| name | crisis-communicator |
| description | PR crisis management covering response timelines (golden hour), holding statements, press release templates, social media response protocols, stakeholder communication strategies, apology frameworks, trust rebuilding, media training essentials, and crisis prevention planning. Use when the user asks about crisis communicator or needs help with related topics. Do NOT use for unrelated domains or when a more specialized skill exists.
|
| license | Apache-2.0 |
| metadata | {"author":"foundry-skills","version":"1.0.0","tags":"business-writing writing strategy","category":"writing","subcategory":"business-writing","depends":"","disclaimer":"none","difficulty":"advanced"} |
Crisis Communicator
When to Use
Use this skill when a user needs expert guidance on managing a reputational, operational, or safety crisis through strategic communication. Activate it in these specific scenarios:
- Active crisis unfolding now: User reports an incident (data breach, product recall, executive misconduct, workplace accident, viral social media attack) and needs immediate response guidance, a holding statement, or press release drafted within the hour.
- Pre-crisis preparation: User wants to build a crisis communication playbook, run a vulnerability audit, train a spokesperson, or draft pre-approved holding statement templates before anything happens.
- Apology or accountability statement needed: User needs to craft an organizational apology, acknowledgment letter, or accountability statement following a mistake, scandal, or failure.
- Media pressure management: User is facing incoming press inquiries, a hostile journalist interview, or a news cycle that is accelerating and needs talking points, bridging techniques, and spokesperson coaching.
- Stakeholder communication strategy: User needs to sequence and structure communications to employees, board members, regulators, customers, or partners during or after a damaging event.
- Post-crisis trust rebuilding: User's organization has weathered a crisis and needs a structured recovery communications plan spanning weeks to months.
- Social media crisis escalation: A hashtag campaign, viral video, or influencer pile-on is threatening brand reputation and requires platform-specific triage and response protocols.
Do NOT use this skill when:
- The user needs general PR strategy, brand positioning, or marketing communications unrelated to a crisis -- use a brand strategy or PR planning skill instead.
- The request is primarily about legal liability, insurance claims, or regulatory compliance filings -- refer to legal advisory skills and flag the need for actual legal counsel.
- The situation is an internal HR conflict without public exposure -- use an HR communication or conflict resolution skill unless it has escalated to public visibility.
- The user needs journalism or media relations training outside of a crisis context -- use a media relations skill.
- The request involves government or political crisis communications (scandal management for elected officials) -- that subspecialty involves different legal constraints and stakeholder dynamics that require political communications expertise.
- The incident is a cybersecurity technical response (forensics, patching, incident containment) -- use a cybersecurity incident response skill, though this skill handles the communications layer of a breach.
- The user asks about personal reputation management for an individual, not an organization -- use a personal brand or reputation repair skill unless the individual is a named organizational executive in an active corporate crisis.
Process
Step 1: Immediate Triage -- Establish Crisis Coordinates
Before drafting a single word of communication, gather the eight critical coordinates that define every crisis response decision.
- What happened: Separate confirmed facts from rumors, reported allegations, and speculation. Write two columns: CONFIRMED and UNCONFIRMED. Only confirmed facts enter public communications.
- Scope and harm: Who is directly affected, how many people, what categories of harm (financial, physical, privacy, reputational)? Scale determines urgency and tone -- a breach affecting 200 internal accounts requires a different response than one affecting 4 million customers.
- Public awareness status: Use four levels -- (1) Not yet public, (2) Social media rumors circulating, (3) Media has picked it up, (4) Mainstream coverage or viral. Level determines how fast you must move and what you can still control.
- Is the incident ongoing or contained: An active data exfiltration, a product still on shelves, or an executive still in role requires different framing than a contained past event.
- Legal exposure: Has legal counsel been engaged? What constraints exist on admissions, specificity, or named individuals? Never issue substantive communications without legal sign-off, but do not let legal indefinitely block a holding statement -- delay is its own liability.
- Authorization structure: Who is the designated spokesperson? Who has authority to approve statements? Identify primary, backup, and media-facing vs. internal-facing spokespeople.
- Active monitoring: What channels are showing activity -- press inquiries, social media volume, customer service call spike, employee Slack/Teams noise? Monitoring intelligence shapes message prioritization.
- Remediation status: What concrete actions has the organization already taken or can credibly commit to? Communications without action are hollow -- identify at least one tangible step to anchor the response.
Step 2: Apply the Golden Hour Framework
The first 60 minutes sets the trajectory of the entire crisis. Compress decision-making into three tight windows.
- Minutes 0-15 (Assess and Assemble): Confirm the crisis is real and not a false alarm. Activate the crisis response team -- at minimum: communications lead, legal counsel, senior operations or product leader, and an executive decision-maker. Designate a single external contact point. Issue an internal freeze: all employees route external inquiries to communications, nothing is posted on personal social accounts, no unofficial statements.
- Minutes 15-30 (Holding Statement Decision): Determine whether the incident requires a public-facing holding statement within the hour. Threshold: if media has the story, if affected parties are experiencing harm right now, or if social volume is accelerating -- a holding statement is mandatory. If the incident is still fully private and contained, you may have more time, but begin drafting immediately.
- Minutes 30-60 (Holding Statement Deployment): Draft, approve, and distribute the holding statement. Post to website, send to press contacts who have inquired, pin on primary social channels. Brief internal leadership simultaneously. Establish a specific time for the next update -- "We will provide a detailed update by 3:00 PM EST" -- and honor it.
- Never go silent: Silence reads as hiding. If you have nothing new to report, still post an update: "Our investigation is ongoing. We remain committed to full transparency and will share findings by [time]."
- Parallel workstream: While holding statement goes out, begin drafting the substantive response. Do not wait for holding statement deployment to start the next document.
- Document everything: Timestamp every decision, every draft, every communication sent. This log matters for legal discovery, post-crisis analysis, and accountability.
Step 3: Craft the Holding Statement
The holding statement is the highest-stakes single paragraph in corporate communications. It must exist before you have all the facts.
- Five mandatory elements: (1) Acknowledgment -- name the situation plainly, (2) Immediate action -- what you did the moment you knew, (3) Values anchor -- why this matters to you (safety, trust, integrity), (4) Commitment to update -- a specific time, not "soon," (5) Contact channel -- where affected parties go for immediate help.
- Maximum length: Three to five sentences. This is not the place for explanation, context, or defense. Those come in the full statement.
- Tone calibration: Grave and direct, never defensive or minimizing. The word "inconvenience" is forbidden in any crisis holding statement -- it trivializes harm. "Any concern" is forbidden -- it makes empathy conditional.
- Legal review under time pressure: Give legal counsel a hard deadline of 20 minutes to review the holding statement. Their job at this stage is to remove factual inaccuracies and admissions of specific legal liability -- not to drain all human accountability from the language. A sterile holding statement is a second crisis.
- Platform-specific adaptation: The press holding statement is the master version. Social media versions compress to 280 characters for Twitter/X with a link to full statement. Customer email opens with the holding statement language reformatted as a subject line and first paragraph.
- Do not speculate on cause, timeline of discovery, or financial impact in the holding statement. These are for the substantive response once confirmed.
Step 4: Build and Execute the Stakeholder Communication Matrix
Different audiences need different information delivered through different channels at different speeds. Sequence matters -- stakeholders who learn from media before hearing from you directly become adversaries.
- Priority 1 (Within the first hour, before or simultaneous with public statement): Directly harmed parties (direct call or personal email, not mass blast), board of directors and C-suite (phone call from CEO or CCO), employees (internal all-hands email or town hall within two hours), regulators if legally required to notify (formal filing per counsel's direction).
- Priority 2 (Within one to four hours): Media contacts who have made inquiries (press release or on-record statement, not off-the-record briefing unless strategically necessary), key customers and enterprise clients (personal outreach from account executives with approved script), business partners and vendors who may be affected or asked by their own clients.
- Priority 3 (Within 24 to 48 hours): Industry peers and trade associations (appropriate only when lessons are shareable and crisis is stabilizing), general public updates beyond initial statement, community stakeholders in geographically affected areas.
- Internal communication is never secondary: Employees who learn from Twitter become leaks, morale crises, and glass-door nightmares. The employee communication must go out within two hours maximum. It should contain: what happened (facts only), what the organization is doing, what employees should and should not say if asked, where to direct media inquiries, and when the next internal update will come.
- Tailor depth by audience: Regulators get compliance-level detail and formal language. Employees get plain language, reassurance where warranted, and clear behavioral guidance. Customers get impact to them specifically and remediation steps. Media gets approved statements only -- reporters are not confidants.
- Create a communication log: Track who was contacted, by whom, at what time, and what was said. This prevents contradictory messages and documents good-faith outreach.
Step 5: Draft the Full Substantive Response
The full response goes out within one to four hours of the incident becoming public. It must answer the four questions every audience is asking.
- The four core questions: (1) What happened and who is responsible? (2) Who was affected and how badly? (3) What are you doing about it right now? (4) How will you make sure it never happens again?
- Narrative structure for press release: Open with the most important fact (not the company name or boilerplate). Paragraph two contains specific, numbered corrective actions. Paragraph three contains a leadership quote that is personal, empathetic, and forward-looking -- not corporate-speak. Paragraph four tells affected parties exactly what to do step by step. Paragraph five commits to a specific next update with a channel and time.
- The leadership quote must be human: "I am deeply troubled that this happened and take full responsibility for our response" works. "XYZ Corp is committed to the highest standards of excellence in customer data stewardship" does not -- it sounds written by a lawyer, which it was.
- Specificity is credibility: "We have implemented enhanced monitoring" is meaningless. "We have engaged [firm category] to conduct an independent forensic audit, results of which we will publish by [date]" is credible. Every vague commitment erodes trust faster than the original incident.
- Never include unconfirmed numbers: Do not state the number of affected users, financial impact, or timeline of events unless confirmed by internal systems or legal sign-off. Wrong numbers in an initial statement become the story.
- The remediation commitment section should include: immediate actions taken (past tense, confirms you acted), ongoing actions (present tense, shows active engagement), structural changes (future tense with specifics, shows you are fixing root cause).
Step 6: Execute Social Media Triage
Social media is where crises accelerate and where response velocity matters most, but also where organizations do the most self-inflicted damage.
- First action on any crisis: Pause all scheduled social content. Marketing automation must be paused immediately. Nothing looks worse than a cheerful promotional post running during a crisis -- it signals indifference.
- Pin the official statement on all primary channels within the first hour. The pinned post is the single source of truth that should be referenced in all replies.
- Triage incoming comments and DMs into four tiers: (T1) Immediate response required -- people reporting direct harm, journalists, accounts with large followings amplifying misinformation that could cause additional harm. (T2) Within one hour -- affected individuals seeking information or help, specific questions that have answers. (T3) Within four hours -- general concern, requests for updates, supportive comments. (T4) Do not engage -- bad-faith trolling, political opportunists, people expressing anger without specific claims.
- Response templates for T1-T3: All templates should acknowledge, empathize, direct to resource, and not create new commitments. Example for T1 harm report: "We are so sorry to hear you experienced this. This is exactly what we're investigating and addressing. Please DM us your contact information so our team can reach out to you directly within the hour."
- Never delete critical comments unless they contain personal identifying information of third parties, explicit threats, or illegal content. Deletion screenshots spread faster than the original post and confirm cover-up narrative.
- The 4-hour silence rule: If more than four hours pass without a public update from your accounts, journalists and influencers fill the narrative vacuum. Set calendar reminders for update intervals regardless of whether there is new information.
- Do not argue, litigate, or explain at length in comment threads. Every extended comment thread reply is an invitation for further attack. Acknowledge, redirect to official channel, offer direct support.
Step 7: Deploy the Apology Framework (When Warranted)
An apology is a precision instrument, not a reflex. Applied incorrectly, it either amplifies legal exposure or reads as performative and backfires.
- Determine whether apology is warranted: Apology is appropriate when the organization bears direct responsibility for harm, when facts are confirmed, when legal counsel has approved the language, and when the apology will be accompanied by concrete remedy. Apology is not appropriate when the organization is not at fault, when facts are still disputed, or when "apology" would be mistaken for admission of legal liability in a live litigation context.
- Five elements of an effective apology (all five must be present for the apology to land):
- Acknowledgment: Name the specific harm. "We exposed your personal financial data" not "there was a data incident."
- Responsibility: Own it without deflection. "This happened because our security protocols were inadequate" not "sophisticated attackers exploited a vulnerability."
- Empathy: Demonstrate you understand the human impact. "The anxiety of not knowing whether your identity has been compromised is real and serious" not "we understand this may have caused inconvenience."
- Remedy: Commit to specific, tangible reparation. "Two years of complimentary identity theft monitoring through [service category], a $500 credit to your account, and a personal call from our security team if requested" not "we are reviewing ways to support affected customers."
- Commitment: Promise specific structural change. "We have hired a new Chief Information Security Officer reporting directly to the CEO, and we will publish a third-party security audit by [date]" not "we are committed to doing better."
- Anti-patterns to eliminate from any draft:
- "We're sorry if anyone was offended" -- conditional empathy shifts blame to the audience.
- "Mistakes were made" -- passive voice erases accountability.
- "We're sorry, but..." -- anything after "but" cancels the apology.
- "We regret any confusion" -- implies the audience is confused, not that you failed.
- Generic form letter with mail-merge name field -- the format itself communicates that individuals don't matter.
- A CEO apology delivered via press release only, with no direct outreach to most affected parties -- signals that optics matter more than people.
Step 8: Execute Trust Rebuilding (Weeks 2-8)
The crisis is not over when coverage stops. Trust rebuilds through demonstrated action over time, not through communications alone.
- The 30-60-90 day reporting rhythm: Publish concrete progress updates at 30, 60, and 90 days post-crisis. Each update should report on specific commitments made during the crisis with measurable status -- completed, in progress, or revised with explanation.
- Third-party validation: Commission independent audits, bring in recognized external experts, or engage a neutral advisory board to assess your corrective actions. Self-reported progress is discounted; externally validated progress is believed. Announce the audit publicly and commit to publishing findings even if unflattering.
- Community and direct stakeholder engagement: For significant crises, convene a customer advisory panel or community roundtable. Invite critics as well as supporters. Document what you heard and what you changed in response. This process generates proof of listening that no press release can replicate.
- Narrative pivots must be earned, not declared: Organizations frequently attempt to change the subject to good news -- a product launch, a charity initiative, a positive quarterly result -- too soon after a crisis. This reads as distraction. The pivot is earned only after demonstrable completion of corrective actions. The rule of thumb: do not attempt narrative pivot until at least one substantive 30-day progress report has been published.
- Internal rebuilding is concurrent: Employee trust, morale, and institutional credibility must also be rebuilt. Town halls, skip-level conversations, updated policies with employee input, and transparent leadership communication are the internal equivalents of the external trust rebuilding program.
- Post-crisis analysis within two weeks: Reconstruct the complete incident timeline at minute-level granularity. Evaluate each communication: Was it accurate? Timely? Did it reach its intended audience? Where did response break down? Update the crisis playbook with specific lessons. Schedule the next tabletop exercise within 90 days.
Output Format
When delivering crisis communication support, structure output using the following framework. Select only sections relevant to the specific request -- an active crisis needs the Immediate Action Block first; a preparation request starts with the Vulnerability Assessment.
CRISIS COMMUNICATION BRIEF
Organization: [Name / Industry / Size]
Incident Type: [Data breach / Product safety / Executive misconduct / Workplace incident / Viral social attack / Financial disclosure / Environmental / Other]
Incident Date/Time: [When it occurred vs. when organization learned]
Current Public Status: [Not public / Social rumors / Media coverage / Viral/mainstream]
Incident Status: [Ongoing / Contained / Partially contained]
Legal Counsel Engaged: [Yes / No / Pending]
Designated Spokesperson: [Name, Title, Backup: Name, Title]
IMMEDIATE ACTION CHECKLIST (First 60 Minutes)
| Time Window | Action | Owner | Status |
|---|
| 0-15 min | Confirm facts and activate crisis team | [Role] | [ ] |
| 0-15 min | Freeze all external communications and scheduled posts | [Role] | [ ] |
| 15-30 min | Draft holding statement | [Role] | [ ] |
| 15-30 min | Brief board/executive team | [Role] | [ ] |
| 30-60 min | Approve and publish holding statement | [Role] | [ ] |
| 30-60 min | Begin substantive response draft | [Role] | [ ] |
| 60 min | Internal employee communication | [Role] | [ ] |
HOLDING STATEMENT
Target deployment time: [Specific time, within 60 minutes of activation]
Approved by: [Legal / Executive sign-off]
[Draft holding statement text -- 3 to 5 sentences following the 5-element structure]
Elements present:
SUBSTANTIVE RESPONSE / PRESS RELEASE
FOR IMMEDIATE RELEASE | [Date, Time, Time Zone]
[HEADLINE -- factual, direct, non-sensational]
[City] -- [Opening sentence: who did what, when, factual scope]
[Paragraph 1 -- What happened and current status, confirmed facts only]
[Paragraph 2 -- Specific remediation actions with numbers and dates]
- Action 1 (completed): [Specific measure taken]
- Action 2 (in progress): [Specific measure with completion date]
- Action 3 (committed): [Specific measure with timeline and accountable party]
[Paragraph 3 -- Leadership quote: personal, empathetic, accountable, forward-looking]
"[Quote]," said [Name], [Title].
[Paragraph 4 -- What affected parties should do: numbered steps]
- [Specific step]
- [Specific step]
- [Resource or support available -- phone number, URL, email category]
[Paragraph 5 -- Next update commitment: channel and specific time]
[Boilerplate -- one paragraph company description]
Media Contact: [Name] | [Phone -- direct line] | [Email]
STAKEHOLDER COMMUNICATION MATRIX
| Stakeholder Group | Priority | Channel | Timing | Key Message Emphasis | Owner |
|---|
| Directly harmed individuals | 1 | Personal phone/email | Immediate | Impact to them + specific remedy | [Role] |
| Board / C-suite | 1 | Phone call | Within 1 hour | Facts, exposure level, response plan | CEO/CCO |
| Employees | 1 | All-hands email + FAQ | Within 2 hours | What happened, what to say/not say, next update | HR + Comms |
| Regulators | 1 | Formal filing | Per legal counsel | Compliance language, disclosure requirements | Legal |
| Media (inquiring) | 2 | Press release + on-record | 1-4 hours | Approved statements only | Comms lead |
| Key enterprise clients | 2 | Personal outreach | 2-4 hours | Impact on them + dedicated support contact | Account lead |
| Business partners | 2 | Direct email | Within 4 hours | Operational impact + coordination | Operations |
| General public | 2 | Website + social | 1-4 hours | Accessible summary + action steps | Comms |
| Industry/peers | 3 | Professional channels | 24-48 hours | Lessons (only when appropriate) | Executive |
SOCIAL MEDIA RESPONSE PROTOCOL
Immediate actions:
Response triage:
| Tier | Criteria | Response Time | Template |
|---|
| T1 -- Immediate | Direct harm reported, media, misinformation causing harm, large amplifiers | Within 15 minutes | [See template below] |
| T2 -- Urgent | Affected individuals seeking help, specific answerable questions | Within 1 hour | [See template below] |
| T3 -- Standard | General concern, update requests, expressions of anger | Within 4 hours | [See template below] |
| T4 -- No response | Bad-faith trolling, political opportunists, unanswerable speculation | N/A | Do not engage |
Response Templates:
- T1 (Reported harm): "We are so sorry to hear this happened to you. Please DM us your contact information -- our team will reach you directly within [time]. This is exactly what we are working to address."
- T2 (Information request): "We hear you. Our full update is available at [link]. We will post the next update by [specific time]. If you have a specific concern, please DM us."
- T3 (General concern): "Thank you for raising this. We are taking it seriously. Official updates will continue at [channel/link]."
- Misinformation correction: "We want accurate information available. What we know: [1-2 confirmed facts]. Full details at [link]. We're committed to keeping you informed as facts develop."
APOLOGY ASSESSMENT AND DRAFT
Apology warranted: [Yes / No / Conditional -- explain]
Basis: [Organization responsible + facts confirmed + legal approved + remedy ready]
Draft apology -- all five elements:
- Acknowledgment: [Specific harm named]
- Responsibility: [Direct ownership without deflection]
- Empathy: [Human impact articulated]
- Remedy: [Specific, tangible reparation with numbers and dates]
- Commitment: [Structural change with accountability and timeline]
Anti-patterns eliminated: [List any phrases removed and why]
SPOKESPERSON BRIEFING SHEET
Key messages (maximum 3):
- [Message 1 -- What happened / what we know]
- [Message 2 -- What we are doing about it]
- [Message 3 -- Our commitment going forward]
Anticipated hard questions and approved responses:
| Question | Bridging approach | Approved response points |
|---|
| [Hardest question] | "What I can tell you is..." | [Key message anchor] |
| [Second hardest] | "The most important thing to know is..." | [Key message anchor] |
| [Liability question] | "I can't speak to [that specific] because [reason]. What I can tell you is..." | [Redirect to facts and actions] |
Do not say list: [Specific words, phrases, numbers, names that are off-limits]
Unknown facts list: [What you will respond to with "I don't know -- I'll find out and get back to you"]
TRUST REBUILDING TIMELINE
| Milestone | Action | Owner | Target Date |
|---|
| 2 weeks post-crisis | Internal post-crisis analysis complete | Comms lead | [Date] |
| 30 days | First external progress report published | CCO | [Date] |
| 30 days | [Specific committed action] completion | [Role] | [Date] |
| 60 days | Second progress report | CCO | [Date] |
| 60 days | Third-party audit findings published | [Role] | [Date] |
| 90 days | Final progress report + policy update | CCO | [Date] |
| 90 days | Updated crisis playbook + next drill scheduled | Comms lead | [Date] |
Rules
-
Never issue a public statement without legal review, but never let legal review delay a holding statement beyond 60 minutes. The two most common crisis communications failures are (a) issuing statements without legal sign-off that create liability and (b) waiting for legal perfection while the story writes itself. Legal gets 20 minutes for the holding statement. Full statement gets up to two hours.
-
Separate CONFIRMED facts from UNCONFIRMED at all times. Every communication must be built only from confirmed facts. When uncertain, say "We are still investigating [specific aspect]." Publishing an incorrect number -- 50,000 affected when it was 500,000 -- turns a crisis into a cover-up story.
-
The spokesperson is singular and prepared. Multiple spokespeople create contradictory messages. The primary spokesperson must be briefed with the three key messages, the hardest ten anticipated questions, and the explicit do-not-say list before any media interaction. A spokesperson who goes off-script is worse than no spokesperson.
-
Silence is a statement. Going dark for more than four hours during an active crisis cedes narrative control to journalists, critics, and social media amplifiers. If you have nothing new to report, post an update that says exactly that with a commitment for when the next substantive update will come.
-
Employees learn from you, not from the news. Internal communication to all employees must go out within two hours of the incident becoming public. Employees who learn from media coverage cannot be trusted to give consistent responses to friends, family, or journalists they encounter. Every employee becomes a spokesperson the moment they walk out the door.
-
Remediation actions must precede or accompany communications. Announcing that you "take this seriously" without a corresponding concrete action is a trust accelerant in the wrong direction. Do not issue a full response statement until at least one substantive remediation action has been taken and can be named specifically.
-
Deleting critical social media comments is almost always wrong. The only exceptions are content containing personal threats, illegal material, or private identifying information of third parties. Screenshots of deleted critical comments spread faster than the original post and confirm the cover-up narrative. Archive everything before taking any action.
-
"No comment" is retired vocabulary. "No comment" tells journalists and the public you have something to hide. The replacement is: "I'm not able to speak to [specific aspect] because [honest reason -- legal, investigation ongoing, etc.]. What I can tell you is [key message]." Even "I don't know" is superior to "no comment."
Edge Cases
1. The Slow Leak -- Incident Discovered Through Journalism, Not Internal Systems
A reporter calls your communications team with detailed information about an incident you were unaware of -- a safety issue, financial irregularity, or executive behavior. You have 30 minutes before their story publishes.
Handling: Do not confirm, deny, or provide detail until you have verified the claim internally -- but you cannot take hours to do so. Your response to the journalist is: "We have just become aware of this allegation and are taking it with the utmost seriousness. We will respond on the record by [time, maximum 30-60 minutes]." Simultaneously: emergency call with legal, operations, and executive leadership to verify. If the allegation is confirmed: issue the holding statement before the story runs if possible. If unconfirmed: tell the reporter on record that you cannot confirm the allegation but are investigating urgently, and provide your holding statement once verified. Never let a reporter's deadline force an unreviewed public statement.
2. Third-Party Fault -- Your Vendor, Supplier, or Partner Caused the Crisis
A cloud service provider's outage took your platform down for eight hours. A logistics partner lost customer shipments. A contractor's employee committed misconduct on your premises. The fault is not yours, but your customers experienced harm through your relationship.
Handling: Legally the distinction between vendor fault and organizational fault matters -- operationally and reputationally, your customers don't care. Your communications must acknowledge customer impact (which is real and yours to address) without assigning public blame to the third party during the acute phase. "Our service was disrupted due to an issue with a critical infrastructure partner. We are working directly with them to restore service and prevent recurrence." Once the immediate crisis is resolved, factual attribution is appropriate in the post-crisis analysis. Privately, your legal team is already in contact with the vendor. Publicly blaming your vendor during the crisis reads as deflection and makes you look operationally negligent for having chosen them.
3. The Executive Is the Crisis -- Internal Misconduct at the Leadership Level
The CEO, board chair, or senior executive is accused of sexual harassment, financial fraud, discrimination, or public misconduct. The organization's crisis is inseparable from the person who would normally lead the crisis response.
Handling: The named executive must be removed from all crisis communications immediately -- they cannot be spokesperson or approver for their own misconduct crisis. Identify the next most senior executive (typically COO or Board Chair) to lead response. Holding statement must come from the organization, not the individual. The board of directors activates immediately -- this is a governance crisis as much as a communications crisis. Language must be definitive about action taken (administrative leave at minimum, termination if appropriate and legally defensible) and about the investigation (independent, not internal HR). The named individual should not issue a personal statement without separate personal legal counsel -- and their personal statement, if any, must not contradict the organizational statement. Companies that attempt to stand behind an accused senior executive while "investigating" typically face a second, larger crisis when the investigation confirms what was reported.
4. A False or Substantially Inaccurate Report Goes Viral
A journalist, influencer, or former employee publishes a claim about your organization that is factually wrong in material ways -- not merely unflattering but demonstrably incorrect. It is spreading rapidly.
Handling: Speed matters because viral misinformation compounds. Your response must be rapid (within two hours) but surgical. Issue a fact-specific correction, not a defensive screed. Format: "We want accurate information available. Here are the facts we can confirm: [numbered list of specific factual corrections with supporting evidence where available]. We take [genuine underlying concern, if any] seriously and [any relevant action]." Do not use the word "false" or "lie" in your initial correction -- it escalates conflict and positions this as a fight. If the core underlying concern has any validity even if the specific claim is exaggerated, acknowledge the validity before correcting the specifics. If the claim is entirely fabricated with no basis in fact, you may consider a formal demand for correction through media channels, but your legal team must advise on this -- public threats of legal action against press typically create worse coverage than a factual correction.
5. Crisis Occurs During a News Blackout Window -- Holiday Weekend, Major Breaking News Event
Your crisis breaks on Christmas Eve, during a major election, or while a natural disaster dominates news cycles. Your normal media contacts are unavailable and public attention is elsewhere.
Handling: Two competing dynamics operate here. On one hand, media capacity is reduced and public attention is diverted -- a poorly timed crisis may receive less initial coverage. On the other hand, attempting to "bury" a crisis in a news blackout has become itself a news story and reads as cynical and deliberate. The correct approach: proceed with all crisis communications exactly as you would in normal circumstances. Issue holding statement within 60 minutes. Internal communications within two hours. Full statement within four. The benefit is that you have more time to get communications right before journalist responses arrive. The risk is that if coverage does break later, "they disclosed this on Christmas Eve" becomes part of the narrative. Proactively brief your most important journalist relationships when they return, so you control the framing rather than letting them discover it cold in an archived press release.
6. Crisis Escalates After Initial Response -- New Information Makes Initial Statement Incorrect
You issue a holding statement that 2,000 customer accounts were affected. Forty-eight hours into the investigation, the actual number is 280,000. Your initial statement is now public and wrong.
Handling: This is one of the most damaging scenarios in crisis communications because it creates a "cover-up" narrative regardless of intent. The only path through is proactive, voluntary correction before journalists discover the discrepancy. Issue a correction statement immediately upon confirming the new information. The correction must: acknowledge the discrepancy explicitly, explain why the initial information was incorrect (investigation was ongoing, not deliberate misstatement), provide the correct information, and add additional remediation commensurate with the larger scope. The statement: "As our investigation has progressed, we have determined that the scope of this incident is significantly larger than our initial assessment indicated. We are providing this correction immediately upon confirmation. We now know that [correct information]..." A correction issued by you is bad. A correction issued by a journalist who discovered your initial statement was wrong is a catastrophe. Issue corrections the moment you have confirmed new information, without waiting for a scheduled update.
7. Regulatory Disclosure Requirements Conflict With Communications Strategy
Your legal team identifies that a data breach triggers mandatory disclosure timelines under GDPR (72 hours), HIPAA, SEC material event disclosure, or state breach notification laws. The communications team's ideal response sequence doesn't align with regulatory deadlines.
Handling: Regulatory disclosure is non-negotiable and takes precedence over communications strategy. The 72-hour GDPR notification clock does not care about your messaging readiness. Immediately confirm with legal counsel what specific regulations apply, which regulatory bodies require notification and when, and whether the regulatory notification is public or confidential to the regulator only. In most cases, mandatory regulatory disclosures are to the regulator, not the public -- public communications can then be coordinated to align with regulatory timelines. Where public disclosure is legally required (SEC material events, for example), legal and communications must work in parallel under tight timelines, not in sequence. Never instruct communications teams to delay a legally required disclosure in order to develop better messaging -- this is the definition of a cover-up and creates criminal exposure for individuals involved.
8. Social Media Pile-On Without a Clear Factual Claim -- Sentiment Crisis
No specific incident has occurred, but a hashtag campaign, viral tweet thread, or TikTok video accumulates massive negative sentiment about your organization based on a general grievance, cultural moment, or comparison to a competitor. There is no discrete event to address.
Handling: This is a reputational crisis rather than an incident crisis, and the response strategy differs significantly. Do not issue a "crisis" statement -- this validates and amplifies the narrative. First: listen without responding for 2-4 hours to understand whether sentiment is driven by a specific grievable issue, a cultural moment, competitive trolling, or genuine pattern of customer experience. Identify whether there is any factual basis to the sentiment -- if yes, address the underlying issue substantively, not just the social media noise. If the sentiment is driven by a genuine pattern, the communications response must be paired with operational changes -- otherwise the response reads as hollow. If the sentiment is manufactured or substantially bad-faith, consider: (a) prominent genuine customer voices and third-party supporters who can speak on your behalf, (b) factual content that demonstrates the counter-narrative through evidence, (c) no direct engagement with the hashtag or campaign itself, which would amplify it algorithmically. Resist the pressure to issue a statement for the sake of saying something -- a thoughtful response 24 hours later is better than a reactive statement in four hours that becomes a new target.
Example
Input:
"We are a healthcare technology company with about 800 employees. We just found out an hour ago that one of our cloud storage buckets was misconfigured, and patient health records were exposed publicly for approximately three weeks. We believe about 47,000 patient records were affected. These are records from hospital clients who use our platform. Our CEO just learned about it. We have not yet contacted our hospital clients, the patients, the media, or regulators. Our legal team is coming online now. What do we do?"
Output:
CRISIS COMMUNICATION BRIEF
Organization: Healthcare technology company, ~800 employees
Incident Type: Data breach -- patient health records exposed via misconfigured cloud storage
Incident Date/Time: Exposure period: approximately 3 weeks. Discovery: [today's date, approximately 1 hour ago]
Records Affected: ~47,000 patient records (confirm exact count before any public statement)
Current Public Status: Not yet public -- but exposure has been live for 3 weeks; assume unknown parties may have accessed or retained data
Incident Status: Contained (misconfiguration has been or should be immediately corrected -- confirm with engineering NOW)
Legal Counsel Engaged: Coming online now -- top priority is to brief them in the next 15 minutes
Regulatory Framework: HIPAA applies (healthcare records), HITECH Act breach notification, state breach notification laws for each state where affected patients reside, and potentially GDPR if any EU patients are included
Designated Spokesperson: To be confirmed -- CEO is appropriate primary; CCO or VP Communications as operational point of contact for media
IMMEDIATE ACTION CHECKLIST -- NEXT 60 MINUTES
| Time | Action | Owner | Status |
|---|
| RIGHT NOW | Confirm cloud bucket is sealed/reconfigured -- remediation before anything else | Engineering lead | [ ] |
| RIGHT NOW | Confirm exact record count with engineering (47,000 is preliminary) | Engineering / CISO | [ ] |
| 0-15 min | Brief CEO with facts: scope, timeline, remediation status, regulatory exposure | CCO / Legal | [ ] |
| 0-15 min | Activate crisis team: CEO, CCO, General Counsel, CISO, COO, Head of Client Relations | CCO | [ ] |
| 0-15 min | Freeze all external communications and pause all scheduled content | Marketing | [ ] |
| 0-15 min | Brief Legal on HIPAA 60-day notification clock and HHS reporting requirements | General Counsel | [ ] |
| 15-30 min | Draft holding statement for hospital clients (NOT yet for media or public) | CCO | [ ] |
| 15-30 min | Identify all affected hospital clients -- which institutions, how many patients per institution | Client Relations | [ ] |
| 30-60 min | Personal phone calls to C-suite contacts at each affected hospital client | CEO + Account leads | [ ] |
| 30-60 min | Approve and send holding statement to hospital clients | CEO / Legal | [ ] |
| 60-90 min | Employee communication -- all staff | HR + CCO | [ ] |
| By Day 3 | HHS breach notification (HIPAA requires notification if breach affects >500 individuals in a state; full HHS report within 60 days; individual patient notification within 60 days) | Legal | [ ] |
Critical note on HIPAA timing: Under HIPAA and HITECH, your hospital clients (as covered entities) must notify affected patients within 60 days of discovery. Your company, as a Business Associate, must notify your covered entity clients "without unreasonable delay and no later than 60 days" after discovery of a breach. That 60-day clock started the moment this was discovered -- approximately one hour ago. Do not confuse "60 days" with "we have 60 days to decide whether to tell anyone" -- legal must be in the loop now, today.
HOLDING STATEMENT -- FOR HOSPITAL CLIENTS ONLY (First Communication)
Target delivery: Phone call to C-suite contact at each affected hospital, followed immediately by written confirmation via email. Not for public or media release at this stage.
Approved by: CEO + General Counsel [pending]
Delivery method: Personal phone call from CEO or VP Client Relations, followed by written version below
Written version (following verbal call):
Subject: Urgent Security Notification -- Immediate Action by [Company Name]
[Hospital Client Contact Name],
I am writing to follow up on the call you just received from [caller name]. We are notifying you immediately because you and your patients are our highest priority.
We have identified and immediately remediated a misconfiguration in one of our cloud storage environments that may have exposed patient records from your institution between [approximate start date] and [today's date]. We are actively conducting a forensic investigation to determine the precise scope, the exact records involved, and whether any unauthorized access occurred.
We have engaged [external cybersecurity forensics firm category] to assist in the investigation. We will provide you with a full technical briefing within 24 hours, including the specific records involved, the forensic evidence regarding access, and our recommended steps for your HIPAA notification process.
We take complete responsibility for this. Our team is entirely dedicated to supporting your institution through this process.
We will contact you again by [specific time tomorrow] with a comprehensive update. In the meantime, please contact [Name, Title, direct phone number] for any immediate questions.
[CEO Name]
[Title]
[Direct phone]
INTERNAL EMPLOYEE COMMUNICATION (Within 2 Hours)
Distribution: All staff, company-wide email
From: CEO
Subject: Important -- Security Incident Update -- Please Read Now
Team,
I need to share an important and serious situation with you directly.
Earlier today we identified a security misconfiguration that exposed patient records processed through our platform. We have immediately sealed the exposure and activated our incident response protocols. We are working with external cybersecurity experts and our legal team.
What this means for you:
- Do not discuss this incident with anyone outside the company -- including friends, family, or on social media -- until further notice.
- Direct all inquiries to [comms contact name, email, phone]. If a journalist, client, or patient contacts you, say only: "I'm not the right person to speak to this. Please contact [name] at [contact]." Do not improvise.
- Do not speculate about causes, scope, or responsibility in internal communications or chat channels.
- Your next update from me will come by [specific time today/tomorrow].
We will handle this with complete transparency and full accountability. This is difficult, but how we respond will define us. I am proud of how quickly our team identified and sealed this issue. The next steps require the same focus and integrity.
[CEO]
SUBSTANTIVE RESPONSE -- HOSPITAL CLIENT FULL BRIEFING (24 Hours Post-Discovery)
This communication goes to your hospital client contacts after the forensic investigation has produced its initial findings.
FOR IMMEDIATE DISTRIBUTION TO AFFECTED HOSPITAL CLIENTS | [Date]
Re: Security Incident Full Briefing and Remediation Plan -- [Company Name]
What happened:
On [discovery date], [Company Name] identified that a cloud storage environment used to process patient data was misconfigured, allowing unauthorized external access between [start date] and [discovery date] -- a period of approximately [X] days. The misconfiguration has been corrected. The affected storage environment contained records from [number] patients associated with [hospital name].
What we have confirmed:
- Records exposed: [specific categories -- name, date of birth, diagnosis codes, treatment information, etc. -- be specific, do not generalize]
- Record count for your institution: [number -- institution-specific breakdown]
- Exposure window: [specific dates]
- Forensic access evidence: [what the logs show regarding whether external parties accessed or downloaded data -- if unknown, say so]
- No other storage environments were affected.
What we have done:
- Immediately sealed the misconfigured storage environment upon discovery [date/time].
- Engaged [forensic firm category] to conduct a complete forensic investigation -- findings delivered by [date].
- Completed an audit of all storage configurations across our entire platform -- results: [findings].
- Placed all systems under enhanced monitoring.
- Engaged external legal counsel specializing in HIPAA compliance to support your institution's notification obligations.
What we are doing next:
- Deliver a patient-level record manifest to your HIPAA Privacy Officer by [date] so you have the complete affected patient list for your notification process.
- Provide a dedicated compliance support contact for your legal team at no charge.
- Commission an independent third-party security audit of our complete infrastructure, with results to be published by [date].
- Hire a Chief Information Security Officer reporting directly to the CEO by [date].
Your HIPAA notification obligations:
Under HIPAA, you as the covered entity are responsible for patient notification within 60 days of breach discovery ([calculated date]). We will provide everything you need to meet this obligation. Your dedicated support contact is [name, phone, email].
Leadership accountability:
This failure was ours. A misconfiguration of this type should have been caught by our internal audit procedures and was not. [CEO Name] and the executive team have taken direct ownership of the investigation and remediation program.
Next update: Full forensic findings delivered to your team by [specific date/time].
[CEO Name] | [Direct contact]
[General Counsel Name] | [Direct contact]
SPOKESPERSON BRIEFING SHEET -- CEO
Key messages (these three form every external response):
- We identified this immediately upon discovery and sealed it. We are conducting a full forensic investigation and will share complete findings.
- We have notified our hospital clients directly, are providing them full support for patient notification, and are taking complete responsibility.
- We have made structural changes to prevent this -- including [specific named actions] -- and will publish a third-party audit of our entire security infrastructure.
Hard questions and bridging approaches:
| Anticipated question | Bridge phrase | Approved response |
|---|
| "Why did it take three weeks to discover this?" | "The most important thing for me to tell you is..." | "We identified this through [internal audit / monitoring process]. We are investigating why our detection timeline was not faster and have [specific detection enhancement] now in place. Complete forensic findings will be published by [date]." |
| "Did anyone access the records?" | "What we know from our forensic investigation so far is..." | "We are conducting a complete forensic review of access logs. We will share what that investigation confirms. We are treating this as a breach that requires full patient notification regardless of what the access logs show, because that is the right thing to do." |
| "Are you facing HIPAA fines?" | "I can't speak to regulatory outcomes..." | "I'm not in a position to predict regulatory outcomes. What I can tell you is that we are cooperating fully with all relevant oversight and that our hospital clients have our complete support in meeting their notification obligations." |
| "Is this grounds for clients to terminate their contracts?" | "What I know is..." | "That is a decision for our clients. What I am focused on is doing everything in our power to support them through this situation and demonstrating through our actions why they can trust us going forward." |
| "How many patients were affected?" | "Our investigation has confirmed..." | "[Number] patient records from [number] hospital clients were in the affected storage environment. We are providing each institution with an institution-specific patient manifest." |
Do not say: specific dollar figures for remediation costs, names of forensic firms (unless approved by those firms), speculation about who accessed the data or why, characterizations of intent ("we never intended," "this was an honest mistake" -- too dismissive), the phrase "at this time" (signals there is a different answer coming later), "we take privacy seriously" without immediately following with specific actions that prove it.
APOLOGY ASSESSMENT
Apology warranted: Yes. Organization is directly responsible for the misconfiguration. Facts are sufficiently confirmed (scope may evolve). Legal counsel should review specific language, but accountability is not in question.
Draft apology -- CEO statement:
"I want to speak directly to every patient whose records were affected by this breach.
What happened was a failure of our security processes, and that failure is my responsibility and the responsibility of this company. Patient health information is among the most sensitive data that exists, and we were entrusted with protecting it. We did not meet that obligation.
I understand that seeing your private health information exposed -- without your knowledge, for weeks -- is a violation of trust that goes beyond the technical facts. The worry that comes with not knowing who may have seen your records or what they may do with them is real and serious, and I am deeply sorry that we put you in this position.
Here is what we are doing:
Your hospital will contact you directly with the specific information about your records and what steps we recommend. We are providing [specific identity monitoring or relevant support resource] at no cost to you. You can reach our dedicated patient support line at [number], staffed [hours], beginning [date].
We have made immediate structural changes to our security infrastructure, and we will publish the results of an independent security audit by [date]. I have hired a Chief Information Security Officer who reports directly