
Operations
Part of Crisis communications: what to keep and what to drop
Delay versus distortion: what actually slows crisis communications
how to improve crisis communications starts with response roles, live evidence, short approvals, exercises, accessible messages, service, and closed actions.
What to take away
- Delay is clock timesignal to owner, owner to approval, approval to publication.
- Distortion is content errorchanged facts, unchecked sources, and corrections that never reach the audience that saw the first version.
- Fix authority and fact access before rewriting a single template.
- Publish targetsa named owner within 15 minutes, a first holding statement within 60 minutes, one approval pass for routine updates.
- Reconstruct one real incident minute by minute, then retest the worst failure within 90 days.
Two failures, two repairs
A slow response and a wrong response are different problems. Speed work targets detection, contact routes, and approver availability. Accuracy work targets fact ownership and version control. Teams that treat both as one problem usually fix neither.
Start with the operating constraint. If nobody can reach a decision maker in ten minutes, no template will save the release. For a fuller account of what to keep and what to drop, see crisis communications.
Walk one incident through the table and mark where the time went. The score matters less than the location of the worst gap.
| Moment | Evidence to inspect | Likely repair |
|---|---|---|
| Detection | First signal and escalation time | Clear trigger, monitored route |
| Activation | Who was contacted, and what gap | Alternates and a secure contact card |
| Verification | Source, owner, confidence, dispute | Shared fact log |
| Approval | Versions, reviewers, elapsed time | Risk-based authority |
| Publication | Channel access and accessibility | Named backups, pretested formats |
| Support | Volume, wait, resolution, unmet need | Capacity trigger and escalation |
| Correction | How the error surfaced, who saw it | Visible correction workflow |
Time targets worth writing into the plan
Set the numbers yourself and write them down. A workable starting set is a named owner within 15 minutes of first signal, a first holding statement within 60 minutes, and one approval pass for routine updates.
| Update type | Approver | Scope | Time target |
|---|---|---|---|
| Life-safety instruction | Incident lead | Wording and release | Immediate, no queue |
| Securities-relevant statement | Legal plus disclosure lead | Material facts | Under 60 minutes |
| Routine status update | Duty communications lead | Approved fact pattern | Under 30 minutes |
| Correction | Duty lead plus fact owner | Error and remedy | Within 2 hours of confirmation |
Record the authority, scope, and version for every row. A version number on each approved fact stops two teams issuing different figures in the same hour. Where the plan has no target at all, the common crisis communications questions about activation and first statements are a useful place to begin.
One row needs outside reading. When a statement touches material information, a separate route applies, and the SEC's interpretive guidance on Regulation FD explains when selective disclosure to analysts or investors becomes a compliance problem.
Example: forty minutes of a composite incident
This reconstruction is a composite built from common failure points, not a named case. Times are illustrative.
Forty minutes of a composite incident
- 0:00. A customer posts a photo of a damaged delivery. Social monitoring is unstaffed that hour.
- 0:06. Support replies with an unverified cause.
- 0:11. A journalist emails the press inbox, which one person monitors. That person is on leave.
- 0:18. The duty lead opens the fact log on a mobile and finds two disputed facts.
- 0:24. Legal drafts a statement containing a claim operations has not confirmed.
- 0:31. A correction goes to one channel only. The first audience never sees it.
- 0:40. The duty lead names an owner for every open fact and sets a 60-minute checkpoint.
The bottlenecks are visible: an unstaffed channel, a single point of contact, a one-way correction. Log the same detail for internal communications, where a stale employee note starts the next wave of distortion.
Assign roles and finish conditions
Each step needs a named role and a finish condition an outsider can check. The analyst must reproduce the result. The decision owner must explain the action and the stop rule.
- A named owner for every public fact
- A tested backup for every monitored channel
- Approval limits written beside each role
- Translation and accessible alternatives checked
- Call-center and partner capacity confirmed
- Every version and decision captured
- The highest-risk failure retested within 90 days
Grade behavior in the exercise, not recitation. Note who moved, how fast, and what they produced. A retest on the same measure is the only proof the fix held.
External references worth keeping
CISA's StopRansomware Guide asks teams to maintain and exercise an incident response plan with a communications annex, notification procedures, and prepared holding statements. Its scope is ransomware and data extortion, so other crisis types need other controls.
NIST SP 800-61 Revision 3 integrates incident response with cybersecurity risk management across preparation, detection, response, recovery, and improvement. Its governance and continuous-learning emphasis transfers directly to communications.
Run both through your own retest, which is where marketing communications strategy mistakes tend to reappear.
Common questions
What should we fix first?
Fix the failure that could cause the greatest harm. Delayed activation, an unverified safety claim, and an unreachable support route all qualify. Then retest that same failure.
How often should the plan be exercised?
Use a risk-based schedule. A quarterly decision drill plus a deeper annual scenario suits many growing companies, and any major change to people or tools justifies a new drill.
Who should attend?
Include the people who will decide, verify, publish, help affected people, and cover absent colleagues. Observers should not outnumber participants.
How do we know a fix worked?
Set the target before the retest and compare both runs on the same measure. Evidence beats a written promise to improve.







