Crisis management
Also known as: crisis response
How top management leads the whole organisation through a serious event - decisions, priorities, staff, customers and press.
Draft - this entry has not been reviewed yet.
Formal
The leadership level of the response to a severe disruption, in which a crisis team makes business decisions, sets priorities, handles communication with staff, customers, media and authorities and starts continuity plans, while technical teams handle the incident itself.
In plain English
Like parents after a house fire - the fire brigade fights the flames, but the parents decide where the family sleeps tonight, who calls the insurer and what to tell the children.
In practice
During a ransomware attack on a Danish dairy company, the crisis team meets every three hours, decides to take orders from shops by phone, approves a press statement and chooses not to pay the ransom.
Why it matters
A serious attack is a business crisis, not only an IT problem, and slow or muddled leadership can cost more in trust than the attack itself.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Agree with top management what turns an incident into a crisis, for example a threat to critical services, to people's safety or to the organisation's reputation, and who may call the crisis team together.
- Set up a crisis team of senior leaders with fixed roles - chair, situation picture, communication, legal and HR - and a deputy for each, and decide how it connects to the incident response team, usually through the incident lead.
- Decide in advance the hardest calls and who makes them, such as disconnecting from the internet, stopping production or taking a position on ransom payment together with legal advisers and the insurer.
- Prepare a crisis room, physical or virtual, that works without the normal IT, with a meeting agenda template, a situation log and a decision log.
- When the team is activated, meet at a fixed rhythm; open each meeting with the common situation picture, follow up on actions from the last meeting and end with decisions and owners.
- Record every decision with its reason and time in the decision log, so choices made under uncertainty can be explained later to the board, auditors and regulators.
- Start the continuity plans and the communication plan from the crisis team, and agree when and how the crisis is stood down and handed back to normal management.
- Train the crisis team, including new board members and managers, and exercise it at least once a year with a cyber scenario.
Common pitfalls
- Leaving a serious attack to IT alone, so business decisions about customers, production and the press are made late or not at all.
- Crisis team members pulling into the technical work instead of deciding priorities and leaving the technical work to the incident team.
- Making decisions without writing down why, so they cannot be explained or defended afterwards.
- Planning to meet in a room or on a platform that depends on the systems the attack has taken down.
Good guides
- Cyber Governance Code of Practice(opens in a new tab) · NCSC UK
- Build - A cyber security incident response team (CSIRT)(opens in a new tab) · NCSC UK
- Struktur og organisering(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
- Retningslinjer for krisestyring(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
Technical deep dive
ISO 22361:2022 treats a crisis as an abnormal and unstable situation that threatens an organisation's strategic objectives, reputation or viability, and distinguishes crisis management from incident management by the nature of the problem rather than its size. Incidents are handled with prepared procedures; a crisis is characterised by high uncertainty, novelty, time pressure and conflicting interests, so it has to be managed with judgement and decision-making rather than by following a plan step by step. Many cyber incidents never become crises, while a modest data leak can become one if it involves vulnerable people, public outrage or regulatory scrutiny.
The typical structure is layered. A strategic crisis management team of senior executives decides on priorities, trade-offs and external positions; a tactical level coordinates resources across functions; and operational teams, including the incident response team, carry out the work. The UK emergency services' gold, silver and bronze command model is a common reference for these tiers. The crisis team works in a fixed rhythm of meetings, each opening with a common situation picture, reviewing actions from the previous cycle and ending with decisions recorded in a decision log with rationale, so that choices made under uncertainty can be explained afterwards to boards, auditors and regulators.
Cyber crises bring specific decisions to the table: whether to disconnect from the internet or shut down production, whether to pay or negotiate a ransom (with sanctions, legal and insurance constraints), when to involve the police and the national CSIRT, what to tell customers before the facts are known, and how to keep delivering critical services. Norsk Hydro's response to the LockerGoga ransomware in 2019, with manual production and daily open press briefings, and Maersk's recovery from NotPetya in 2017 are frequently cited cases of crisis management that preserved trust despite severe operational damage.
NIS2 Article 21(2)(c) names crisis management alongside business continuity as a required measure, and Article 20 makes the management body responsible for approving and overseeing cybersecurity risk-management measures and requires its members to undergo training. At EU level, Article 16 establishes EU-CyCLONe to coordinate large-scale cybersecurity incidents and crises between member states. Crisis management differs from incident response in that incident response contains and eradicates the technical cause, while crisis management steers the organisation through the business, legal and reputational consequences; the two run in parallel and need a clear interface, usually an incident lead who briefs the crisis team.
What to learn first
Everything this builds on, foundations first.
Relationships
- Requires
- Business continuity plan (BCP)
- Don't confuse with
- Incident response
Sources & further reading
Standards & official texts
- ISO 22361:2022 - Security and resilience - Crisis management
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 7 og Ordliste (BCP, Kommunikationsplan)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…