When an incident needs executive decision-making, the question most organisations get wrong is not when to notify someone senior. Escalation policies route incidents upward based on severity tiers and notification chains, but they rarely establish what the executive is supposed to decide once they arrive. That gap turns executive involvement into a cost the organisation absorbs without measuring.

In 2014, the Ponemon Institute surveyed more than 600 IT security practitioners across the United States about senior executive involvement in breach response. Seventy-nine per cent said involvement was necessary. When asked what the executive should actually decide once they were in the room, most organisations had no answer.

The survey covered IT security, but the pattern is the same wherever escalation matrices exist. I have watched it play out in manufacturing and in hospital management: the incident team stops working the problem and starts preparing a briefing, the executive arrives and asks questions the team has already resolved, and the response stretches while authority sits in the room without a defined purpose. This is the pattern that makes leadership under pressure expensive: seniority does not improve a decision when the senior person has no defined question to answer.

An incident needs executive decision-making when the response requires committing resources or organisational direction that exceeds the incident commander's authority, and no existing delegation or policy covers the gap.

What Only an Executive Can Decide During an Incident

An executive has a defined role during an incident in two situations: when the response requires committing resources that exceed the incident commander's delegated budget or staffing authority, and when the response will bind the organisation to a regulator or major customer in a way only a senior leader can authorise. Outside those two situations, the incident commander is better placed to decide, and routing operational questions upward wastes executive attention while extending the response time.

The Universal Decision-Making Method asks a direct question before any decision: what do you need to be sufficiently certain about before you act? Applied to incident escalation, that question replaces the severity matrix with a decision-quality test. If the incident commander can identify the assumptions the response depends on and has the authority to act on them, the executive does not need to be in the room.

If one of those assumptions requires authority the commander does not have, that specific assumption is the reason to escalate, and the executive arrives knowing exactly what they are being asked to decide.

Name the decision your escalation policy expects the executive to make during the next incident, before the severity matrix routes the call. Start the Walk →

What Escalation Policies Actually Specify

The standard escalation matrix specifies who hears about an incident at each severity level. It does not specify what any of them should decide once notified. The team handles routine events internally; for serious disruptions, a director or vice-president receives a call.

I once asked a CIO who had just redesigned his organisation's escalation procedures whether the new matrix defined what the executive would decide once they arrived. He said the executive's role was to "provide oversight and support." I pressed him: when the server room is offline and the team is working the restoration, what does "provide oversight" mean in practice? He could not say. "Provide oversight" describes a notification function; it tells the executive to be present without specifying what they will decide. That gap is precisely what the Ponemon survey documented across more than 600 organisations.

A notification tells someone something has happened; a decision commits resources, accepts a trade-off on behalf of the organisation, or changes direction in a way the incident team cannot do alone. When an escalation policy treats these as interchangeable, the executive appears for every serious incident regardless of whether it presents a question only they can answer.

The result follows the same pattern each time: the executive receives a briefing and ratifies whatever the team was already doing, having added delay without adding judgment. That is the boundary problem risk management should have resolved before the first call went up the chain.

There is a related failure I encounter repeatedly in escalation reviews. An incident occurs, and the first response from leadership is: "The audit did not flag this." That statement treats the absence of a finding as evidence of safety, and it short-circuits the escalation decision: if the audit was clean, there was nothing to escalate.

But an audit checks what it was designed to check, at the interval it was scheduled to run. If the incident arose from a condition the audit was never designed to detect, the clean report tells you nothing about whether this incident needed executive authority. The real question for any high-stakes decision during an incident is whether the monitoring system was watching the assumption that actually failed, not whether a prior audit gave the organisation permission to stop looking.

Incident escalation decision path showing when executive decision-making is needed versus operational response
When an incident needs executive decision-making depends on the decision, not the severity
Click to expand

When Executive Authority Distorts the Incident Response

Executive involvement does not just add time to an incident response; it changes what people in the room are willing to say. A 2023 empirical study in the Journal of Safety Research documented how authority bias operates during incident investigations: when senior figures participated, investigation teams deferred to their initial interpretation of events even when physical evidence contradicted it. The higher-ranking person's framing became the conclusion before the analysis was complete.

NASA's Columbia disaster in 2003 is the catastrophic version of this pattern. During the mission, engineers identified potential foam-strike damage to the shuttle's thermal protection system and requested satellite imagery to assess the risk. Management deprioritised the request. The Columbia Accident Investigation Board concluded that NASA's organisational culture treated institutional status as more authoritative than technical expertise. The engineers had the data and the concern; the executives had the authority and the schedule. Seven crew members died on re-entry because the authority overruled the data.

When an executive enters an incident response, the information environment shifts. The people preparing the briefing begin filtering for what they believe the executive wants to hear, and assumptions that would have been questioned among peers become conclusions that nobody challenges because the person who stated them outranks everyone else in the room. That distortion is invisible from the executive's perspective; the briefing they receive already reflects their assumed preferences, so they have no way of knowing what was filtered out before it reached them.

The Overhead That Arrives With the Executive

Beyond the distortion of what people are willing to say, executive involvement pulls the response team off the problem and into briefing preparation, and most organisations treat that overhead as inevitable.

Liquid Web documented in 2024, drawing on years of managing infrastructure incidents, what happens when executives enter an active response: the incident team begins preparing status updates for the executive instead of resolving the problem, and the dynamic of recommendations shifts so that options are framed to protect the recommender rather than to close the incident. The response gets slower in direct proportion to the seniority of the person observing it.

A story from the First World War has stayed with me because it captures something about communication chains that severity matrices will never account for. A message was sent down the line: "Send reinforcements, we are going to advance." By the time it reached its destination, it had become: "Send refreshments, we are going to a dance." The communication chain worked at every link; the content was destroyed in transit.

When an executive receives a briefing during an incident, the same degradation applies. Each person between the incident commander and the executive summarises and adjusts emphasis, dropping what they consider unimportant. The briefing that reaches the executive is a processed version of what the responders actually know, stripped of the context that would let the executive evaluate it properly. This is why a crisis playbook should define what information survives the chain, not merely whom the chain connects.

The difference between a useful escalation and an expensive interruption is whether the policy defines what the executive is being asked to decide before the incident arrives.

You could follow the escalation policy and still leave no one knowing what the executive should decide.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.