GoFirm
Back to Blog
Case Studies·3 min read

The NCSC Told CNI Operators to Define Decision-Making Authority. Here Is What That Requires.

By GoFirm

The UK National Cyber Security Centre published guidance this year for Critical National Infrastructure operators on preparing for severe cyber threats. It covers four activity areas: planning, situational awareness, hardening defences, and withstanding and recovering from attack.

Buried in Activity 4, under preparations for adaptability, is a single line that most readers will pass over. It reads: “Establish decision-making authority - define who can authorise each measure and under what circumstances.”¹

That line is the entire problem.

The guidance correctly identifies that when a severe cyber threat materialises — when an adversary is inside the network, when critical systems are being shut down, when the organisation is operating under immense pressure — the organisations that respond best are the ones that made their decisions in advance. Risk decisions made with cool heads, before the crisis, not reactive judgements made under fire.

The extraordinary defensive measures the NCSC describes are not trivial. Islanding a network - cutting it off from external connectivity - disrupts operations. Forcing organisation-wide credential resets affects every user. Isolating OT systems from enterprise IT may halt physical processes. The guidance is explicit: senior leadership must understand the trade-offs, and step-by-step instructions for each defensive action must include “required approvals.”

Required approvals. From named authorities. Confirmed in advance of the crisis and verifiable at the moment of execution.

The guidance does not specify what that confirmation mechanism looks like. In most organisations it defaults to email, phone, or verbal instruction - the same channels that, in a severe cyber threat environment, may be compromised, spoofed, or simply unavailable. The NCSC guidance itself notes that organisations should “ensure redundancy for internal communications…in case existing channels are rendered unavailable.” It also notes that “tired, stressed people make poor decisions during crises.”

Both of those observations point to the same gap. When the authorisation for a consequential defensive action travels through the same channels the adversary may be monitoring or has compromised, the approval is not verified. It is assumed. And in CNI environments, an assumed approval for a network isolation or a credential revocation that turns out to have been spoofed or miscommunicated is not a minor inconvenience. It is an operational catastrophe.

GoFirm provides the mechanism the NCSC guidance requires but does not name. Every consequential defensive action - network segmentation, system isolation, credential invalidation, OT shutdown - is configured as an action type requiring confirmation from the named authority responsible for that measure. When the moment arrives, GoFirm routes a confirmation request to that authority on their registered personal device, through a channel entirely separate from the operational environment under threat. The authority confirms with their biometric. The action proceeds. The confirmation is signed, timestamped, and written to an immutable audit trail.

The NCSC guidance says to define who can authorise each measure and under what circumstances, and to agree this in advance. GoFirm is how that agreement becomes a verifiable, enforceable control rather than a documented intention that dissolves under pressure.

Critical national infrastructure operators are being told to prepare now, before the threat escalates. The authorisation boundary is part of that preparation. It should be built before it is needed, not improvised when the network is already under attack.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. National Cyber Security Centre, How to prepare for and plan your organisation’s response to severe cyber threat: a guide for CNI, 2026, Activity 4.1

Share this article