Build a Crisis Communications Plan Before You Need One
Creates the scenarios, roles, thresholds, and pre-approved materials that let you respond in minutes instead of scrambling for a day. Use it as preparation, not in an emergency.
0 likes
0 dislikes
Sign in to rate this prompt
Prompt
You are a crisis preparedness consultant. Organizations with a real plan and a named team recover substantially faster than those improvising — the difference is measured in weeks. The plan's value isn't the document; it's that decisions are already made when nobody has time to make them.
**Our organization** — what we do, size, structure: {{organization}}
**What we're exposed to** — data, physical operations, regulated activity, public-facing staff, supply chain, executives with a public profile: {{risk_surface}}
**Who's available to respond** — roles, not names, plus their real availability: {{team}}
**Existing plan or process, if any:** {{current_state}}
**Regulatory or contractual notification duties we know about:** {{obligations}}
Produce:
1. **The scenario list.** Eight to twelve credible scenarios for an organization like ours — not a generic list. For each: how it would likely surface, how fast it moves, who's affected, and severity. Include the ones people avoid planning for: a founder or executive behaving badly, an employee posting something damaging, a customer harmed by our product, a data exposure, a safety incident, a layoff leaking, a viral misunderstanding, an investigative journalist calling with a well-sourced story.
2. **Severity tiers**, with the trigger for each and who they wake up. Define them so the decision is mechanical at 2am: what constitutes an incident handled by the duty team, an escalation to leadership, and a full crisis with the CEO and counsel involved. Vague tiers cause the real failure — everyone waiting for someone else to decide it's serious.
3. **Roles and the decision tree.** Who leads, who is the single approver for public statements, who speaks publicly (and the strict rule that nobody else does), who handles employees, customers, partners, regulators, and monitoring. Name the deputy for every role. Include the escalation path when the person at fault is the person who'd normally approve the statement.
4. **The first-hour checklist**, in order, printable on one page: verify what's actually happened, convene, notify counsel, pause outbound marketing and scheduled social, issue the holding statement, brief employees, set up monitoring, schedule the next update. Include the target of having something published within the first hour, and the reminder that clarity beats speed when the two conflict.
5. **Pre-approved materials.** What to write now: holding statement templates per scenario type, an employee notification template, a support macro set, the "we can't comment yet" line, and a dark site or unpublished page ready to activate. Note what legal should pre-review while there's time.
6. **Contacts and logistics.** The contact tree with out-of-hours numbers, counsel, insurer, key customers owed a direct call, regulators, and a communication channel that works if our own systems are the thing that's down.
7. **Employee guidance.** What staff should do when contacted by press or asked at a party, who to forward to, and the social media rule during an incident. Written in advance and in plain language, because this is where most uncontrolled leaks come from.
8. **The rehearsal.** A tabletop exercise: how to run a 90-minute simulation, which scenario to use first, and what to look for — how long until the first statement, who was missing, what nobody could find, which decision stalled.
9. **Maintenance.** What to review quarterly, and the fact that a plan with the wrong phone numbers is worse than no plan because it wastes the first twenty minutes.
Hard rules:
- Everything must be usable by someone panicking. Short sentences, checklists, no theory.
- Flag any scenario where notification is legally mandated and on what clock, and say counsel must confirm the specifics for our jurisdiction.
- If our team is too small for the roles as described, collapse them realistically rather than designing a structure we don't have.