How to Develop a Crisis Management Plan

Come costruire un piano di crisis management

A crisis management plan is put to the test when information is incomplete, decisions must be made quickly, and the impact on operations, people, or reputation risks escalating. Under these conditions, knowing how to develop a crisis management plan means establishing a governance system that enables the organization to make decisions, communicate, and take action under pressure.

The plan is not simply a list of phone numbers or a generic procedure to be stored in a shared folder. It is an operational framework that integrates governance, scenario assessment, roles, decision-making processes, communication, and response capabilities. Its effectiveness depends primarily on the quality of the work done prior to the event and the frequency with which it is reviewed.

What risks should a crisis management plan address first?

Planning must begin by identifying the risks that could jeopardize priority objectives, people, assets, business continuity, data, regulatory obligations, and stakeholder trust. Not all incidents require the activation of a crisis response: a clear distinction prevents both inappropriate escalation and delays in mobilizing management.

Scenario analysis should incorporate the company’s risk assessment, business impact analysis, findings from audits, past claims and incidents, and assessments of physical and digital vulnerabilities. For a manufacturing company, for example, a fire, a shutdown at a critical supplier, an infrastructure failure, or a contamination incident may unfold in very different ways but require the same command and control framework. For a regulated or highly technology-dependent organization, ransomware, cloud service outages, data breaches, and core system disruptions must also be evaluated in terms of notification timelines and obligations to authorities and customers.

The goal is not to predict every possible event. It is to identify categories of plausible, high-impact scenarios, defining escalation thresholds and response options. A plan that is too detailed regarding marginal cases tends to become unusable; one that is too abstract does not provide sufficient guidance when action is needed.

Define governance, authorities, and activation thresholds

The most critical aspect of developing a plan is governance. During a crisis, ambiguity about who makes decisions can lead to delays, conflicting messages, and uncoordinated actions. The plan must therefore formally establish the Crisis Management Team, its mandate, the rules for convening the team, and its relationship with incident response, emergency response, business continuity, and corporate management functions.

The team’s composition varies depending on the sector and risk profile, but typically includes a crisis leader with effective authority, as well as representatives from operations, HSE or security, IT and cybersecurity, legal and compliance, communications, human resources, and managers from the affected departments. For incidents involving insurance exposure or significant property damage, it is also advisable to establish a clear communication process with adjusters, insurers, and brokers, while ensuring that records are preserved and decisions are traceable.

It is not enough to simply list names. For each role, responsibilities, authorities, on-call substitutes, and escalation criteria must be clearly defined. The crisis leader, for example, must be able to convene the team, request extraordinary resources, approve immediate protective measures, and bring decisions that exceed pre-established financial, legal, or reputational thresholds to senior management.

Trigger thresholds require the same level of precision. They may relate to risks to life and safety, the expected duration of the disruption, media exposure, data compromise, failure to meet contractual obligations, or potential relevance to the authorities. The threshold should not be a constraint: in a rapidly evolving situation, the prudent approach is to trigger the response early and scale it back later, if necessary.

Developing Procedures That Can Be Used Under Pressure

An effective plan prioritizes clear, sequential, and accessible instructions. In the first few hours of a crisis, the team must be able to answer essential questions: What happened? Which people or processes are involved? What immediate actions are being taken? Who needs to be notified? And which decisions cannot wait?

The operational structure can be organized into four distinct blocks:

  • initial assessment of the incident, including the collection of verified facts, an estimate of the impact, and classification of the severity;
  • forming the team, establishing a meeting schedule, and creating a decision log;
  • response management, with priorities assigned to personnel, containment, operations, legal obligations, and communication;
  • Transition to recovery, with criteria for moving to business continuity, disaster recovery, or routine operations.

The decision log deserves special attention. It must document timelines, information sources, decisions, responsible parties, deadlines, and justifications. In addition to supporting coordination, it is an important tool for subsequent analysis, disputes, interactions with insurers, and compliance verification.

Procedures must also account for operation under degraded conditions. If email is unavailable, if a location is inaccessible, or if the collaboration system is compromised, the team must have alternative channels, up-to-date contacts, and secure methods for sharing information. A plan that can only be accessed through the infrastructure affected by the incident poses a clear design risk.

Communication: Accuracy Before Apparent Speed

Crisis communication is not simply about issuing a press release. It requires a process to verify the facts, develop consistent messages, identify stakeholders, and determine who is authorized to speak. Employees, customers, suppliers, authorities, local communities, the media, and insurers do not necessarily receive the same level of detail, but they must receive messages that are consistent with one another.

The plan should include approved templates for initial communications, authorization criteria, and a stakeholder matrix. However, the templates do not replace professional judgment. In the event of ongoing investigations, unverified data, or confidentiality obligations, the content and timing of the communication depend on the nature of the event and the advice of the relevant departments.

The operational rule is simple: do not fill the information gap with speculation. Communicate what has been confirmed, state which investigations are underway, and indicate when an update will be provided. This approach protects the company’s credibility more than a hasty response that is later refuted.

Test the plan and address its weaknesses

An untested plan is just a hypothesis. Drills serve to verify not only whether people are familiar with the procedure, but also whether the governance structure can withstand tight deadlines, conflicting priorities, and imperfect information.

Tabletop exercises are useful for validating roles, escalation procedures, and strategic decisions. Functional simulations, on the other hand, allow for testing communication channels, on-call availability, and workflows with IT, operations, and suppliers. For industrial, logistics, or infrastructure sites, exercises coordinated with emergency plans and external stakeholders can highlight dependencies that do not emerge in a purely document-based test.

Every test must yield evidence: observations, response times, effective decisions, critical issues, and corrective actions—including the person responsible and the completion date. Without this cycle of improvement, the exercise remains merely a formality. With a structured program, it becomes an investment in actual command capabilities.

Integrate the plan into the company’s resilience strategy

Crisis management does not operate in isolation. It must be consistent with the risk management system, business continuity plans, disaster recovery strategies, cyber incident response protocols, and measures to protect people and sites. This integration reduces overlap and clarifies the transition from event management to the resumption of critical operations.

The plan’s maintenance must keep pace with organizational and operational changes: acquisitions, new facilities, critical third parties, technological changes, new markets, regulatory developments, and financial results. An annual review may be appropriate for stable scenarios, but it does not replace updates following a significant incident or a major transformation.

Developing a crisis management plan requires a systematic approach, cross-functional skills, and a realistic assessment of the organization’s vulnerabilities. The value of the plan lies not in its scope, but in the ability of the designated personnel to apply it with discipline when the margin for error narrows. Developing this capability before a crisis strikes is a governance responsibility, not a task to be delegated solely to the emergency phase.