Skip to content
Line chart dropping then recovering, illustrating the crisis communication plan that governs a response

What is in a crisis communication plan?

A crisis communication plan is a short working document that answers, in advance, the questions nobody has time to argue about during an incident: what counts as a crisis, who is on the team, who is allowed to approve a public statement, what the first statement says, which audiences get told in what order, and where each of them is reached. It is not a manual and it is not a strategy paper. A usable plan is closer to a checklist with phone numbers, and the test of one is whether a deputy can open it at two in the morning and act.

What a crisis communication plan is for

The expensive delays in a real incident are almost never about wording. They are about authority. Who is allowed to say this. Whether legal has cleared it. Whether anyone can reach the one executive whose approval is required, and what happens if they are on a flight. A plan is largely a document that settles those questions while there is time to argue about them calmly.

That framing also sets the length. A fifty-page binder that nobody has opened is not a plan. Small organisations can get to something genuinely useful in two or three pages, and the SBA's guidance on managing a business is a reasonable reminder that operational readiness scales down as well as up. The sections below are the ones that earn their space at any size.

Response team roles, named and deputised

Roles first, names second, deputies always. A plan listing job titles without people is a plan that has never been tested.

Role Owns Must be reachable
Decision lead Committing the organisation, activating and standing down the plan Always, or a named deputy is
Operations lead The underlying fix and the facts about it Always
Communications lead Every outbound word, and the update schedule Always
Legal What is constrained, and which notification clocks are running Within the hour
Human resources Anything involving an employee, and internal messaging Within the hour
Log keeper A timestamped record of what was known and decided From activation onward

The log keeper is the role most often cut and the one most often missed afterwards. A contemporaneous record of what the organisation knew at each hour is what makes an honest review possible, and it is what protects people who made reasonable calls on incomplete information.

Activation thresholds and the approval path

The plan must say what turns it on, in terms a duty manager can apply without judgment calls. Written triggers beat adjectives: any injury, any confirmed loss of customer data, any contact from a regulator, any inbound media enquiry about a named incident, any content about the organisation crossing a defined engagement threshold on a public platform.

Next to the trigger sits the approval path, and it needs a stated timeout. "Comms drafts, legal reviews within thirty minutes, decision lead approves" is workable. "Comms drafts, legal reviews" is how a statement sits unapproved for six hours. Name who can approve when the named approver cannot be reached, and write down that this substitution is legitimate, because in the moment people hesitate to act without it.

Holding statements and the pre-cleared library

Draft these in peacetime, get them cleared by legal in peacetime, and store them where the team can reach them without the corporate network. Three or four templates cover most of the ground: an incident affecting customers, an incident affecting employees, a data or systems incident, and an allegation about an individual associated with the organisation.

The pre-cleared library should also hold the things that always get written from scratch under pressure and always take too long: the internal note to staff, the holding line for frontline and customer-facing teams, the short statement for the website, and a list of what the organisation will not comment on and why.

Stakeholder notification order

Write the order down, because in the moment it is decided by whoever is loudest. The default sequence runs from the strongest claim to the weakest: people directly harmed, then employees, then customers and partners, then regulators on whatever statutory clock applies, then media and the public.

Regulated organisations have notification deadlines set by law that override any communications preference, and a data incident often triggers several at once. Nothing here is legal advice, and the applicable deadlines are a question for counsel. What the plan can do is record which obligations exist and who is responsible for meeting each one, so that nobody discovers a seventy-two hour clock on day four.

Channel strategy: where each audience actually is

A channel section fails when it lists channels the organisation owns rather than channels its audiences use. For each named audience the plan should record the primary channel, a backup that does not depend on the same infrastructure, and who has the credentials.

That last point is not a detail. If the incident is a systems compromise, the corporate email, the website content system, and the social accounts may all be unavailable or untrusted at exactly the moment they are needed. The NIST Cybersecurity Framework treats response and recovery as named functions alongside identification and protection, and communication during an incident sits inside them rather than beside them. A crisis communication plan that assumes working infrastructure has an untested dependency at its centre.

Drills, and the post incident review

An untested plan is a hypothesis. A tabletop exercise, ninety minutes, once or twice a year, with a scenario the team has not seen, finds the gaps cheaply: the deputy who never received the document, the out-of-hours number that rings a disconnected desk, the approval step that quietly requires three people.

After a real event, the post incident review is the phase that converts an expensive week into something the organisation keeps. Run it against the log rather than against memory, separate the question of what happened from the question of who is at fault, and finish with a small number of changes that have owners and dates. The PRSA Code of Ethics is a useful reference point for the review itself, because its provisions on honesty and disclosure apply to the internal account of an incident as much as to the public one.

What a plan will not do for you

It will not decide what your organisation is accountable for. It will not make an unfixed problem look fixed. It will not survive contact with an incident if the people named in it have never read it.

What it does is remove the three delays that reliably make things worse: not knowing whether to act, not knowing who may approve, and not having the first words already written. If the concern is the record that a past incident left behind rather than a future one, that is a different question, and reading the current published record is where a reputation audit begins.

Questions about how to build a crisis communication plan

What should a crisis communication plan include?

Activation thresholds, a named response team with deputies, an approval path with a stated timeout, pre-cleared holding statements, a stakeholder notification order, a channel plan with backups that do not share infrastructure, and a schedule for drills and post incident review.

Who should be on a crisis team?

A decision lead who can commit the organisation, an operations lead who owns the fix, a communications lead who owns outbound wording, legal, human resources where an employee is involved, and a log keeper. Each with a named deputy.

How long should a crisis communication plan be?

Short enough that people read it. Two or three pages is genuinely workable for a small organisation. What matters is that a deputy can open it at two in the morning and know the first three things to do.

How often should a crisis plan be tested?

A tabletop exercise once or twice a year, against a scenario the team has not seen, plus a check that contact details and credentials still work. Most failures found in drills are logistical rather than strategic.

Have your case reviewed

Find out what a search for your organisation returns before a plan has to be used.