What is crisis communications?
By Joel Andren · Published by PressFriendly, a PR agency · Reviewed August 21, 2026 · Editorial standards · 10 of 10 in this section
Crisis communications is the governed flow of verified information before, during, and after an incident. It helps affected people make decisions, supports operational response, and keeps employees, customers, partners, investors, regulators, and the public informed. It cannot replace safety work, containment, forensics, legal analysis, required notices, business continuity, or remediation.
Incident command and harm reduction control communication
Put communications inside the response structure. The incident type changes the specialists, but the authority split should remain clear:
| Owner | Decision |
|---|---|
| Incident lead | Priorities, operating picture, cadence, and workstream owners |
| Domain lead | Safety, security, product, finance, workforce, or operational facts and response |
| Counsel and compliance | Legal duties, preservation, privilege, regulators, and notice review |
| Communications lead | Stakeholders, approved updates, inquiries, channels, and response monitoring |
| Executive owner | Resources, material tradeoffs, and accountability for remediation |
For cyber incidents, NIST's April 2025 SP 800-61 Rev. 3 integrates incident response into cybersecurity risk management. The FTC's data breach response guide recommends a cross-functional response and warns against misleading statements or disclosures that create further risk. Notification duties vary by jurisdiction, data, industry, contract, and facts. The communications provider should not decide them.
Readiness and active response are different purchases
Readiness support should leave the company with:
- a role and decision matrix with primary and backup owners;
- stakeholder, channel, account, recovery, and out-of-band contact records;
- secure collaboration and approval arrangements;
- notification and escalation paths owned by qualified specialists;
- monitoring, inquiry routing, and correction responsibilities; and
- an exercise record, identified gaps, and remediation owners.
The joint CISA, FBI, NSA, and MS-ISAC StopRansomware Guide recommends maintaining and exercising an incident response plan and associated communications plan, including response and notification procedures. It also recommends an offline copy because normal systems may be unavailable or monitored.
Active-response support joins the existing incident team. Its scope may cover verified-fact intake, stakeholder updates, inquiry management, misinformation monitoring, correction, channel operation, and recovery communication. Require a named senior lead, 24-hour coverage terms where needed, secure handoffs, and a clear end or transition point.
Select outside support for the incident and operating model
A general PR agency may be suitable for readiness or lower-severity issues when it has relevant experience. A cyber breach, fatality, product safety event, litigation, regulatory action, or workforce crisis may require a specialist team coordinated with counsel, forensics, safety professionals, insurers, or other domain owners.
Evaluate providers on:
- comparable incidents and the proposed lead's actual role;
- ability to work under the company's command structure;
- availability, backup staffing, geography, and language coverage;
- secure handling, access controls, subcontractors, and conflicts;
- working relationships with counsel and technical specialists;
- fees for readiness, activation, after-hours work, travel, and surge staffing; and
- handoff, asset delivery, retention, and deletion terms.
Check insurance notice and vendor-consent conditions before an incident where possible. During an active event, do not let a broad competitive process delay safety, containment, or required response.
The company retains facts, notices, accounts, and risk
The incident lead owns the operating picture. Domain leaders approve their facts. Counsel and compliance own legal analysis and notice requirements. The communications lead owns the approved communication workflow. The company retains its channels, recovery access, source record, monitoring data, and published archive. Spokespeople own their on-record answers; the executive owner accepts material tradeoffs.
Measure whether priority stakeholders received accurate, useful, and timely information, whether inquiries and corrections were handled, and whether communication supported recovery. Volume, sentiment, or favorable coverage cannot establish that the incident response succeeded.
Use how to buy crisis communications support for provider scope and governance. The gated Startup PR Playbook contains the working procedure.