Resolve the channel paradox first
A cyber incident can affect the systems normally used to alert and coordinate the response. If the identity provider is compromised, a successful sign-in may no longer establish the identity expected. If email is affected, an invitation to a replacement channel may itself be manipulated.
The incident plan therefore needs an agreed switch condition and an independent way to confirm the replacement location, participants and trust anchors. A second messenger without independent verification merely moves the problem.
- Which systems are untrusted in this scenario?
- Who can declare and end the trust transition?
- How are destination and participants confirmed out of band?
- Which data may be processed in the fallback channel?
