In a national-scale incident, technical correctness does not automatically create authority.
Someone must decide.
Cybersecurity teams may be responsible for protecting networks.
Operations teams may be responsible for keeping services running.
Facility safety organizations may be responsible for preventing physical harm.
Emergency authorities may be responsible for the wider national impact.
Their responsibilities overlap, but they are not identical.
This creates situations in which two different decisions can both be rational.
A cyber command may need a compromised system taken offline.
A safety authority may need the same system restored to its last verified operating state.
Neither side has to be incompetent for conflict to occur.
This section explores incident command, change authorization, emergency authority, independent safety oversight, and what happens when different organizations are responsible for protecting different kinds of risk.