Skip to content
atlas

Crisis management

Also known as: crisis response

How top management leads the whole organisation through a serious event - decisions, priorities, staff, customers and press.

Draft - this entry has not been reviewed yet.

Formal

The leadership level of the response to a severe disruption, in which a crisis team makes business decisions, sets priorities, handles communication with staff, customers, media and authorities and starts continuity plans, while technical teams handle the incident itself.

In plain English

Like parents after a house fire - the fire brigade fights the flames, but the parents decide where the family sleeps tonight, who calls the insurer and what to tell the children.

In practice

During a ransomware attack on a Danish dairy company, the crisis team meets every three hours, decides to take orders from shops by phone, approves a press statement and chooses not to pay the ransom.

Why it matters

A serious attack is a business crisis, not only an IT problem, and slow or muddled leadership can cost more in trust than the attack itself.

Technical deep dive

ISO 22361:2022 treats a crisis as an abnormal and unstable situation that threatens an organisation's strategic objectives, reputation or viability, and distinguishes crisis management from incident management by the nature of the problem rather than its size. Incidents are handled with prepared procedures; a crisis is characterised by high uncertainty, novelty, time pressure and conflicting interests, so it has to be managed with judgement and decision-making rather than by following a plan step by step. Many cyber incidents never become crises, while a modest data leak can become one if it involves vulnerable people, public outrage or regulatory scrutiny.

The typical structure is layered. A strategic crisis management team of senior executives decides on priorities, trade-offs and external positions; a tactical level coordinates resources across functions; and operational teams, including the incident response team, carry out the work. The UK emergency services' gold, silver and bronze command model is a common reference for these tiers. The crisis team works in a fixed rhythm of meetings, each opening with a common situation picture, reviewing actions from the previous cycle and ending with decisions recorded in a decision log with rationale, so that choices made under uncertainty can be explained afterwards to boards, auditors and regulators.

Cyber crises bring specific decisions to the table: whether to disconnect from the internet or shut down production, whether to pay or negotiate a ransom (with sanctions, legal and insurance constraints), when to involve the police and the national CSIRT, what to tell customers before the facts are known, and how to keep delivering critical services. Norsk Hydro's response to the LockerGoga ransomware in 2019, with manual production and daily open press briefings, and Maersk's recovery from NotPetya in 2017 are frequently cited cases of crisis management that preserved trust despite severe operational damage.

NIS2 Article 21(2)(c) names crisis management alongside business continuity as a required measure, and Article 20 makes the management body responsible for approving and overseeing cybersecurity risk-management measures and requires its members to undergo training. At EU level, Article 16 establishes EU-CyCLONe to coordinate large-scale cybersecurity incidents and crises between member states. Crisis management differs from incident response in that incident response contains and eradicates the technical cause, while crisis management steers the organisation through the business, legal and reputational consequences; the two run in parallel and need a clear interface, usually an incident lead who briefs the crisis team.

What to learn first

Everything this builds on, foundations first.

  1. Asset inventory
  2. →Availability
  3. →CIA triad
  4. →Asset
  5. →Critical assets
  6. →Impact
  7. →Business impact analysis (BIA)
  8. →Business continuity plan (BCP)
  9. →Crisis management

Relationships

Don't confuse with
Incident response

Sources & further reading

Standards & official texts

  • ISO 22361:2022 - Security and resilience - Crisis management

Course material

  • Cyber Security Fast Track - Kursuskompendium, Modul 7 og Ordliste (BCP, Kommunikationsplan)

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.