me about the last time your incident response process failed — and what you changed."

We don't ask "how do you report to the board during an incident." We ask "tell me about a time the board disagreed with your materiality assessment — and how you resolved it."

We don't ask "how do you manage team burnout during incidents." We ask "when was the last time you made a personnel decision during an active incident that you later reconsidered?"

These questions surface the operational scar tissue that distinguishes a CISO who has been tested from one who has been trained.

IV.The Market Implication

CISOs with documented incident response experience at scale — real breaches, real regulatory engagement, real board communication — command a 20–30% compensation premium over CISOs with equivalent technical credentials but no incident history.

This premium is not a reward for having been breached. It's a market valuation of the operational intelligence that only comes from navigating the most consequential test of security leadership.

A tabletop exercise reveals your process. A breach reveals your character. The CISO who has navigated both — and learned from the difference — is the hire that changes your security posture. Not because they prevent breaches. Nobody can guarantee that. But because when the breach comes, they've already built the architecture that contains it.

V.Key Citations

SEC Cyber Incident Disclosure Requirements · GDPR Article 33 — Breach Notification · MAS Notice on Cyber Hygiene · DIFC Data Protection Law — Breach Notification · SANS Incident Response Framework · Mandiant M-Trends 2025 · Verizon Data Breach Investigations Report 2025

Three Ways to Begin a Mandate.

Every engagement starts with alignment. Choose the path that matches where you are.

Confidential · 30 minutes · Partner-led · No obligation

Three candidates, every one we would hire ourselves.

Commission a Search

You know the role. You need the operator. Define what this hire needs to unlock.

Begin AI Assessment

Two weeks of precision diagnostics before committing to a search. Know what you need before you hire for it.

See the Assessment

Submit a brief without your company name. We confirm fit before any details are exchanged.

Request Partner Allocation

A confidential briefing with a resident corridor partner. No gatekeepers, no intermediaries.

Request Partner Allocation

Secure calendar allocation — cross-border mandates only.