A crisis communication plan governs who speaks and when. It almost never records what was decided or why. That gap means the spokesperson defends a position nobody wrote down, and the first hard question from a journalist exposes it. Templates solve the logistics. They leave the judgement unprotected.
A client asked me to review their crisis communication plan last year. It ran to forty pages. Spokesperson roster named and media-trained. Approval chain from CEO through General Counsel to Head of Communications, with a backup at each level. Holding statements pre-drafted for six scenarios, pre-cleared by legal. Channel protocols specified which platforms carried the message, in what sequence, at what frequency. Contact lists for regulators, key clients, and board members verified that quarter.
I read the entire plan twice before I could say exactly what was missing: there was not a single sentence, anywhere in those forty pages, that recorded what the organisation had actually decided about any of the situations the plan was supposed to handle.
A crisis communication plan is a coordination protocol: who speaks, what approval sequence a statement follows, which channels carry the message.
The statement that did everything right
When CrowdStrike pushed a faulty sensor update in July 2024 and crashed roughly 8.5 million Windows devices worldwide, CEO George Kurtz had a public statement out within hours. It was technically accurate and confirmed the outage was not a cyberattack. It said a fix had been deployed. By every measure of speed and factual precision that a crisis communication plan is designed to enforce, the response worked exactly as intended.
Crisis-communications consultant Davia Temin described the result as "a response scrubbed by a legal team with lawsuits in mind." The statement said everything the approval chain required and nothing the audience needed to hear. There was no apology and no acknowledgment that the company had just brought down hospital systems, airline check-in desks, and banking platforms across multiple continents. Kurtz had to correct course hours later, and by then roughly $30 billion in market value had evaporated.
This was not a failure of the plan; the plan performed its function and got a legally cleared, factually accurate statement out fast. The failure sat one level above the plan, in a question nobody had resolved before the crisis arrived: was owning the failure publicly worth the litigation risk? The plan had a field for "legal clearance" but no field for "judgment call about what we owe the people we just harmed."

When the protocol becomes the cover
In 2016, a data breach at Uber exposed 57 million user and driver records, and the company's chief security officer, Joseph Sullivan, had a protocol at hand: the bug bounty program, designed to handle exactly this kind of discovery. Sullivan routed a $100,000 payment to the hackers through the existing program and obtained a non-disclosure agreement stating that no data had been taken. The mechanism worked precisely as it was designed and documented to work.
What the mechanism never asked was whether a breach of this scale had to be disclosed to the Federal Trade Commission, which was at that moment investigating Uber for a previous breach involving different data. Sullivan was convicted of obstruction and misprision of felony in October 2022, the first corporate security executive ever criminally convicted for breach-response conduct. The Ninth Circuit upheld the conviction.
Sullivan already had a procedure for handling exactly this kind of discovery. What he had never resolved was whether a breach of this magnitude required disclosure, and the procedure he already had filled the silence comfortably enough that nobody paused to ask the question.
In August 2023, wildfire swept through Lahaina on Maui and killed more than a hundred people, the deadliest wildfire in the United States in over a century. Hawaii maintained an all-hazard warning network of roughly 400 sirens, tested monthly, designed for exactly this class of emergency. The sirens were not sounded. Herman Andaya, the administrator responsible, decided under pressure that residents would associate the sirens with a tsunami warning and move inland toward the fire. He resigned nine days later, after sustained public criticism.
The warning network existed and was maintained according to schedule. Nevertheless, nobody had pre-decided whether this particular hazard warranted this particular mechanism, so the question was answered in the moment by a single person who got it catastrophically wrong.
Open your crisis communication plan and find the decision it is supposed to communicate, before the next crisis finds it for you. Start the Walk →
What a crisis communication plan cannot replace
The pattern across these three cases is consistent and worth stating plainly. CrowdStrike's statement-clearance chain worked and Uber's bug bounty protocol worked. So did Maui's siren network. In each case the artifact that was supposed to prevent failure performed exactly as built, and in each case the failure sat one level above the artifact, in a decision the artifact was never designed to make.
This is the central problem with the crisis communication plan as it is conventionally constructed. The plan specifies the apparatus: who approves, who speaks, and which channels carry the message. That apparatus is coordination machinery, and it is certainly necessary.
But the plan treats coordination as if it were the hard problem, when in fact the hard problem is the decision the apparatus then communicates. The plan is structurally silent on that decision.
A risk management framework built entirely from artifacts converts unresolved questions into filed documents. Registers categorise threats and heat maps produce colour-coded displays that make the organisation feel covered.
The crisis communication plan is one more artifact in that collection, and it is the most visible one because its failure plays out in public. But the gap it contains is the same gap that runs through the risk register and every other piece of filed paperwork that substitutes for a recorded judgment. Nobody notices that the document answers "who speaks" and "how fast" but never records "what we decided" or "what we assumed when we decided it."
What the crisis communication plan needs before the crisis arrives
The crisis communication plan needs something that no template I have seen includes: a record of the decisions the plan exists to communicate. This is not aspirational; it is mechanical, and it follows directly from the way Roger and I structured the Universal Decision-Making Method we have used with clients.
For any decision that might produce a crisis, the plan should contain what templates leave out. It should record the specific commitment: not a policy label but a decision. "We will store driver records on servers managed by vendor X with encryption standard Y" is a decision. "We are committed to data security" is not.
Alongside the commitment, it should state the assumptions supporting it and the conditions under which those assumptions would fail: "Vendor X will maintain compliance with standard Y because their contract requires annual audit. If vendor X fails an audit, the assumption has failed and we reopen the decision." Those elements turn a holding statement into something that can actually be checked against reality when the crisis arrives.
When the crisis arrives, you do not start from a blank holding statement and try to reconstruct what you think under the worst possible conditions. You open the record and check whether the assumptions still hold. If they have failed, you say so and you name what changes.
The statement follows directly from the record, because it describes a real commitment that either held or did not. The alternative is a position invented under pressure by a committee that cannot remember what was originally decided.
Wouter Jong published a 30-item checklist for evaluating crisis communication in 2021 because the field still could not agree on what good crisis communication looked like in real time. Even the researchers, when they tried to improve the discipline, produced a retrospective scoring instrument that scored decisions after the fact rather than offering a better way to make them in the moment. That tells you something about where the gap actually sits, and it is not in the template.
If your CEO has asked you for a crisis communication plan by end of month, build one: name the spokespersons, draft the holding statements, and get them cleared.
Then do the thing the template will never prompt you to do: for each scenario the plan covers, write down what the organisation has actually decided and what that decision assumes. State the conditions under which you would need to say something different. What you end up with is a decision record with communication protocols attached.
You could polish the crisis communication plan and still leave the decision it communicates unrecorded.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.