River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Crisis Communication Plan Template

A crisis plan where every scenario names the clock it is on, and the drafting window is whatever the deadline leaves once the lag is subtracted.

Free download  ·  No account needed

Scenario Register

One row per obligation, and the window is what is left

drafting window = deadline − hours gone before comms was told − hours the facts take

ScenarioClockDueLagFactsWindowApprovals
Misconduct allegation against an officerMedia convention, the outlet’s stated deadlineMedia4h0.52.01.5h5.5h
Death of a field engineer on a customer siteOSHA, 8h from the employer learning of itStatutory8h1.55.21.3h1.6h
Access unit unlocks on power loss, two injuriesCPSC, within 24h of obtaining the informationStatutory24h31.012.0−19.0h4.0h
Personal-data breach reaching EU data subjectsArticle 33, 72h from becoming awareStatutory72h19.058.0−5.0h3.5h
Same breach, largest customer’s data agreementContractual notice, 24h from becoming awareContract24h19.04.01.0h2.2h
Cyber incident determined material to investorsForm 8-K Item 1.05, four business daysStatutory96h0.024.072.0h6.0h

What the subtraction found

Nine obligations. Five cannot produce an approved statement inside the deadline, because the window is smaller than the approval path. Two are already gone: the clock ran out before comms was told the incident existed. The 30-minute holding-statement convention binds in none of them.

The row with a zero lag is the only one where comms is in the room when the clock starts. That is the whole difference, and it is a seating arrangement rather than a process.

Nately had a holding statement for every scenario and a rule that one would go out inside the hour. Then somebody ran the arithmetic across nine obligations. Subtract the hours gone before comms was told, subtract the hours the facts take, and five of the nine could not produce an approved statement before the deadline. Two were worse than late: the window was negative, so the clock had already run out by the time comms heard the incident existed.

The reason is the zero. A crisis plan starts counting when a reporter calls, and the deadlines that bind start earlier and elsewhere. A work-related death is reportable to OSHA within 8 hours of the employer learning of it. A product hazard goes to the CPSC immediately, defined as within 24 hours of obtaining the information. A personal-data breach runs 72 hours from becoming aware, and a material cyber incident runs four business days from the determination.

Nately's mean escalation lag was 11.6 hours, worst-case 31, an engineering team holding a firmware fault as a ticket against a 24-hour clock. Three of the five failing scenarios closed through delegated approval; the other two need someone upstream to recognize a clock has started, a tooling gap, not a comms one. It pairs with the press release and announcement kit for an incident already public. A planned change with its own release date belongs instead in the internal comms and announcement pack, where the clock nobody checks is arrival time, not escalation lag.

The sheets that treat the deadline as arithmetic

Nine obligations with the subtraction run on each, where the measured lag came from, and what six hours of tabletop changed.

Scenario Register

Nately: US-listed, connected building-access hardware plus a SaaS platform, EU customers, field engineers on customer sites. Nine obligations, sorted by deadline.

ScenarioClockDueLagFactsWindowApprovals
Misconduct allegation against an officerMedia4h0.52.01.5h5.5hshort 4.0h
Death of a field engineer on a customer siteStatutory8h1.55.21.3h1.6hshort 0.3h
Field engineer hospitalised as an in-patientStatutory24h6.04.513.5h1.6hfits
Access unit unlocks on power loss, two injuriesStatutory24h31.012.0−19.0h4.0hmissed
Same breach, largest customer’s data agreementContract24h19.04.01.0h2.2hshort 1.2h
Key component supplier enters administrationMedia48h8.06.034.0h1.0hfits
Personal-data breach reaching EU data subjectsStatutory72h19.058.0−5.0h3.5hmissed
Cyber incident determined material to investorsStatutory96h0.024.072.0h6.0hfits
Same breach, residents of a 30-day stateStatutory720h19.058.0643.0h3.5hfits
All nine obligations7 statutory or contractual11.6 mean5 short of approvals2 already gone

One row per obligation, not one per event. The same breach appears three times here, on a 72-hour supervisory-authority clock, a 24-hour contractual one and a 30-day state statute, from one awareness timestamp. Collapse them into a single row and the failure hides behind the 643 hours of slack.

Rank by deadline, then by feasibility, never by likelihood. The once-a-decade product hazard with a 24-hour clock and a 31-hour lag is more urgent work than the annual supplier scare with 34 hours to spare.

Window plus lag plus facts must equal the deadline, per row. If it does not, somebody has adjusted an estimate to make the row survivable, which is the one edit this sheet exists to prevent.

Escalation Lag

The hours between a clock starting and comms being told. Measured, from real incidents and from drills where the escalation was walked rather than described.

Incident or drillFound byEvidenceLagClockLeft
2024-03 access-unit firmware faultFault ticket opened with two injury reports attachedEngineeringReal incident31.0h24h−7.0h
2024-11 vendor credential compromiseVendor credential confirmed live in our tenantIT securityReal incident19.0h24h5.0h
2025-01 supplier distressAdministration notice appeared on the insolvency registerProcurementReal incident8.0h48h40.0h
2025-06 depot fall, in-patientSite manager told the engineer had been admittedSite managerReal incident6.0h24h18.0h
2025-05 tabletop, field fatalityDrill zero, the supervisor reaching our engineerSite supervisorTabletop1.5h8h6.5h
2025-09 tabletop, officer misconductDrill zero, the enquiry email arrivingPress mailboxTabletop0.5h4h3.5h
Disclosure committee, 8-K determinationThe materiality determination itselfThe committeeStructural0.0h96h96.0h
Distribution across nine scenariosComms discovered none of them11.6 mean, 8.0 medianmax lag 31.0h

Read the Found by column, not the average. Engineering, IT security, procurement and a site manager. In the worst case an engineering team held a firmware fault as a ticket for 31 hours with no idea a 24-hour reporting clock had started when they opened it.

Do not interpolate one scenario’s lag from another. The lag is a property of who discovers the thing. The site manager who knew there was a reporting duty produced 6.0 hours; the ticket queue that did not produced 31.0.

An empty cell is a finding and it argues for a tabletop. A flattering estimate is worse, because it survives review and the register gets built on top of it.

Drill Log

Three tabletops, two hours each, each started at the clock’s real zero and run out of hours. A drill that changed no number on any sheet did not count.

DrillWhat it foundNumber it changedRow
2025-02EU data breachThe plan started the 72-hour clock at the authority’s acknowledgement, not at our own awarenessClock zero corrected on three rows. Article 33 window moved to −5.0hStill broken
2025-05Field fatalityApprovals ran 1.6h against a 1.3h window, because counsel was the only approverDelegated the first statement to the safety lead. Approvals 1.6h to 0.4hClosed
2025-09Officer misconductThe board chair was unreachable for 5.5h. Nobody had tried the out-of-hours numberNamed a standing deputy. Approvals 5.5h to 1.2hClosed
Six hours of tabletopThree findings, all of them arithmeticClosed 3 of the 5 infeasible rows2 need the lag fixed

Split the failures by cause, because the fixes are unrelated. A row short on approvals is closed by a delegation decision somebody makes in a meeting. A row with a negative window is not, and no approval change reaches it.

The two that stayed broken are not a comms problem. They need an engineering team and an IT team to know a statutory clock starts when they open a ticket, which is training and tooling and belongs to whoever owns those teams.

Every reach time in the contact tree dates from the 2025-09 drill. Before somebody actually dialled the numbers at 21:15, all six were estimates and the chair’s was wrong by five hours.

What's in the pack

01

Clock Method

Fixes what a deadline means, where each clock starts, and what counts as evidence for the lag, before a single scenario gets added.

02

Scenario Register

One row per obligation with the subtraction run on it: deadline, lag, hours the facts take, the window left, and the approval path it has to fit inside.

03

Notification Requirements

Every deadline the company is on, in the source's own words, with the event that starts it, who it goes to, and a citation you can point at.

04

Escalation Lag

The measured hours between a clock starting and comms being told, from real incidents and walked drills, with who found each one.

05

Holding Statements

Three or four sentences per scenario, drafted tightest deadline first, each carrying the approval it needs and the filing it sits alongside.

06

Escalation Procedure

The chain from the person who actually discovers the thing, including the upstream half that runs before comms is involved at all.

07

Spokesperson Guidance

Who speaks at what severity, the short list of lines pre-cleared for use verbatim, and the things nobody says whatever the pressure.

08

Contact Tree

Roles, deputies, out-of-hours routes, and measured minutes to reach each person, taken from a drill rather than from the org chart.

09

Drill Log

What each tabletop found and which number it changed on which sheet. A drill that moved no number is recorded as not having counted.

10

Post-Incident Review

The observed timeline against the register's own arithmetic, and whether the miss came from the approvals or from the lag upstream of them.

How to use it

  1. 1

    Install it, or take the files

    Hand River your existing crisis plan and risk register, or download the Word documents and CSV sheets and work through them yourself.

  2. 2

    Write down the clock zeros

    Per obligation, the event that starts it in the source's own words. This is the step that reveals whether your current plan is anchored on the media clock.

  3. 3

    Find the lag from a real incident

    Take the last incident of any size, including the ones handled quietly, and get two timestamps: when the clock started and when comms was told.

  4. 4

    Run the subtraction, then drill the worst row

    Two hours on the scenario whose window is tightest or missing. Start at the real zero, out of hours, and call the approver on the number in the plan.

Frequently asked questions

Is this template free?

Yes, and there is nothing behind a form. Take the zip and you have the whole pack, not a teaser version of it. The other route is Edit with AI: send your existing plan and River checks it against the clocks instead of rewriting it. More packs sit in the template library.

What am I actually downloading?

Five Word documents and five CSV sheets in one zip. The sheets are comma-separated text, so Excel, Numbers and Google Sheets open them directly, and the register's arithmetic is a visible column rather than something computed elsewhere and pasted in.

How is this different from a normal crisis plan template?

The usual one gives you severity tiers, a notification matrix and pre-drafted statements, then tells you to get something out inside 30 to 60 minutes. Here every scenario names a statutory or contractual clock, the event that starts it, and the hours already spent before comms was told.

Is the 30-minute holding statement rule wrong then?

It is good advice about a media dynamic and a poor foundation for a plan. On the worked register it was the binding constraint in none of the nine obligations. Keep it as a target for the media clock and stop treating it as the deadline the plan is designed around.

Does this replace legal advice?

No, and the Notification Requirements sheet is built to make counsel's time cheap rather than to substitute for it. Each row carries a specific question and a citation, so the review is a confirmation of seven deadlines rather than an open reading of the whole plan.

We have no incident history. Can we still fill in the lag?

A two-hour tabletop produces the number, provided the escalation is walked rather than described. Start at the clock's real zero with the person who would actually find it, do not warn comms, and dial the approver on the number in the plan. Estimates do not count.

What does Edit with AI actually do?

It signs you up free, puts these ten files in a private workspace, and opens by asking three things: what you make, where your customers sit, and who you employ. Those answers generate the obligation set, and then it asks for one real incident with two timestamps.

Find out which of your deadlines you cannot actually meet

Download the ten files and run the subtraction on your tightest three obligations, or install the pack and let River check the plan you already have.

Edit with AI