Crisis communication and brand crisis management
What burns a brand in a crisis is rarely the incident itself but the silence after it. Thresholds, the first 60 minutes, statements and closure.
It is 6:40 p.m. on a Friday. Support sends one line: "Thirty-odd tickets in two hours, all describing the same thing." A post is spreading on social media and customers are confirming each other's accounts in the replies. The office is empty, nobody is sure who may speak, and marketing is asking what legal would think. Two hours of silence pass, and by the end of them the story is no longer a product defect — it is a company that heard and said nothing.
What burns a brand is rarely the incident; it is the gap that follows. A team that has not decided in advance what it will say writes the most expensive sentence available: a denial, a paragraph of legalese, or nothing. This guide covers the thresholds that separate a crisis from a complaint, what preparation should produce, how the first sixty minutes run, how to write the statement, which channels to use, and how to close the file.
Crisis or ordinary complaint? Where the line sits
Not every negative comment is a crisis. A crisis grows faster than your support flow can absorb and puts brand trust up for public debate. Three tests make the difference usable. Speed of spread: the same subject arriving repeatedly across channels within an hour is no longer an isolated case. Subject weight: a late delivery and an incorrect charge are not equivalent, and anything touching money, health, safety, or personal data jumps a level immediately. Third-party interest: once non-customers, industry communities, or reporters carry the story, it is a public narrative, not a customer relationship.
Write your escalation thresholds before you need them
Debating whether something qualifies while it happens burns the hours that matter. Write a three-tier table instead: tier one stays with support, tier two notifies the department head and communications owner, tier three convenes the decision team. Give each a concrete trigger — ticket volume on one subject at a multiple of its normal band, the story appearing on a news site, any allegation involving payments or data security. Routine reviews and ratings are a separate discipline, covered in our piece on online reputation management on complaint sites. A crisis starts where that routine stops holding.
Types of crisis, and the risk specific to each
Writing one scenario and declaring yourself ready is the most common mistake. Crises behave differently depending on where they originate, and each demands its own opening move.
- Product or service failure: A bad batch or a miscalculated invoice originates with you, so speed and clarity about scope decide the outcome; a number you guess at is hard to correct later.
- Data breach or security incident: Verification, notification duties, and communication run in parallel, which puts legal counsel and information security at the center of the table.
- Employee conduct: When one person's behavior reflects on the company, the question the audience is really asking is whether the organization owns it.
- Supply chain problem: The fault may sit upstream, but the customer signed with you; "our supplier caused this" is information, not a defense.
- Content read the wrong way: A campaign visual gets read independently of its intent, and the urge to win the argument is the thing to resist.
- Third-party allegation: When a claim of uncertain accuracy spreads fast, a well-built "we are investigating" beats silence while you verify.
Preparation: knowing today who says what
Preparation should produce a few working pages, not a slide deck. A scenario list: eight to ten realistic headlines specific to your business, since an ecommerce team's list will not match a software company's. A spokesperson assignment: who speaks, who speaks if that person is unreachable, who never speaks alone. A decision team and call tree with after-hours numbers and response times. And pre-written statement skeletons with blanks to fill, already in your voice.
That voice should not be invented under pressure; the framework in our brand voice and tone guide exists so you stay recognizable when it arrives. Test the document once a year with a drill: pick a scenario, pull the team together without warning, ask for a draft statement in forty-five minutes. The weak link shows up on the first run.
Early warning: hearing it before your customers do
A crisis rarely detonates. There is usually a swelling period of a few hours, and the team that sees it gets in front of the story. Keep three signals open. Brand mention monitoring collects posts naming you, and a sudden jump in volume is an alarm on its own. Ticket anomalies mean volume on one subject stepping outside its normal band, which needs a threshold rule, not someone eyeballing a queue. Signals from sales and field teams are the most underrated source, because customers tell their own rep the bad news first.
Reading tone at machine speed pays off here; we covered the method in sentiment analysis for customer messages. Ticket volume broken down by subject does the same job, and without the tagging discipline in help desk and ticketing an anomaly is nearly impossible to spot. In Rocketly, tagging shared-inbox conversations and firing a workflow when a tag crosses a threshold automates the alert.
The first sixty minutes: verify, scope, brief internally
The goal of the first hour is not to solve the crisis but to take control of it. Verification: is the claim true, which part of it, and what evidence do you hold. Scoping: how many customers, what date range, which product — understating scope makes every fact that surfaces on day two look like a lie. Internal briefing: nothing goes out until support, sales, and field teams know what to say, because a rep answering "nobody told me anything" does more damage than the statement. First contact: even with incomplete information, do not stay silent.
Using "we are investigating" properly
That sentence is a commitment, not a delay tactic. Written well it carries what you are looking into, that you know who is affected, and when you will come back. "We received the reports, confirmed the error at the payment step, and are identifying affected accounts; we will post an update at 8 p.m." is a different object from "the matter is under review." Return at the promised time even with nothing new — keeping a small commitment builds more trust than the update itself.
Principles for writing the statement
A good crisis statement is short, concrete, and written in a human voice. Ownership: say plainly what happened without hiding responsibility behind the passive voice; the distance between "an issue occurred" and "our own update delayed your orders by two days" is the entire distance of trust. Concrete action: what you have done and what you will do. A time commitment: when the next update arrives. Centering the affected person: the subject is the harm someone experienced, not how the company feels about it.
In a crisis, the most expensive sentence is usually the one that looks safest to legal: it admits nothing, promises nothing, and for exactly that reason convinces nobody.
The tension between legal and communications is real: counsel worries about expanding liability, communications about collapsing trust. Build the sentence together, because describing facts without offering a legal characterization is usually possible. "We are sorry you went through this, and here is what we are doing to make it right" is defensible and human without conceding fault. Settle that boundary while drafting templates, not at midnight.
Channel choice and internal communication
Where a statement lands matters as much as what it says. Your own site is the source of record: one timestamped page you keep updating, with every channel pointing to it, keeps the narrative's center with you. Social media is a distribution channel, not a debating chamber; work through one pinned update instead of arguing reply by reply. Email reaches affected customers directly and needs segmentation, since a crisis email to people who were never affected manufactures panic. Direct contact by phone, reserved for the worst-affected accounts, outweighs the other three combined.
Brief internally a few minutes before you go public: what happened, what will be said, what will not, and where questions get routed. Running inbound questions through one inbox is critical here, because fragmented channels give one question five answers and the inconsistency creates a second wave. If a press statement is required, our piece on press releases and PR for small businesses lays out the structure.
Crises that trigger notification duties
A personal data breach, a payment security incident, or a security event in a regulated sector can create formal notification obligations whatever your communication preferences. The first call there belongs to legal counsel, not marketing. Scope, deadline, and who must be told vary by country, sector, and incident, which is why we name no deadlines or clauses here. The path is clear enough: record the technical verification, keep an hour-by-hour timeline, base the notification decision on local regulation and your legal counsel, and align customer communication with it. Lowering the odds of facing that scenario is preparation too; the fundamentals in cybersecurity for small business are the cheapest way to never sit at that table.
What to switch off during a crisis
The marketing machine humming in the background produces the worst timing available. Stop scheduled social posts. Pause ads, because cheerful creative appearing against searches about the incident enlarges the argument. Suspend automated email flows, birthday messages, and sales nudges. Write down what you paused; flows waiting to be re-enabled can stay dark for months. In Rocketly, a "crisis mode" group of workflows makes this a single click.
After the crisis: remedy, fix, closing report
A crisis ends when the affected customer's problem is genuinely resolved, not when your last statement goes out. Remedy: proportionate to the harm and specific to the person, not an automated coupon; turning a bad experience into a relationship is covered in service recovery. Process fix: a concrete change that prevents a repeat, because an action item without an owner and a date is not an action item. Closing report: a short document answering what happened, why, what you did, and what you changed.
Publishing that report feels counterintuitive, but it does not reopen the story — it lets you be the one who closes it. Clearing the individual complaints that piled up belongs here too, and the flow in handling customer complaints is what you need.
Measurement and the mistakes teams repeat
Instead of declaring the crisis over, measure it. Track four indicators: how long mention volume and tone take to return to their pre-crisis band, customer loss inside the crisis window, how long support load takes to normalize, and recovery time itself. Watch them daily during the incident — that is the only way to see which statement turned the tone. One dashboard in your CRM moves the next crisis conversation off instinct and onto evidence.
The mistakes repeat with remarkable consistency: waiting because it might blow over; writing the first statement in legal language; understating scope; blaming a supplier or the customer; arguing in the replies; speaking before the team is briefed; and changing no process afterward. They share one shape: relief now, paid for with trust later. The habit of intervening before problems grow ends most crises before they are born, and our piece on proactive customer support explains how to build it.
Crisis preparation is the most profitable investment you will make for a day you hope never comes. Seeing signals in one place, tagging conversations, alerting the team when a threshold breaks and turning the incident into a report all need common ground. Try Rocketly by creating a free account and build your early warning flow today; the difference shows in the first hour of the first real incident.