Leadership and chaos: 5 mistakes we always see in a cyber crisis
There are moments when everything speeds up. An alert goes off. A service collapses. Nothing responds anymore. And then everyone turns to "management".

There are moments when everything speeds up. An alert goes off. A service collapses. Nothing responds anymore. And then everyone turns to "management".
That is often the moment you grasp something essential: leadership is not measured by the PowerPoints of normal times, but by the silences of a crisis. Here are five mistakes I see regularly. And what they quietly reveal about our relationship with responsibility.
These moments are no longer the exception. In its 2024 cyber threat overview, published in March 2025, ANSSI notes that more than half of its most sensitive defence operations originate in the exploitation of a flaw on security equipment sitting at the edge of the network. The question is no longer whether the crisis will come. It is how you will hold yourself the day it lands.
Should you communicate right away, at the risk of getting it wrong?
In the first hours, silence is a poison. It leaves room for rumours, for anxiety, for internal paranoia. You do not need all the answers. You need to say what you know, what you are doing, and when you will know more. An imperfect word beats an absence of direction. Internal communication is not an option. It is a tool for stabilisation.
ANSSI says nothing different. Its guide "Anticipating and managing your cyber crisis communication", published in June 2026, devotes an entire section to steering internal communication and sets out, in black and white, the traps to avoid. A cyber crisis, the agency defines there, is "the immediate and major destabilisation of an entity's day-to-day functioning": it calls for a reaction fitted to the moment, not for the reflexes of calm times.

Can you delegate crisis management to your provider?
"The managed services provider has it." "We are waiting for the CERT report." "The CISO is handling it." No. In a crisis, you are exposed. Your organisation. Your image. Your customers. You cannot outsource your responsibility even if you have outsourced your infrastructure. Leadership means staying present. Asking questions. Making the calls. Carrying the message.
It is no accident that the reference guides address leaders first, and not only technical teams: executive management, chief of staff, secretary general. A cyber crisis is a board-level subject, not a ticket you forward to support.
Should you trust the processes or your teams when everything collapses?
Many crisis plans look like aircraft flight manuals. Complex. Unusable in flight. In reality, a crisis is people under pressure, working with partial information, who have to improvise fast and well. If you only watch the metrics, you miss the state of your troops. The fatigue. The panic. The fog. A good leader does not just manage the incident. They keep an eye on the nervous strain. They support, steady and calm. Not in guru mode. In useful mode.
The human factor is not a detail of the crisis, it is its core. Year after year, Verizon's Data Breach Investigations Report is a reminder that the most frequent causes of breaches remain massively human: social engineering, phishing, stolen credentials. And the exit from a crisis, as ANSSI points out, often stretches far beyond the technical incident. In other words, your teams will be holding the line for days, sometimes weeks. Relief rotations and morale are steered like everything else.
Should you hunt for someone to blame while the fire is burning?
This reflex runs deep. Looking for who clicked. Who approved. Who mishandled it. But in the thick of a crisis, this need to point fingers slows everything down. It blocks communication. It silences the weak signals. It isolates the good instincts. The time for the after-action review will come. But during the storm, you manage. Together. Then you learn.
Do you need to understand everything before deciding?
The fantasy of "zero risk" drives inaction. You want more information, more sign-off, more analysis. Meanwhile, the situation spirals. An imperfect decision now is often better than an excellent decision too late. Leadership is not about knowing everything. It is about setting a clear direction, even a provisional one, so others can act.
Here again, official doctrine meets the ground truth. Guillaume Poupard, then director general of ANSSI, sums it up in a single sentence in the guide "Cyber crisis, the keys to operational and strategic management": "You cannot improvise responses in the middle of a disaster! Preparation, tooling and training are indispensable." Deciding fast is not deciding at random: it is the fruit of preparation done beforehand.
What I take away, every time
A crisis reveals. Not the CVs. Not the org charts. The postures. The fears. And the ability to stay useful when everything shakes. What we call "leadership" has nothing mystical about it. It is a human skill. Accessible. Trainable. Indispensable. But it cannot be improvised.
For ANSSI, it has even become a necessity rather than merely an opportunity: training for cyber crisis management, through regular exercises, is the only way to be ready the day the real one lands. You do not discover your composure in the middle of an attack. You prepared it, or you did not.
Discover my appearances in the media
Sources
- Crisis communication, silence and traps to avoid: ANSSI, "Anticiper et gérer sa communication de crise cyber", 2026 (in French).
- The role of leaders, preparation and the impossibility of improvising: ANSSI and CDSE, "Crise d'origine cyber, les clés d'une gestion opérationnelle et stratégique", 2021 (in French).
- Training for crisis management, a necessity: ANSSI, "Organiser un exercice de gestion de crise cyber", 2020 (in French).
- Origin of attacks and structural threat: ANSSI, "Panorama de la cybermenace 2024", March 2025 (in French).
- Human factor in data breaches: Verizon, Data Breach Investigations Report, 2026.
Frequently asked questions
Why is silence dangerous in the first hours of a cyber crisis?
Because it leaves room for rumours, anxiety and internal paranoia. An imperfect word, saying what you know and what you are doing, is better than an absence of direction. The ANSSI guide on cyber crisis communication, published in June 2026, devotes a whole section to internal communication.
Can crisis management be delegated to your provider or to the CISO?
No. Outsourcing the infrastructure does not outsource the responsibility. The leader stays exposed for their organisation, their image and their customers, and must stay present to ask questions and make the calls. The ANSSI guides are in fact addressed first of all to executive management.
Should you look for who is responsible for an incident during the crisis?
No. Hunting for someone to blame while the fire is burning slows everything down, blocks communication and silences the weak signals. The after-action review comes after the storm.
Do you need to understand everything before deciding in a crisis?
No. The fantasy of zero risk drives inaction while the situation spirals. An imperfect decision now is often better than an excellent decision too late.
Is crisis leadership an innate gift?
No. It is a human skill, accessible and trainable, but it cannot be improvised. A crisis reveals your posture and your ability to stay useful.
Is cyber crisis management something you prepare, or something you improvise?
You prepare it. Guillaume Poupard, then director general of ANSSI, sums it up like this: "You cannot improvise responses in the middle of a disaster! Preparation, tooling and training are indispensable." Training through regular exercises is what makes it possible to decide fast when the day comes.
Is the human factor really central in a cyber crisis?
Yes. Verizon's Data Breach Investigations Report is a yearly reminder that breaches remain massively linked to the human factor: social engineering, phishing, stolen credentials. Steering the state of your teams is not a soft extra, it is the core of crisis management.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
