All articles
Human Incident Response: The Next Evolution of Cybersecurity Leadership
Cybersecurity strategists Ty Hughes and Jothi Dugar explain how their Human Incident Response plan keeps responders functioning through weeks-long breaches.

Make The Security Digest one of your go-to sources on Google
We build incident response plans for compromised systems all the time. We don't always do that for compromised human capacity, and that's the blind spot.
Security teams engineer single points of failure out of their systems, then route a six-week incident through one exhausted incident manager and never account for that person as the same kind of risk. A prolonged breach is decided by judgment, and that is the first capability exhaustion takes. The leaders closing that gap treat responder capacity as part of the response itself, planned and protected before the pressure arrives.
Ty Hughes and Jothi Dugar built Human Incident Response (HIR) around that problem, a plan that runs alongside the technical work of containment and recovery and keeps the people doing it from breaking down first. Hughes, known in the field as the "AI Alchemist," is a transformational technologist with nearly two decades spent helping organizations navigate complexity through human-centered technology leadership and a President's Management Council Interagency Rotation Fellow. Dugar, an executive strategist and international bestselling author with more than 25 years at the intersection of technology, cybersecurity, and human-centered transformation, is widely known as Jojo D., "The Chaos Guru."
Their work over the past several years has pushed security teams to treat the people behind the systems as something worth protecting. "We build incident response plans for compromised systems all the time. We don't always do that for compromised human capacity, and that's the blind spot," Hughes says.
Second in command
One of the practices Hughes leans on is something he calls Acting in Place. For a set window, a leader stays physically in the building handling administrative work but steps out of the decision-making seat entirely, and a designated deputy carries every operational duty in their place. He uses it on purpose with staff who are not yet ready to hold the full operation, treating the planned absence as the thing that grows them into it.
"She's unavailable unless there's an emergency. Someone has been assigned to act on her behalf, and they go through and carry out all the duties," Hughes says. He has run it with his own teams for years, and the payoff shows up on ordinary days as much as hard ones. A leader can take a vacation or a mental health day without the operation stalling. By the time an emergency makes someone unreachable, the handoff has already been rehearsed, and the gaps surface when the cost of finding them is low.
Built-in backup
The deputy who steps in is building toward their own next role. Hughes frames the experience as a credential a person can carry forward, proof they have run the operation under real conditions. "It does wonders in training staff up, giving them that level of confidence," Hughes says. The organization gets a deeper bench out of the same arrangement, with more than one person fluent enough to take the lead, so no individual becomes the point everything routes through.
Adversaries do not pause for weekends or holidays, and the average breach still takes 241 days to identify and contain, the better part of a year from first alert to all clear. A crisis on that timeline cannot sit with one incident manager.
You have better coordination, you have better team resilience, you're actually faster."
- JoJo D., "The Chaos Guru," Cybersecurity Strategist
"If the incident lasts four weeks, it's not fair to put one person on call for two months at a time. With people acting in place, you keep shifting every eight hours, so you have multiple people on the team well versed on the incident versus just one leader," Dugar says. The plan also writes in mandatory recovery time, so a responder who loses a weekend to a crisis is not expected back at full speed on Monday.
Permission to pause
Dugar watches for strain long before an incident starts. She treats compassionate leadership as a diagnostic instrument as much as a management style, and one of her routines is a brief check-in at the top of meetings, often called a rose and a thorn, where each person names something good in their life and something they are struggling with. It takes a few minutes and gives a leader a baseline read on the room. "If this person doesn't normally act this way, there must be something going on," Dugar notes. The check-in is there to catch when a capable person is quietly carrying something heavy, a sick child or a family emergency that raises the cognitive load they walk in with.
Inside an incident, that load compounds and lands on judgment first. Exhaustion rarely stops a responder from working. It slows their decisions and narrows what they notice, so the subtle indicator that should redirect an investigation slips past. Dugar builds her next intervention to counter that directly. Pausing in the middle of a breach sounds counterproductive, and resistance is the first thing she runs into when she introduces it. She installs the pause regardless. The whole team takes a mandatory 10-to-15-minute reset every four hours, fully away from screens, with no email and no dashboards, long enough to walk or breathe and clear the head before going back in. She compares it to a NASCAR pit stop, where even the leading car surrenders track position for tires and fuel because the car that never stops loses the race. "You have better coordination, you have better team resilience, you're actually faster," Dugar says of teams that build the resets in.
The discipline extends past the incident itself. When a responder has lost a weekend to a crisis, the plan treats the days that follow as operational maintenance, the same care a team gives any system it has just pushed past its limits. Returning someone depleted to a full inbox and a stack of postponed work only moves today's fatigue into the next incident. "You actually take some time off for yourself," Dugar adds.
The cape comes off
Hughes has grown wary of a culture that prizes constant heroics. He still recognizes extraordinary effort, but he no longer lets it pass without examination. When someone goes above and beyond, he follows the applause with a question about what made the heroics necessary, and whether missing redundancy forced one person to carry too much. "A lot of times we have confused exhaustion with commitment, and we call it cyber culture," Hughes says.
A repeated pattern of last-minute saves reads to him as an early signal that something structural has gone wrong. The same instinct that keeps a leader from running critical systems without a backup, he argues, belongs with the people running the response, and most of the work is planning for human limits in advance, while the stakes are still low.
For Hughes, the goal is to make heroics the rare exception they are meant to be. "I want to reduce the number of times that someone has to be a hero for us to be successful. If a person or persons are constantly being the hero, that's an indicator for me that burnout is quite possibly around the corner," Hughes says.
The people who defend an organization are critical infrastructure, no less load-bearing than the systems they protect, and planning for their limits is what keeps the cape in the closet on all but the worst days. "I don't want them to put that cape on except for those extreme emergency moments. And then when they take that cape off, we've got to identify what was the situation that required them to put the cape on to begin with," Hughes says.






