Skip to main content
  • Home
  • Crisis management
The Economy Wiki

Crisis management

Crisis management coordinates urgent operational, legal, governance and communications decisions when an event threatens people, continuity, assets, legitimacy or organizational control.

Entry type: Knowledge article

Field: Risk and Corporate Situations

Last reviewed: 24 August 2026

Definition

Crisis management is the governance and response process used to prepare for, contain, investigate, communicate and recover from high-impact events under conditions of uncertainty, urgency and intense stakeholder scrutiny.

Crisis dimensions

Operational

  • Safety and continuity
  • Cyber or technology incident
  • Supply and service disruption
  • Financial liquidity

Legal and governance

  • Regulatory notification
  • Evidence and investigation
  • Board oversight
  • Liability and privilege

Stakeholder

  • Employees and customers
  • Investors and lenders
  • Government and media
  • Reputation and legitimacy

Lifecycle

  1. Preparedness: scenarios, roles, contacts, exercises and continuity plans.
  2. Activation: verify the event, establish command and protect people and operations.
  3. Containment: control harm, preserve evidence and meet immediate obligations.
  4. Stabilization: restore services, investigate causes and manage stakeholders.
  5. Recovery and learning: remediate weaknesses, compensate where appropriate and revise systems.

Crisis governance

LayerRoleCritical requirement
Incident teamOperational containment and factsClear command and technical authority
Executive teamEnterprise trade-offs and resourcesRapid, documented decisions
BoardOversight and major judgmentsTimely, independent information
External advisersLegal, forensic, technical and communications supportIntegrated roles and preserved accountability

Communications

Crisis communication should be fast enough to reduce harmful uncertainty but accurate enough to withstand later scrutiny. Known facts, unknowns, actions and next updates should be separated. Legal review matters, yet silence can itself create operational and reputational consequences.

Sources and further reading

View sources and editorial notes
  • ISO 22301, business continuity management systems.
  • NIST, Cybersecurity Framework and incident-response resources.
  • ISO 31000, Risk management — Guidelines.

Editorial note: Emergency, notification and reporting duties depend on the event and jurisdiction. This entry is an institutional framework, not emergency advice.