🚨 My latest Forbes Opinion Piece is live! 🚨 Over the last decade I have led high stakes cyber crisis response assignments as well as facilitated dozens of executive cyber crisis simulations with my clients and global leaders who go through our flagship Cyber Leadership Program (CLP). In my latest Forbes article I discuss five critical but often overlooked measures to boost cyber crisis response: 1️⃣ Manage team burnout and stress – rotations, counselling, and clear staff briefings prevent fatigue and fear from derailing response efforts. 2️⃣ Secure legal privilege early – without airtight legal frameworks, forensic reports may be exposed in litigation, as Optus discovered in 2023. 3️⃣ Seek legal injunctions – court orders can restrict third parties from spreading stolen data, minimizing reputational and regulatory fallout. 4️⃣ Draft holding statements in advance – pre-approved templates for media, regulators, high-value clients, and customers prevent delays and missteps under pressure. 5️⃣ Adopt a board-approved ransomware payment matrix – having predefined criteria avoids chaotic boardroom debates during high-stakes negotiations. 👉 These are not theories, but practical lessons from the frontlines of cyber leadership that often spells why some organisations quickly bounce back from cyber beaches while others are hacked into bankruptcy. Link in comments section. . I’d love to hear your views. What other essential measures are often overlooked in the heat of the moment. #CyberSecurity #Leadership #IncidentResponse #Forbes
Crisis Management Training
Explore top LinkedIn content from expert professionals.
-
-
Crisis management is a critical skill in communications. But here’s the truth: By the time you start managing a crisis, you’re already behind. That’s why crisis prevention matters more than crisis management. Prevention is possible. Here’s how: Study your internal systems—beyond just communications. Look at production, sales, marketing, admin, compliance, and more. Connect regularly with practice leaders. Monthly check-ins are ideal for spotting issues early. Flag anything that could trigger a future crisis. If possible, join meetings where corrective actions are discussed. Build potential crisis scenarios for each identified trigger. This is where prevention ends, and preparation begins. Create training modules for each crisis scenario. Assign clear responsibilities for every action in these scenarios. Run periodic mock drills to test your readiness. Adjust the frequency based on the scenario. Business is dynamic. Even with all the preparation, surprises can happen. But with a crisis prevention mindset, you’ll be ready to manage with speed and agility.
-
Crisis training isn’t optional. It’s CPR for your reputation. Yesterday, I ran a half-day, issues & crisis-focused media interview workshop for my long-time client, Goodwill of South Central Wisconsin. I will die on the hill that every organization with public-facing operations needs to run updated media trainings, crisis simulations, and playbook reviews 3–4 times per year. Why? Because it’s no different than office/school fire drills or renewing your CPR cert. You don’t do them because you expect the worst tomorrow; you do them because lives, livelihoods, and millions of dollars are at stake if you don’t keep your response muscles fresh. Pay a little now. Or pay much more later. Here are the core elements of my crisis trainings, updated with feedback from 30+ fellow trainers, journalists, and comms pros: 1. Safe Space & Energy – Ice breakers and laughter lower the stakes so trainees can fail fast and learn. 2. News Value & Archetypes – Journalists hunt for conflict, hypocrisy, humor, contradiction (“man bites dog”), rags-to-riches, romance gone bad, David vs. Goliath. And they’ll cast you as hero, villain, or something in between. Know both before you walk in. 3. Prep Your Headlines – Pick 2–3 key points you must convey. Even if your interview is 30 minutes, it may be condensed into one 10-second soundbite or a single sentence. If you said it, it’s fair game — context or not. 4. Modes Matter – Decide: are you educating with nuance, or delivering tight soundbites? The worst interviews are when you mismatch. 5. Foundations – Bridging, blocking, flagging, hooking. And always have a call to action ready. 6. Don’t Repeat Negatives – If asked “why is your company failing at X,” never restate “we’re not failing.” That soundbite will haunt you. Reframe and redirect. 7. The Big Crisis Questions – What happened? Who’s to blame? What are you doing to make it right? Train for these — they’ll come every time. 8. Nonverbals – Solid colors. Hands visible. Lean in. Silence beats nervous rambling. 9. Mock Interviews ON CAMERA – Not an iPhone selfie. Real lights, mic, hostile rapid-fire Qs. Run two full reps per person. 10. Respectful Feedback – Watching yourself is awkward. In a trust-based room, it’s priceless. 11. On the Record ≠ Optional – Yes, there’s on background, off record, and Chatham House rules. But unless there’s rare mutual consent, assume everything is on the record. Mic is always on. 12. Refreshers – Media training is never “one and done.” Quarterly reps keep you sharp. 👉 That’s my list. What’s yours? What’s the one drill, exercise, or tactic you swear by to make crisis simulations stick? And if your team hasn’t dusted off its crisis plan in a hot second — or you’ve never pressure-tested your spokespeople under fire — it might be worth a quick convo with someone who’s been in the room (I’m always happy to chat). Because crisis comms isn’t theory. It’s muscle memory. And muscle memory only works if you keep training.
-
Every communication professional should understand this: Crisis communication is not only about responding when things go wrong. It is the strategic management of information, perception, and trust under pressure. It is how you speak when stakes are high, emotions are elevated, and people are watching closely. Handled well, it can preserve credibility. Handled poorly, it can damage years of trust in a matter of hours. So what should every communication professional know? - Before a Crisis (Preparation is your advantage) Prepare before the crisis, not during it. The strongest organizations do not improvise crisis communication. They plan for it. They define protocols, assign roles, and anticipate scenarios. Preparation is what allows composure under pressure. This also means knowing your risks, aligning leadership, and ensuring everyone understands how communication will flow when it matters most. Because when a crisis hits, confusion inside the organization will always show up outside. - During a Crisis (This is where trust is tested) a. First, speed matters; but accuracy matters more. Silence creates a vacuum, and that vacuum will be filled with speculation. But rushing out unverified information can worsen the situation. The balance is to respond quickly, while ensuring what you say is grounded and reliable. b. Second, acknowledge before you explain. In a crisis, people are not just looking for information; they are looking for reassurance. Acknowledge the issue clearly, show awareness., then provide context. Skipping acknowledgment often comes across as avoidance or insensitivity. c. Third, control the narrative early. If you do not define what is happening, others will define it for you. The first few communications in a crisis often shape public perception long after the situation is resolved. d. Fourth, consistency builds trust. Mixed messages from different spokespeople create confusion and weaken credibility. Align internally before speaking externally. One message, clearly delivered. 5. Fifth, tone is as important as content. In high-pressure moments, how you say something matters just as much as what you say. Defensive, dismissive, or overly technical language can escalate tension. Calm, direct, and human communication helps stabilize it. - After a Crisis (Reputation is rebuilt here) The work does not end when the storm dies down. You must continue communicating, clearly and consistently, until confidence is restored. Rebuilding trust requires transparency. Review what happened. Identify gaps, strengthen your systems and most importantly, reshape the narrative so the crisis does not become the only story people remember about your organization. Because the truth is this: A crisis is not the time to decide how your organization communicates. It is the time your communication is tested and when that moment comes, your response will do more than address the issue.
-
#Incidents Don’t Ruin #Reputations—Poor #Responses Do In any organizational #crisis, the response can have a bigger impact than the incident itself. #Cybersecurity breaches? Even more so. They don’t just hit your systems.. they test your #resilience, #trust, #transparency, and #tone. Let’s take a look at how different companies responded to major incidents, and what we can learn from them: ❌️ #Equifax (2017): Hackers accessed sensitive data of 147 million people, but the real damage came afterward. The company #delayed and waited weeks to disclose the breach, offered #unclear guidance, and #mishandled public communication. The result? Public #outrage, #lawsuits, and #billions lost. The breach was bad, but the response made it worse. ❌️ #Uber (2016, revealed in 2017): Instead of disclosing the breach, Uber #paid hackers $100,000 to cover it up and disguised it as a “bug bounty.” Once exposed, the #backlash was swift, #regulatory investigations, #reputational harm, and #leadership changes followed. A case study in what not to do. ✅️ #Microsoft (2020 SolarWinds attack): Though impacted, they didn’t hide. Microsoft #shared technical insights, #guided customers, and called for international #cooperation. Their clarity and leadership #strengthened, not weakened, their position. ✅️ #Maersk (2017 NotPetya attack): 80% of their global IT infrastructure was wiped out. But Maersk responded with #honesty, #speed, and #collaboration,restoring operations in record time. Their transparency turned crisis into #credibility. 🌩"You can’t #control the #storm, but you can control how you #sail through it." And in cybersecurity, how you respond speaks louder than what happened. 📚 So what should you #prepare in advance to #respond effectively to a crisis? ✨️ A pre-approved #crisis_communication plan with draft messages for different scenarios ✨️ #Darkweb_monitoring to detect compromised data and offer affected users early support ✨️ A list #contracts with of external #partners: legal advisors, PR firms, forensics experts, regulatory contacts ✨️ Incident #playbooks tailored to different attack types (e.g., ransomware, phishing, insider threat) ✨️ A #communication_chain with clear #roles for executives, legal, tech, and customer support ✨️Pre-established #customer_support workflows for high-volume, high-stress inquiries ✨️Regular #tabletop exercises to rehearse real-time crisis scenarios with leadership ✨️And most importantly: a #culture that values transparency, accountability, and speed 🚨"It’s not a matter of #if , but #when".. And when it happens, your preparedness is your #power.✊️ Have you seen an incident response done exceptionally well, or painfully wrong? What would you add to the preparation checklist? #Cybersecurity #CrisisResponse #Leadership #IncidentManagement #DigitalTrust #Reputation #BoardroomTalk #CxO #Governance #CyberAwareness #TechLeadership #CyberResilience
-
The first 24 hours of a crisis determine whether you control the narrative or the narrative controls you. Organizations don’t lose control when the crisis breaks. They lose control in the silence that follows. The crisis isn’t the problem. The delay is. What that gap often looks like: Hour 1 No clear spokesperson. Legal, communications, and leadership are operating in separate lanes. Hours 2–4 Stakeholders haven’t been mapped. Employees learn about the situation from social media before hearing from leadership. Hours 4–6 The holding statement is still being drafted while the narrative is already forming without you. Hours 18–24 The original incident fades. The organization’s response—or lack of one—becomes the story. None of this is inevitable. The organizations that handle crises well don’t improvise under pressure. They prepare in advance. They map stakeholders. They align leadership, legal, and communications. They build holding statements and crisis Q&As before they’re needed. Because in a crisis, every hour compounds impact. The best time to build a 24-hour response plan was before you needed it. The second-best time is now. #CrisisCommunications #CrisisManagement #CrisisPR #ReputationManagement
-
50 Strategic Moves to Make Your Organization Crisis-Ready Most cybersecurity strategies fail one simple test: They look good on paper… But collapse in real-world decision-making. Cyber resilience isn’t built in tools. It’s built in how your organization responds under pressure. I’ve compiled 50 strategic moves behind one of the most underused leadership tools: 👉 Cyber Tabletop Exercises This isn’t about simulations. It’s about exposing how your business actually behaves during a crisis. What most organizations miss: They focus on: • Prevention • Detection • Technical controls But ignore the real risk: ❌ Decision delays ❌ Communication breakdowns ❌ Ownership confusion 1–12: Foundations → Understand response lifecycle → Define roles across IT, Legal, HR, Leadership → Shift mindset from prevention → readiness 13–25: Scenario Design → Ransomware + data exfiltration → BEC + AI phishing → Insider & supply chain threats 26–38: Advanced Simulation → Double extortion scenarios → Media & regulatory pressure → Executive decision-making under uncertainty 39–50: Maturity → Measure MTTR & response speed → Build continuous improvement loops → Turn exercises into a core business function A security plan tells you what should happen. A tabletop exercise shows you what actually will. The gap between those two? That’s where breaches become disasters. Be honest has your leadership team ever been tested in a realistic cyber crisis simulation? Follow Marcel Velica for more insights like this. And if this was valuable, reshare it with your network. If you want short daily thoughts, quick threat observations, and real-time discussions, follow me on X as well →https://x.com/MarcelVelica
-
If your emergency response plan has 2 pages on communication, that's not enough. I review these plans regularly. Engineering firms with 500+ employees. Healthcare facilities managing patient safety. Educational institutions protecting students. Oil & gas companies with complex operations. Most have precisely-mapped evacuation routes. Safety protocols for every scenario. Regulatory compliance checkboxes filled. Then I flip to the communication section. Often two pages. Maybe three. "Notify stakeholders." "Issue press release." "Monitor social media." That's like saying "fly the plane" without teaching someone how to take off. Here's what those 2 pages are missing: 𝗦𝘁𝗮𝗸𝗲𝗵𝗼𝗹𝗱𝗲𝗿 𝗺𝗮𝗽𝗽𝗶𝗻𝗴 𝗯𝘆 𝘀𝗰𝗲𝗻𝗮𝗿𝗶𝗼 Not just "employees and media." Which employees? Through what channels? Who speaks to families vs. regulators vs. community members? Figure this out - the conversations you have now make it so much easier when the heat is on. 𝗠𝗲𝘀𝘀𝗮𝗴𝗲 𝗳𝗿𝗮𝗺𝗲𝘄𝗼𝗿𝗸, 𝗻𝗼𝘁 𝘀𝗰𝗿𝗶𝗽𝘁𝘀 Scripts fail under pressure. But frameworks work. C̲o̲m̲p̲a̲s̲s̲i̲o̲n̲,̲ C̲o̲n̲v̲i̲c̲t̲i̲o̲n̲,̲ ̲O̲p̲t̲i̲m̲i̲s̲m̲ with facts sprinkled in. Under stress, there's no need to guess what works. A structure with flexibility brings clarity for you - and for your audiences. 𝗗𝗲𝗰𝗶𝘀𝗶𝗼𝗻 𝘁𝗿𝗲𝗲𝘀 𝘄𝗶𝘁𝗵 𝗿𝗲𝗮𝗹 𝘁𝗿𝗶𝗴𝗴𝗲𝗿𝘀 "Significant media attention" means nothing at 8pm when social media is lighting up. You need specifics: 5+ media calls in an hour, trending in your city's top 3 media stories, employee post shared to community Facebook groups. Take away the guesswork by sorting out what is meaningful to your organization ahead of time. 𝗖𝗵𝗮𝗻𝗻𝗲𝗹 𝘀𝘁𝗿𝗮𝘁𝗲𝗴𝗶𝗲𝘀 𝘁𝗵𝗮𝘁 𝗺𝗮𝘁𝗰𝗵 𝗿𝗲𝗮𝗹𝗶𝘁𝘆 Your people check for texts before email. Parents use Facebook groups. Media monitors X. Your channels need to match where people actually go for information during a crisis. If they're out of date or have gaps, the time to rectify is now. 𝗔𝘂𝘁𝗵𝗼𝗿𝗶𝘁𝘆 𝗺𝗮𝘁𝗿𝗶𝗰𝗲𝘀 𝘁𝗵𝗮𝘁 𝘀𝘁𝗶𝗰𝗸 Who approves what, when? Not titles - actual names. Not "Communications Director" but "James can approve statements up to Level 2. Above that, call Sarah." One education client's 2-page communications section hadn't been updated since two Communications Managers ago. Their media list included retired reporters and outlets that no longer existed. We built it out to 20 useful pages. Not bureaucracy but tools. Templates they actually use, even in day to day work. Frameworks that flex with reality. Later that school year, a bus incident triggered parent concerns. The expanded plan meant they responded in minutes, not hours. Parents got answers where they looked for them. The situation was quickly contained, media didn't even pick up on it. That's the difference between 2 generic pages and being ready. What's in your communication section - real tools or wishful thinking?
-
If a major tech incident hit your organization tomorrow, would your executive team know how to respond? I’ve been in rooms where systems were down, information was incomplete, and every decision carried real consequences. In those moments, preparedness isn’t a binder sitting on a shelf. It shows up in the quality of leadership decision-making under pressure. There are three stages of crisis response during a cyber incident: before, during, and after. Each one requires different executive discipline. Before an incident - Clarify who has decision authority. - Align on risk tolerance at the board and executive level. - Rehearse executive communication plans. - Agree in advance on what transparency looks like during a crisis. During an incident - Avoid reactive decisions driven by fear. - Prioritize action over consensus-building. - Delegate execution to the technical experts. - Avoid speculation. Make decisions based on verified facts. After an incident - Run a rigorous, blameless review. - Fix structural weaknesses, not just surface symptoms. - Reinforce accountability without triggering defensiveness. - Institutionalize what was learned. Technology will fail at some point. That’s the nature of complex systems. What matters is whether your leadership team has already been tested before that moment arrives. #BusinessLeaders #Cybersecurity #RiskManagement #LeadershipDecisionMaking #TechnologyRisk
-
We’ve been told that having a Business Continuity Plan (BCP) means we’re ready for a crisis. But here’s the truth: A plan is only as good as the last time it was tested under pressure. What most organizations get wrong about resilience: 👉 They mistake documentation for capability. 👉 They focus too much on prevention and not enough on operating through failure. ���� They assume a linear recovery. But in reality, disruptions are chaotic. What should we do instead? ➡️ Test resilience, not just compliance. Can you function for 48+ hours with zero IT access? If not, the plan needs work. ➡️ Pressure-test crisis leadership. Do decision-makers know who has final authority and how to escalate? ➡️ Embrace “Black Swan” thinking. Expect the unexpected. Your plan should be flexible, not rigid. Do you think most companies are truly prepared for a major disruption?