A technical playbook answers "what do we do." It rarely answers "who decides."
Many organizations have some version of a technical incident response plan - isolate affected systems, restore from backup, call a specialist. Far fewer have decided, in advance, who has the authority to make the calls that actually determine how the incident unfolds for the business.
Who can officially declare an incident, rather than let it sit as an unconfirmed technical glitch? Who can authorize contact with an external negotiator, or a payment conversation, if it comes to that? Who decides what customers, staff, and regulators are told, and when? Without pre-agreed authority, these get decided under maximum pressure, by whoever happens to be in the room.
Incident response governance is the decision to answer those questions before an incident, not during one - separating leadership authority from the technical response it has to sit alongside.