A crisis is an event with the potential to damage the continuity of your business — where operations could stop and you cop severe financial and reputational harm.
Some events are a crisis the moment they happen: a workplace fatality or serious injury, a product involved in public injury, a product defect causing serious harm. Others start as an emergency or a quality issue and escalate into one — a natural disaster, an IT outage past a business day, adverse media at any level.
That distinction matters, because the response is completely different. An incident is handled by a supervisor with a form. A crisis needs a team, a command point, a comms strategy and a log.
Most businesses have a crisis management plan. It's a Word document, it's forty pages, and it's on a shared drive nobody can reach when the IT outage is the crisis.
The problem isn't the content. It's that a document assumes a calm person with time to read it. At 2am, with a fatality on site and a journalist calling, nobody is reading page 23. They're doing whatever they can remember, and half the team is doing something different.
The plan has to run the team, not sit there waiting to be read.
Trigger criteria, so nobody has to argue about whether this counts. Named roles with proxies, because the primary will be on a plane. A defined command centre and comms setup. Role-based checklists so each person sees only their tasks for the current phase, not the whole plan. A meeting rhythm — initial, sub-teams as needed, situation updates every two hours, full team every four. Pre-written proformas and holding statements. A live log that timestamps every decision.
That last one is underrated. When the regulator, the insurer or the lawyer comes asking six months later, the log is the only thing that shows you responded properly. Memory won't cut it.
Crisis Command Centre is our platform for this. It guides your team through the whole process — the six phases above — with role-based checklists, so each person is shown their tasks for the phase you're actually in.
It carries fillable proformas, reference documents and key contacts so nobody is hunting for a template mid-event. It logs the crisis live and produces a post-crisis report with a full timeline and completion rates. It handles location-based crisis teams, unlimited sites within each location, and ships with thirteen pre-built scenarios — data breach, fire and evacuation, PR crisis, IT outage, natural disaster, workplace incident — or you build your own.
It's built to align with ISO 9001 for the documented procedure and improvement side, and ISO 45001 for welfare checks, incident documentation and emergency preparedness.
The part I'd point you at first is the simulation. You can run a fifteen-minute AI-guided crisis exercise with up to four of your people right now, no account needed. Pick a scenario, pick your roles, and ALDA walks the team through the response. It's the cheapest way there is to find out your plan doesn't work.
Run it once a year and after any change to the team. You'll find the same things everyone finds: a key person with no proxy, nobody authorised to speak to media, no holding statement, and a contact list two years out of date.
Finding that in a simulation costs you an afternoon. Finding it during a fatality costs a great deal more.
- Anything that can stop the business. A fatality, a product causing public harm, adverse media, a natural disaster, or an IT loss past one business day.
- Triggers, roles, command point, checklists. Plus a meeting rhythm, pre-written proformas, a live decision log, and a close-out covering recovery and employee support.
- Yearly, and after team changes. A plan nobody has run is a document, not a capability. A short scenario finds the gaps while they're still cheap.
- Both 9001 and 45001. Documented procedure, training and improvement on one side; emergency preparedness and worker welfare on the other.