When Cyber Risk Becomes Operational Risk: Who Is Actually In Control?
A practical leadership framework for clarifying authority, sustaining critical services, coordinating escalation, and strengthening recovery when a cyber incident reaches physical operations.
When cyber risk affects physical operations, technical containment is only one part of the response.
Leadership must also understand the wider impact. As a result, the organization must protect critical services, coordinate decisions, communicate clearly, and maintain control through disruption.
A Cyberattack Reached Physical Operations
In July 2026, a coordinated cyberattack targeted operational technology at more than 30 community water systems in Minnesota. [1]
However, officials later clarified what “impacted” meant. Investigators had confirmed malicious activity involving a system’s technology. It did not mean that every community lost water service. [2]
Michigan also reported cyberattacks affecting nine water systems. According to a state official, all nine continued to operate safely, and there were no known public health concerns. [3]
A community relied on stored water during the disruption
In Braham, Minnesota, attackers shut down operating controls. As a result, the community’s well and water treatment plant went offline for a short period.
The community relied on its tower reserves until operations were restored, and officials reported no concerns about drinking-water quality. [3]
Attribution had not been confirmed
In Minnesota’s July 30 update, investigators had not publicly attributed the activity to a specific actor. [2]
In addition, state officials said that similarities among the incidents did not prove that the same source was responsible for them all. [2]
From Technical Incident to Operational Disruption
Qualified cyber, information technology, operational technology, engineering, and incident response personnel manage the technical investigation and repair.
Because operational technology, often called OT, supports physical equipment and processes, an incident affecting OT may also disrupt the service, facility, or process that depends on it. [4] [5]
The effects can spread beyond technology
Depending on the organization, leaders may need to manage: [4] [5]
- Disruption to essential services or physical processes.
- Uncertainty about whether operating data can be trusted.
- Manual or reduced operating conditions.
- Worker, public, asset, or environmental protection.
- Regulatory, contractual, and government coordination.
- Reliance on vendors, contractors, and outside specialists.
- Employee, customer, community, and public communication.
- Recovery, restart, and return-to-performance decisions.
Can the organization make the necessary operating decisions quickly and maintain control while technical specialists restore the affected systems?
Connect leadership with operating reality
NIST describes incident response as part of wider cyber risk management. It also recommends connecting response work across the organization. [4]
Ventari Global’s approach connects board-level governance with operational execution across complex, high-risk environments.
As a result, technical response, operating decisions, executive oversight, continuity plans, communication, and recovery should support the same goals.
1. Clarify Roles and Decision Authority
A technical incident can move faster than the normal approval process.
If authority is unclear, operational teams may wait for executives. Meanwhile, executives may wait for technical certainty.
As a result, different locations may make conflicting decisions.
Know who may be involved
The guidance identifies several possible participants in an incident response. For example, these include leaders, incident handlers, technology teams, legal advisers, communication teams, facilities teams, system owners, suppliers, and outside agencies. [4]
However, the exact roles will differ by organization and by incident.
Define the technical role
Depending on the incident, qualified technical personnel may: [4] [5]
- Confirm and investigate the incident.
- Identify affected technology and systems.
- Collect and protect technical evidence.
- Contain malicious activity.
- Check whether affected systems can be trusted.
- Repair compromised technology.
- Advise on technical restoration.
Define the operational role
Operational leaders may need to: [5]
- Assess the effect on physical processes and services.
- Place operations in a controlled state.
- Start approved manual or reduced procedures.
- Coordinate operators, engineers, contractors, and vendors.
- Decide whether work can continue safely.
- Escalate conditions that exceed local authority or skill.
Define the executive role
Executive and crisis leaders may need to: [4]
- Activate the wider crisis or emergency structure.
- Set organization-wide priorities.
- Assign resources and outside support.
- Approve major operating decisions.
- Coordinate legal, regulatory, customer, public, and government duties.
- Oversee recovery and return-to-performance decisions.
Assign decision rights before the incident
Before an incident, leadership teams should decide who can:
- Declare a cyber incident.
- Activate crisis or emergency plans.
- Move operations into a manual or reduced state.
- Reduce or stop an essential process.
- Bring in cyber, engineering, legal, or emergency specialists.
- Contact regulators, police, or public authorities.
- Approve employee, customer, community, or public updates.
- Authorize system reconnection.
- Approve the return to normal operations.
This list applies guidance on roles, authority, notification, manual operations, outside support, and recovery. [4] [5]
A contact list is not a command structure.
Instead, the organization needs clear roles, backup contacts, escalation routes, and communication methods that still work when normal systems fail.
2. Connect the Cyber Plan With the Operational Response
A cyber incident plan should connect with emergency, continuity, operating, communication, and recovery plans rather than sit apart from them.
Connect mission-critical systems to operating plans
EPA advises water utilities to identify mission-critical IT and OT systems. It also tells them to record what those systems do and who is responsible for them. [5]
In addition, it advises utilities to account for possible operating effects in their emergency plans. [5]
Bring related plans together
During an incident, a connected response may include:
- Cyber and technical incident response.
- Operating and engineering procedures.
- Emergency and crisis management.
- Business continuity.
- HSEQ and critical-control plans.
- Legal and regulatory reporting.
- Contractor and vendor coordination.
- Executive and public communication.
- Recovery and restart procedures.
Together, the guidance supports an organization-wide response that connects cyber actions with emergency, operational, communication, and recovery planning. [4] [5]
Keep the structure practical
The exact structure should reflect the organization’s risks, resources, duties, and operating environment.
For example, the joint CISA, FBI, and EPA guide notes that no two utility incident-response plans are the same. Plans depend on each utility’s individual characteristics and reporting obligations, while utilities also differ in resources, size, location, and ownership structure. [6]
Therefore, the goal is not to create one oversized procedure.
The goal is to make sure every relevant plan supports the same decisions during the same incident.
3. Identify What Must Be Protected and Maintained
Business continuity does not mean continuing every activity under every condition.
Instead, it means understanding which services are essential. Leaders can then decide how to protect, sustain, or restore them without creating new risk.
Map essential services and functions
Before an incident, organizations should consider identifying:
- Essential services and operating goals.
- Physical processes that depend on IT or OT systems.
- Systems needed for monitoring, control, communication, or safe shutdown.
- People responsible for each essential function.
- Internal and outside dependencies.
- Suppliers, vendors, contractors, and public resources that may be needed.
- Functions that can operate manually or at a reduced level.
- Functions that must stop when technology is unavailable or cannot be trusted.
- The authority needed to make those decisions.
The guidance recommends understanding essential goals, services, assets, and outside dependencies. As a result, this information helps organizations set response and recovery priorities. [4]
Focus on the operating outcome
This review should focus on the physical process or service supported by the technology.
In other words, a list of devices and software is not enough.
Test the dependencies
An operational response may fail because a supporting need was missed.
For example:
- Operators may know how to run equipment manually but lack current printed procedures.
- Backup communication may exist but fail to reach contractors or remote teams.
- A facility may have backup power but not enough fuel or maintenance support.
- A remote site may keep running but lose central monitoring.
- A replacement system may be available but not approved for use.
- Technical systems may return before operations confirm that the physical process is stable.
These examples apply guidance on essential services, outside dependencies, manual operation, communication, and recovery. [4] [5]
As a result, organizations should test these dependencies together. They should not review each department or plan on its own.
4. Prepare for Manual and Reduced Operations
Manual operation may help an organization maintain essential functions when automated controls or communication systems fail.
However, the instruction to “switch to manual” is not a complete plan.
Understand what manual operation requires
Manual operation may therefore require different staffing, skills, supervision, procedures, records, communication methods, and operating limits.
EPA advises water utilities to train essential staff to perform mission-critical work when business, process-control, or communication systems are disabled. [5]
In addition, its guidance covers the manual operation of water collection, storage, treatment, and conveyance systems. [5]
Confirm what can continue safely
Depending on the facility, leaders should consider: [5]
- Which processes can operate manually.
- Which processes cannot continue safely without automation.
- Who is trained and approved to do the work.
- Whether qualified staff are available when needed.
- Whether procedures and operating information are available offline.
- How teams will monitor conditions without the normal interface.
- What extra checks or supervision are needed.
- How long the reduced arrangement can continue.
- Which conditions require reduction or shutdown.
However, each facility should adapt them to its own systems. Qualified operating, engineering, and technical personnel should also review them.
Exercise the loss of capability
The guidance recommends drills that prepare staff to maintain essential work when key systems fail. [5]
For example, an exercise may test the loss of:
- Automated process controls.
- Remote monitoring.
- Email, telephone, or messaging systems.
- Electronic operating procedures.
- Vendor access.
- Selected process or operating information.
These examples apply established planning, communication, manual-operation, and exercise principles. [5] [6]
The purpose is not to prove that the plan works.
Instead, the purpose is to find weaknesses before a real incident occurs.
Know who decides before disruption reaches a critical process.
When authority is unclear, teams lose time, decisions stall, and disruption can escalate before the right response is activated.
5. Define Escalation Conditions
A direction to “escalate when necessary” leaves too much room for judgment during a fast-moving incident.
NIST recommends setting methods for ranking cyber risks. In addition, it advises organizations to consider operating, safety, reputation, and other business effects. [4]
Use triggers that lead to action
Possible triggers will vary by organization. For example, they may include: [4] [5]
- Loss of control or visibility over a physical process.
- Doubt about whether operating data can be trusted.
- Failure or loss of an important safeguard.
- Loss of communication with an operating site.
- Inability to maintain an essential service.
- Operation outside approved limits.
- Long-term reliance on manual or reduced processes.
- Possible effects on workers, communities, assets, or the environment.
- A legal, contract, police, or public-notice duty.
- An incident affecting several sites or regions.
- A decision that exceeds the local team’s authority or skill.
However, they are not universal legal thresholds. Each organization should set its own triggers based on its hazards, duties, and operating conditions.
Connect every trigger to a decision
Each trigger should lead to:
- A clear action.
- A named decision-maker.
- A communication route.
- A clear next review point.
Together, these elements should reduce uncertainty rather than create another layer of discussion. [4]
Escalation should move the response forward rather than simply create another meeting.
6. Give Leaders a Decision-Ready View
Senior leaders do not need every technical alert, system log, or investigation detail.
Instead, they need clear information about the effect on operations and the decisions within their authority.
In addition, the guidance recommends coordinating response work across internal and outside groups and keeping senior leaders informed during major recovery work. [4]
Separate facts from uncertainty
First, the update should show what the organization has confirmed.
Next, it should explain what is still unknown and why that uncertainty matters.
Report the information leaders need
Depending on the incident, an executive update may include: [4] [5]
- The locations, systems, operations, and services affected.
- Confirmed facts and key unknowns.
- Current worker, public, asset, and environmental conditions.
- The physical processes that depend on affected systems.
- The controls and workarounds now in use.
- Controls that are unavailable, weak, or unverified.
- Whether manual or reduced operations can continue.
- Operating, legal, contract, customer, or community effects.
- Actions already taken and who approved them.
- The next trigger or decision point.
- Resources or outside support required.
- Current recovery limits and restrictions.
Keep the report focused on decisions
The executive summary does not replace detailed technical, engineering, legal, or police reporting.
It should remain concise enough to support action while still showing the evidence behind each decision.
More information does not create control if leadership cannot determine what it means for the operation.
7. Coordinate Communication Carefully
A cyber incident affecting physical operations may involve many groups.
For example, these may include employees, contractors, suppliers, customers, communities, regulators, public authorities, insurers, legal advisers, police, and the media. [4] [5]
Although different audiences need different details, the main facts and decisions should remain consistent.
Set communication authority
Water-sector guidance advises utilities to maintain important contacts, notify relevant personnel, meet reporting duties, communicate with connected organizations, and record response actions. [5]
Therefore, organizations should decide who can: [4] [5]
- Communicate with employees and contractors.
- Notify regulators and public authorities.
- Contact customers or affected communities.
- Coordinate with legal advisers, insurers, police, and outside specialists.
- Communicate with key vendors and suppliers.
- Approve public statements.
- Issue updates when normal systems are unavailable.
Explain what is known
Effective updates should explain:
- What the organization has confirmed.
- What remains under investigation.
- Which operations or services are affected.
- What actions people need to take.
- Which limits or precautions apply.
- When the next update will occur.
Avoid unsupported claims
Meanwhile, organizations should avoid claims about:
- The identity or motive of the attacker.
- The full scope of the incident.
- The reliability of systems still being checked.
- The time needed for full recovery.
- The absence of risk before reviews are complete.
These limits support accurate communication while technical and operating reviews continue. [4] [5]
8. Control Recovery and Return to Performance
Restoring access to a system does not, however, mean that the operation is ready to return to normal.
NIST therefore recommends checking restored assets, restoring essential services in the right order, working with system owners, monitoring restored systems, and defining when recovery is complete. [4]
Check the technology
Qualified personnel should first assess the affected technology.
In addition, backups and recovery tools should be checked for damage or compromise.
Check the physical operation
Operational personnel should then confirm that: [4]
- The relevant systems and services work as intended.
- Operating information can be trusted.
- Required safeguards and critical controls are available.
- Essential services returned in the right order.
- System owners and operational leaders confirmed the restoration.
- Affected personnel understand temporary limits.
- The restored environment can be monitored.
Approve the return to normal
The organization should ultimately define who can approve the return to normal operations.
Technical personnel should confirm the technical recovery within their field. Meanwhile, operational personnel should confirm that the physical process is ready.
Therefore, the final decision should combine technical evidence with operational confirmation.
Pressure to resume service should not replace evidence.
9. Review the Response and Strengthen the System
Even after the immediate disruption ends, recovery is not complete.
EPA recommends preparing an after-action report that documents response activities, successes, and areas for improvement. It also recommends creating an improvement plan and using it to update the utility’s vulnerability assessment, emergency response plan, and contingency plans. [5]
NIST similarly treats lessons learned and ongoing improvement as part of incident response. [4]
Review detection and escalation
Leaders should first ask:
- Was the incident found and escalated quickly enough?
- Did teams understand the escalation triggers?
- Did the right people have enough authority?
Review roles and operating control
Leaders should also ask:
- Were technical, operational, and executive roles clear?
- Could essential processes operate safely at a reduced level?
- Were manual procedures current, available, and useful?
- Did leaders receive information they could act on?
Review communication and recovery
The review should then ask: [4] [5]
- Were regulators, authorities, employees, contractors, and other groups contacted properly?
- Were decisions, assumptions, and approvals recorded?
- Did the restart rely on evidence?
- Which controls, skills, resources, or outside services were weaker than expected?
Turn the review into action
The review should produce clear actions, named owners, due dates, and a process for checking completion.
However, leaders should not decide that the response worked simply because the organization avoided serious harm.
The absence of harm does not prove that every control worked as intended.
Use Independent Review Where Needed
Where confidence remains incomplete, an independent Audit & Assurance review can test the evidence, identify gaps, and clarify what should be strengthened.
Through Enterprise Advisory and the Ventari Summit™ Framework, Ventari Global helps boards and executive teams strengthen governance, decision authority, critical controls, crisis preparedness, and recovery when cyber incidents affect operations.
Technical investigation and remediation remain with qualified cyber, IT, OT, engineering, and incident-response specialists.
Operational Control Is Tested Under Disruption
A cybersecurity procedure does not prove that an organization can manage the operating effects of an incident. For boards and executive teams, the real test is whether governance, critical controls, response plans, and recovery arrangements will hold when disruption reaches physical operations.
Organizations that establish these arrangements before an incident are better positioned to protect critical services, make timely decisions, and maintain control through recovery.
References
Incident reports and official updates
- Minnesota IT Services, MNIT Activates Statewide Cybersecurity Response to Support Affected Communities and Protect Critical Infrastructure. July 28, 2026. Accessed August 5, 2026.
- Minnesota IT Services, Minnesota Continues Response to Cyber Activity Affecting Community Water Systems. July 30, 2026. Accessed August 5, 2026.
- The Associated Press, FBI Investigates as Michigan Joins Minnesota in Reporting Cyberattacks on Its Water Systems. August 1, 2026. Accessed August 5, 2026.
Response, recovery, and sector guidance
- National Institute of Standards and Technology, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. NIST Special Publication 800-61 Revision 3. April 2025. See sections 2.2 and 3.1–3.2. Accessed August 5, 2026.
- U.S. Environmental Protection Agency, Water Sector Incident Action Checklist: Cybersecurity. October 2024. See pages 2–5. Accessed August 5, 2026.
- Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation and U.S. Environmental Protection Agency, Incident Response Guide: Water and Wastewater Sector. January 2024. See section 2.1.1. Accessed August 5, 2026.
Disclaimer: This article provides general guidance on governance, crisis readiness, and operational recovery. It is not a substitute for cybersecurity, engineering, legal, regulatory, or emergency-response advice. Organizations should follow the requirements and procedures that apply to their operations and engage qualified specialists where needed.
Strengthen Operational Control Before Disruption Escalates
Ventari Global helps organizations improve governance, critical controls, crisis readiness, and recovery through disruption.
