Why Crisis Management Planning Needs to Change. The threat of disruption and damage to business from criminals, hostile nation states and their proxies has grown sharply and continues to grow. Leaders of all three of the UK intelligence agencies have recently and publicly warned that business leaders cannot rely on risk assessments and contingency planning formed during the (relatively) benign pre-pandemic environment. The head of MI5 has warned that, alongside growing terrorism threats, we now have to “contend with a second menace of equal or even greater scale, in fast-rising state threats”, while the head of MI6 has warned that we have moved to “a space between peace and war”.

The National Cyber Security Centre (NCSC) has reported that 67% of large firms suffered a significant cyber-attack in 2025. While the experiences of M&S and JLR last year have clearly illustrated the potential for criminals to seriously disrupt even well managed businesses. The advent of rapidly developing AI is delivering an extraordinary step change in cyber-related threats but is also adding to and creating new forms of insider, disinformation and even physical threats. The ability of frontier large language models to identify and exploit vulnerabilities in rapidly shortening timeframes now enables bad actors to compromise systems in minutes, perhaps even seconds. This is much faster than internal and technology supply chain security teams can patch and remediate systems.

In short, the likelihood of a serious disruptive attack is now significant and the probability of severe, orchestrated and multidimensional cyber, insider, disinformation and physical attack is no longer remote (especially for any business that might be seen as providing a critical national infrastructure service or supporting UK foreign and military policy).

Business crisis management plans and arrangements need to be reviewed and reshaped to deal with the world as it now is. Even businesses that have had well-tried and tested crisis management, cyber incident, business continuity and disaster recovery arrangements, are facing a major challenge and should revisit and upgrade their plans and preparations, ensuring they are prepared to deal with a broader, more complex and threatening, set of potential crises.

Preparing for Complex and Fast-Moving Crisis Scenarios

Crisis management planning must be predicated upon a broadly comprehensive but manageable range of severe but now plausible crisis scenarios.

Unfortunately, much established crisis management planning is designed for single dimension scenarios (e.g., the isolated loss of a data centre or other facilities) rather than the more complex crise scenarios that are all too possible in today’s highly integrated organisations. This is troubling because simple crisis planning will fail to capture the cascading impact of the loss of a single facility or service combined with the impact of, for example, the simultaneous loss of IT systems and deliberate disinformation attacks. It is also troubling because of the growth in capability and aggression of serious threat actor groups that are looking to maximise disruption.

Many crisis management plans and arrangements make implicit assumptions about the pace of the crisis and the availability of systems and information during it. In practice, many crises that organisations need to plan for – such as a potentially existential disruption from a major cyber-attack – are characterised by rapid development and considerable uncertainty, especially in the early stages of the crisis, at the exact moment that the initial course of the response is set, sometimes limiting further options. This often results in top management and boards being on the back foot and being forced to react under extreme pressure.

Understanding what may now be entailed in a severe but plausible scenario requires a robust assessment of the full set of threats and risks and how they interact. Security threats and risks should not be considered in isolation, but understood in the context of  business, market, geopolitical, technology-related, activist, regulatory and environmental risks.

Obviously, there is an almost infinite number of possible crises that businesses could prepare for and so insightful threat intelligence and careful thought is required to shape a limited and manageable portfolio of crisis scenarios that will provide the basis for challenge and testing of crisis management plans.

Turning Crisis Management Plans into Operational Readiness

Changes to crisis management arrangements need to include the creation of minimum viable business “lifeboats” to sustain the most important services through a serious disruptive attack. For many businesses, this change in the threat environment may also now be enough to finally force the retirement of old and out-dated infrastructure and systems that cannot be kept secure and resilient against AI-enabled threats.

Plans must be clear about roles and responsibilities, crisis decision making and delegations of authority, as well as emergency processes and procedures, reserve/contingency systems and arrangements for migrating to and from them. Plans developed by middle management may not reflect the roles and interventions needed by top management in a real crisis. The nature of the scenario matters too – the decision-making groups needed to deal with a cyber incident may differ significantly from those involved in a corporate financial crisis, for example.

All crisis management teams, including the most senior executive management team, need to have been familiarised, trained and exercised in the implementation of the crisis management plans. Building instinctive “muscle memory” responsiveness in front line crisis management teams is key to responding rapidly and effectively and limiting long-term damage.

Most importantly, crisis management planning needs to be regularly updated to take account of material new and evolving threat scenarios.

Integrating Crisis Management Across the Organisation

Recent high profile events (notably the 2025 closure of Heathrow Airport) have demonstrated all too clearly that crisis management arrangements need to be comprehensive and operation-wide. It is not sufficient to have detailed crisis management planning undertaken by business continuity, technical, security and communications teams, if front-line business leaders – who would in practice be managing a crisis – are not involved in their planning or exercising.

Failure of plans is too often attributable to implementation – often showing up in details that would have come to light with more inclusive and integrated planning.  Planning must be done in a way that joins up diverse teams, processes and information sets that will need to work together when a crisis unfolds, even if they work separately during “business as usual”.

It should go without saying that crisis management planning also needs to be coordinated and integrated with the critical third parties providing services to the organisation.

Testing and Exercising Crisis Management Plans

Testing and exercising is the best way of assessing the robustness of crisis management plans, but only if it is effective.

Exercises have to be realistic and not a matter of simply going through the motions. Too many tabletop exercises make false and unrealistic assumptions about the response and availability of colleagues, processes and systems.

Exercises also typically make unrealistic assumptions about the pace of events, situational awareness and the impact of stress. Although it is unrealistic to expect senior executives to spend days exercising, they do need to commit sufficient time (at a minimum half a day) to allow carefully constructed immersive exercising to be undertaken and to build crisis management skills at all levels.

Exercising also needs to include critical third parties (CTPs). In practice, real crises typically require multiple organisations to collaborate effectively to respond to a major incident. Without alignment of crisis management arrangements, it is likely that initial (collective) responses will be uncoordinated, sub-optimal and often complicated by unnecessarily heightened legal liability concerns.

The Role of Boards

The fundamental role of the Board of Directors in crisis management is oversight and governance, rather than the management of the operational response. That said, boards should be kept informed of progress and, when and as appropriate, consulted over any material change to policies, strategy and business arrangements that has not been envisaged in pre-crisis planning.

The most important role for the Board in crisis management is to ensure that executive management have put in place appropriate and proportionate arrangements to ensure that the business is well positioned to respond to all plausible but severe crises, regardless of their initiating cause. The Board should actively and regularly review and challenge management’s crisis management and resilience arrangements.

During a crisis, executive management needs to be focused on the management of the business’ response. This is particularly true in the early stages of the initial response – especially when dealing with a fast-moving crisis (e.g., cyber-incident) where there is an ugly combination of the need for urgent action and considerable uncertainty about what has actually happened.

Boards have an important role to play after a crisis and final recovery. In particular, they should lead the review of the crisis and evaluate how well crisis management and resilience arrangements worked.

They should also hold executives accountable for their performance and oversee efforts to strengthen policies, organisation, operational and other arrangements where necessary. As the public face of the organisation, Board members may also have an important role to play, both during and after the crisis, in reassuring key external and internal stakeholders about the robustness of reviews and the future security and resilience of the organisation.