Crisis Communication Plan Template
A crisis plan where every scenario names the clock it is on, and the drafting window is whatever the deadline leaves once the lag is subtracted.
Free download · No account needed
Scenario Register
One row per obligation, and the window is what is left
| Scenario | Clock | Due | Lag | Facts | Window | Approvals |
|---|---|---|---|---|---|---|
| Misconduct allegation against an officerMedia convention, the outlet’s stated deadline | Media | 4h | 0.5 | 2.0 | 1.5h | 5.5h |
| Death of a field engineer on a customer siteOSHA, 8h from the employer learning of it | Statutory | 8h | 1.5 | 5.2 | 1.3h | 1.6h |
| Access unit unlocks on power loss, two injuriesCPSC, within 24h of obtaining the information | Statutory | 24h | 31.0 | 12.0 | −19.0h | 4.0h |
| Personal-data breach reaching EU data subjectsArticle 33, 72h from becoming aware | Statutory | 72h | 19.0 | 58.0 | −5.0h | 3.5h |
| Same breach, largest customer’s data agreementContractual notice, 24h from becoming aware | Contract | 24h | 19.0 | 4.0 | 1.0h | 2.2h |
| Cyber incident determined material to investorsForm 8-K Item 1.05, four business days | Statutory | 96h | 0.0 | 24.0 | 72.0h | 6.0h |
What the subtraction found
Nine obligations. Five cannot produce an approved statement inside the deadline, because the window is smaller than the approval path. Two are already gone: the clock ran out before comms was told the incident existed. The 30-minute holding-statement convention binds in none of them.
The row with a zero lag is the only one where comms is in the room when the clock starts. That is the whole difference, and it is a seating arrangement rather than a process.
Nately had a holding statement for every scenario and a rule that one would go out inside the hour. Then somebody ran the arithmetic across nine obligations. Subtract the hours gone before comms was told, subtract the hours the facts take, and five of the nine could not produce an approved statement before the deadline. Two were worse than late: the window was negative, so the clock had already run out by the time comms heard the incident existed.
The reason is the zero. A crisis plan starts counting when a reporter calls, and the deadlines that bind start earlier and elsewhere. A work-related death is reportable to OSHA within 8 hours of the employer learning of it. A product hazard goes to the CPSC immediately, defined as within 24 hours of obtaining the information. A personal-data breach runs 72 hours from becoming aware, and a material cyber incident runs four business days from the determination.
Nately's mean escalation lag was 11.6 hours, worst-case 31, an engineering team holding a firmware fault as a ticket against a 24-hour clock. Three of the five failing scenarios closed through delegated approval; the other two need someone upstream to recognize a clock has started, a tooling gap, not a comms one. It pairs with the press release and announcement kit for an incident already public. A planned change with its own release date belongs instead in the internal comms and announcement pack, where the clock nobody checks is arrival time, not escalation lag.
What's in the pack
Clock Method
Fixes what a deadline means, where each clock starts, and what counts as evidence for the lag, before a single scenario gets added.
Scenario Register
One row per obligation with the subtraction run on it: deadline, lag, hours the facts take, the window left, and the approval path it has to fit inside.
Notification Requirements
Every deadline the company is on, in the source's own words, with the event that starts it, who it goes to, and a citation you can point at.
Escalation Lag
The measured hours between a clock starting and comms being told, from real incidents and walked drills, with who found each one.
Holding Statements
Three or four sentences per scenario, drafted tightest deadline first, each carrying the approval it needs and the filing it sits alongside.
Escalation Procedure
The chain from the person who actually discovers the thing, including the upstream half that runs before comms is involved at all.
Spokesperson Guidance
Who speaks at what severity, the short list of lines pre-cleared for use verbatim, and the things nobody says whatever the pressure.
Contact Tree
Roles, deputies, out-of-hours routes, and measured minutes to reach each person, taken from a drill rather than from the org chart.
Drill Log
What each tabletop found and which number it changed on which sheet. A drill that moved no number is recorded as not having counted.
Post-Incident Review
The observed timeline against the register's own arithmetic, and whether the miss came from the approvals or from the lag upstream of them.
How to use it
- 1
Install it, or take the files
Hand River your existing crisis plan and risk register, or download the Word documents and CSV sheets and work through them yourself.
- 2
Write down the clock zeros
Per obligation, the event that starts it in the source's own words. This is the step that reveals whether your current plan is anchored on the media clock.
- 3
Find the lag from a real incident
Take the last incident of any size, including the ones handled quietly, and get two timestamps: when the clock started and when comms was told.
- 4
Run the subtraction, then drill the worst row
Two hours on the scenario whose window is tightest or missing. Start at the real zero, out of hours, and call the approver on the number in the plan.
Frequently asked questions
Is this template free?
Yes, and there is nothing behind a form. Take the zip and you have the whole pack, not a teaser version of it. The other route is Edit with AI: send your existing plan and River checks it against the clocks instead of rewriting it. More packs sit in the template library.
What am I actually downloading?
Five Word documents and five CSV sheets in one zip. The sheets are comma-separated text, so Excel, Numbers and Google Sheets open them directly, and the register's arithmetic is a visible column rather than something computed elsewhere and pasted in.
How is this different from a normal crisis plan template?
The usual one gives you severity tiers, a notification matrix and pre-drafted statements, then tells you to get something out inside 30 to 60 minutes. Here every scenario names a statutory or contractual clock, the event that starts it, and the hours already spent before comms was told.
Is the 30-minute holding statement rule wrong then?
It is good advice about a media dynamic and a poor foundation for a plan. On the worked register it was the binding constraint in none of the nine obligations. Keep it as a target for the media clock and stop treating it as the deadline the plan is designed around.
Does this replace legal advice?
No, and the Notification Requirements sheet is built to make counsel's time cheap rather than to substitute for it. Each row carries a specific question and a citation, so the review is a confirmation of seven deadlines rather than an open reading of the whole plan.
We have no incident history. Can we still fill in the lag?
A two-hour tabletop produces the number, provided the escalation is walked rather than described. Start at the clock's real zero with the person who would actually find it, do not warn comms, and dial the approver on the number in the plan. Estimates do not count.
What does Edit with AI actually do?
It signs you up free, puts these ten files in a private workspace, and opens by asking three things: what you make, where your customers sit, and who you employ. Those answers generate the obligation set, and then it asks for one real incident with two timestamps.
Find out which of your deadlines you cannot actually meet
Download the ten files and run the subtraction on your tightest three obligations, or install the pack and let River check the plan you already have.
Edit with AI