Crisis management
Crisis management coordinates urgent operational, legal, governance and communications decisions when an event threatens people, continuity, assets, legitimacy or organizational control.
Definition
Crisis management is the governance and response process used to prepare for, contain, investigate, communicate and recover from high-impact events under conditions of uncertainty, urgency and intense stakeholder scrutiny.
Crisis dimensions
Operational
- Safety and continuity
- Cyber or technology incident
- Supply and service disruption
- Financial liquidity
Legal and governance
- Regulatory notification
- Evidence and investigation
- Board oversight
- Liability and privilege
Stakeholder
- Employees and customers
- Investors and lenders
- Government and media
- Reputation and legitimacy
Lifecycle
- Preparedness: scenarios, roles, contacts, exercises and continuity plans.
- Activation: verify the event, establish command and protect people and operations.
- Containment: control harm, preserve evidence and meet immediate obligations.
- Stabilization: restore services, investigate causes and manage stakeholders.
- Recovery and learning: remediate weaknesses, compensate where appropriate and revise systems.
Crisis governance
| Layer | Role | Critical requirement |
|---|---|---|
| Incident team | Operational containment and facts | Clear command and technical authority |
| Executive team | Enterprise trade-offs and resources | Rapid, documented decisions |
| Board | Oversight and major judgments | Timely, independent information |
| External advisers | Legal, forensic, technical and communications support | Integrated roles and preserved accountability |
Communications
Crisis communication should be fast enough to reduce harmful uncertainty but accurate enough to withstand later scrutiny. Known facts, unknowns, actions and next updates should be separated. Legal review matters, yet silence can itself create operational and reputational consequences.
Related concepts
Sources and further reading
View sources and editorial notes
- ISO 22301, business continuity management systems.
- NIST, Cybersecurity Framework and incident-response resources.
- ISO 31000, Risk management — Guidelines.
Editorial note: Emergency, notification and reporting duties depend on the event and jurisdiction. This entry is an institutional framework, not emergency advice.