← University
Crisis Communication During a Disruption
0 of 4

A regional accounting and advisory firm with 3 offices across southern Alberta discovered on a Thursday morning that its central file management system had become inaccessible. The firm employed 47 staff members across its locations and served approximately 1,200 active clients, ranging from individual tax filers to mid-sized manufacturing operations and several non-profit organizations. The system outage initially appeared to be a routine technical failure, but within 4 hours the firm's IT contractor confirmed that the disruption stemmed from a ransomware attack that had encrypted client files, internal communications archives, and the firm's scheduling and billing platforms.

The timing could not have been worse. The disruption occurred 6 weeks before the personal tax filing deadline, during the busiest period of the firm's annual cycle. Client documents submitted electronically over the preceding 3 months remained locked within the compromised system. Staff members at all 3 locations found themselves unable to access work files, communicate through internal channels, or confirm upcoming appointments with clients. The firm's managing partner and operations director faced immediate decisions about what to tell employees who were arriving at their desks to find their workstations frozen, what to communicate to clients who had entrusted sensitive financial documents to the firm, and whether regulatory notification was required given the nature of the data potentially affected.

The firm maintained a general business continuity plan that addressed premises emergencies and key personnel loss, but the plan had not been updated in 2 years and contained only a brief paragraph on communications during a disruption. No media relations protocol existed. The firm had a modest social media presence — a business page with approximately 800 followers and an occasional professional networking account — but no designated spokesperson and no experience managing public attention during an adverse event. Within 24 hours of the initial discovery, a local business reporter contacted the firm's reception line seeking comment on rumours of a cyberattack affecting a professional services provider in the region.

The firm's leadership now confronted overlapping communication challenges: keeping staff informed and functional across multiple locations, notifying clients whose data might be affected, determining what obligations existed toward professional regulators and privacy authorities, managing supplier relationships while payment systems remained offline, and responding to media inquiries without making statements that could create legal exposure or inflame public concern. The decisions made over the following 72 hours would shape whether the disruption remained a difficult but survivable incident or escalated into a reputational and operational crisis that threatened the firm's long-term viability.

Crisis Communication Principles: What Works Under Pressure and What Fails

When a crisis strikes an organization, the first instinct is often to focus on operational recovery: restoring systems, securing premises, addressing immediate safety concerns, and getting back to business as usual. These priorities are entirely appropriate, but they represent only part of what determines whether an organization survives a disruption with its reputation, stakeholder relationships, and operational capacity intact. How an organization communicates during a crisis frequently matters as much as the technical response itself. Poor communication can transform a manageable incident into a catastrophic failure of public trust, while effective communication can actually strengthen stakeholder confidence even when the underlying situation is serious. Understanding what works under pressure and what fails is not merely a matter of public relations instinct. It requires deliberate preparation, an understanding of human psychology during uncertainty, and alignment with the standards and expectations that govern organizational conduct across Canadian jurisdictions.

Crisis communication as a discipline emerged from decades of research into organizational failures where the communication response either mitigated or amplified the damage caused by the original incident. The foundational principle is deceptively simple: stakeholders need accurate, timely, and appropriately detailed information to make decisions that protect their own interests and to maintain trust in the organization providing that information. This principle operates whether the stakeholders are employees needing to know whether to report to work, customers wondering if their data has been compromised, regulators assessing compliance obligations, or community members concerned about environmental or safety impacts. The challenge is that crisis conditions create precisely the circumstances under which clear communication becomes most difficult. Information is incomplete, the situation is evolving, multiple parties are demanding answers simultaneously, and the stakes of saying something incorrect feel paralyzingly high. Organizations that have not prepared for this reality often default to silence, evasion, or premature reassurance, each of which tends to make the situation worse rather than better.

The standards that inform crisis communication practice in Canada draw from several sources. The International Organization for Standardization published ISO 22301, which addresses business continuity management systems, and ISO 22316, which focuses on organizational resilience. As of the date of authorship, these standards provide frameworks that Canadian organizations across all sectors can adopt, and they explicitly recognize communication as a core element of both preparedness and response. The Canadian Standards Association has developed CSA Z1600, which provides requirements for emergency and continuity management programs and similarly emphasizes the communication function. While these standards are not universally mandatory, they represent accepted professional practice and can inform what constitutes reasonable conduct when an organization faces scrutiny after a crisis. Organizations operating in regulated sectors often face additional requirements. Financial institutions supervised by the Office of the Superintendent of Financial Institutions must maintain business continuity plans that address communication with customers and regulators. Healthcare organizations must comply with provincial and territorial requirements for incident reporting and communication with patients. Organizations handling personal information across Canada must consider their notification obligations under the Personal Information Protection and Electronic Documents Act at the federal level and comparable provincial legislation in Alberta, British Columbia, and Quebec. The common thread is that communication is not an afterthought to crisis response but an integral component that regulators, courts, and the public increasingly treat as a measure of organizational competence and good faith.

What actually works under pressure begins with preparation that occurs long before any crisis materializes. Organizations that communicate effectively during disruptions have typically invested in several things that their less-prepared counterparts neglect. They have identified their key stakeholder groups and understand what each group needs from the organization during different types of incidents. They have established communication channels that will remain operational even if primary systems fail, recognizing that a crisis affecting their email servers or office phone systems will simultaneously impair their ability to reach people through those channels. They have designated and trained spokespersons who understand both the substance of organizational operations and the principles of effective communication. They have developed template messages and holding statements that can be rapidly adapted to specific situations rather than requiring composition from scratch during the chaos of an active incident. Perhaps most importantly, they have rehearsed their crisis communication protocols through exercises and simulations, discovering gaps and awkward coordination problems before those problems manifest during an actual emergency.

The psychology of crisis communication deserves particular attention because it explains many of the failures organizations experience. Under conditions of uncertainty and stress, both communicators and audiences behave differently than they do in normal circumstances. Communicators often experience what researchers term the defensive mindset, where the overwhelming priority becomes protecting the organization from liability or criticism rather than genuinely addressing stakeholder needs. This mindset produces communication that stakeholders perceive as evasive, self-serving, or disconnected from reality. The language becomes legalistic and hedged, the timing becomes reactive rather than proactive, and the emphasis shifts to what the organization did not do wrong rather than what it is doing to address the situation. Audiences in crisis conditions, meanwhile, are primed for threat detection. They scrutinize communication for signs of deception, minimization, or shifting blame, and they interpret ambiguity negatively. They fill information vacuums with speculation that is often worse than the reality. They remember how they felt during the communication experience long after they forget the specific words used, which means that tone and apparent authenticity carry significant weight. Effective crisis communication accounts for these psychological realities rather than proceeding as if stakeholders will interpret messages charitably and patiently.

The principles that consistently produce better outcomes can be summarized as transparency, timeliness, empathy, and consistency, though each requires careful application rather than mechanical implementation. Transparency does not mean releasing every piece of information immediately or speculation in public about matters that remain uncertain. It means being honest about what is known, what is not known, and what the organization is doing to learn more. Organizations that say they are still gathering information about a particular aspect of the situation and will provide updates as they learn more generally fare better than organizations that either refuse to address questions or offer premature conclusions that later prove incorrect. Timeliness means communicating early enough that stakeholders receive information from the organization before they receive it from other sources, but not so early that the communication creates more confusion than clarity. The standard guidance is to acknowledge the situation quickly even if details are unavailable, provide substantive updates at predictable intervals, and correct misinformation promptly when it emerges. Empathy means demonstrating genuine concern for those affected by the situation, which requires understanding who is affected and how. Organizations that lead with expressions of concern for affected parties before pivoting to operational details or organizational interests generally receive more favorable responses than those that appear primarily concerned with their own position. Consistency means ensuring that all organizational communication conveys compatible messages, which becomes challenging when multiple people are speaking to different audiences through different channels simultaneously. Inconsistency suggests either dishonesty or disorganization, neither of which builds confidence.

What fails under pressure is often the opposite of these principles, though failures also emerge from more subtle missteps. Silence is one of the most common and most damaging failures. Organizations that decline to comment, that refer all inquiries to unavailable spokespersons, or that simply fail to issue any communication leave stakeholders to rely on other sources, which may be competitors, critics, or simply uninformed speculation. The information vacuum does not remain empty; it fills with whatever narrative is most compelling or most alarming, and the organization loses any ability to shape that narrative. Delayed communication is a close cousin of silence, where the organization eventually says appropriate things but only after the crisis has defined itself in stakeholder minds without organizational input. The technical term for this window is the golden hour, borrowed from emergency medicine, which refers to the critical early period during which the organization can either establish itself as a reliable information source or cede that role to others. Once lost, this positioning is extremely difficult to recover.

Minimization and denial represent another category of failure. When organizations downplay the severity of an incident that stakeholders correctly perceive as serious, they damage their credibility not only regarding the current situation but regarding future communications as well. Stakeholders who feel they were misled during one crisis will approach subsequent organizational communication with suspicion. Outright denial in the face of evidence is even more damaging, as it suggests either incompetence in understanding the organization's own situation or dishonesty in reporting it. Blame-shifting, whether toward employees, contractors, technology providers, or external circumstances, often backfires because stakeholders generally hold organizations responsible for managing their operations and supply chains. Explanations that focus primarily on why the situation was not the organization's fault read as defensive rather than informative. Finally, premature reassurance, where organizations declare situations resolved or under control before that is actually the case, creates acute credibility problems when subsequent developments contradict the reassurance. The impulse to provide comfort is understandable, but comfort based on claims that later prove false causes more harm than honest acknowledgment of ongoing uncertainty.

Consider a scenario involving a mid-sized manufacturing company operating in Saskatoon that experienced a cybersecurity incident affecting its operational technology systems. The company, which employed approximately one hundred and forty people and supplied components to larger manufacturers in the agricultural equipment sector, discovered on a Tuesday morning in February that several production systems were not responding normally. By early afternoon, the information technology team had confirmed that the company had experienced a ransomware attack that encrypted critical systems and potentially compromised data including employee personal information, customer contracts, and proprietary manufacturing specifications. The company faced immediate operational questions about whether and how to continue production, but it simultaneously faced a cascade of communication challenges. Employees were uncertain whether they would be paid on time given that payroll systems were affected. Customers needed to know whether orders would ship on schedule. The company's insurer needed notification to trigger coverage under the cyber liability policy. And if personal information had been compromised, the company potentially faced notification obligations under federal and provincial privacy legislation requiring disclosure to affected individuals and regulators.

The company's initial response illustrated several common failure patterns. The owner's first instinct was to avoid saying anything until the situation was fully understood, fearing that premature communication might create legal exposure or cause unnecessary alarm. The information technology team was focused entirely on technical recovery and had provided no estimated timeline for when systems might be restored. The office manager began receiving calls from employees asking whether to report for their shifts the following day and gave inconsistent answers depending on which department was inquiring. By Wednesday morning, word of the incident had spread through the local business community, and a reporter from a Saskatoon media outlet had called seeking comment. The owner provided a brief statement saying that the company was experiencing technical difficulties and expected to resume normal operations soon, a characterization that significantly understated the situation. Meanwhile, employees had begun posting on social media about the disruption, speculating about whether payroll would be affected and whether the company was financially stable. Customers who had heard rumors were calling to inquire about their orders and receiving either no callback or vague assurances that everything was fine. The insurance claim notification deadline was approaching without the company having assembled the documentation the insurer required.

The implications of this initial response created compounding problems over the subsequent weeks. When the full scope of the incident eventually became clear, the gap between the owner's initial public statement and the actual severity damaged credibility with the media outlet, which published a follow-up story highlighting the discrepancy. Employees who had been reassured about payroll and then experienced a one-week delay felt deceived rather than supported, damaging workplace trust and morale. Two significant customers began exploring alternative suppliers not because of the incident itself but because they felt the company had failed to communicate honestly with them about delivery impacts. The notification to affected individuals regarding the personal information compromise was delayed while the company struggled to determine exactly what data had been accessed, and this delay itself became a compliance concern under the Personal Information Protection and Electronic Documents Act, which as of the date of authorship requires notification without unreasonable delay after an organization determines that a breach creates a real risk of significant harm. The provincial privacy commissioners in Alberta and British Columbia maintain comparable requirements under their respective legislation, and Quebec's Act respecting the protection of personal information in the private sector imposes its own notification regime with specific timelines and content requirements. The company's failure to have pre-established communication protocols meant that meeting these obligations required crisis-mode assembly of information that could have been organized in advance.

What the scenario reveals is that crisis communication failures rarely stem from a single mistake but rather from the absence of preparation that makes effective response possible. The Saskatoon company did not have pre-drafted stakeholder communication templates. It had not identified who would speak for the organization in different circumstances or trained that person in crisis communication principles. It had not mapped out notification obligations in advance so that compliance could be achieved even under time pressure. It had not established alternative communication channels for reaching employees if normal systems were unavailable. Each of these gaps would have been relatively easy to address before the incident occurred, but each became a significant obstacle during the incident itself. The company also fell into predictable psychological patterns: the defensive mindset that prioritized avoiding bad news over providing accurate information, the premature reassurance that created a credibility gap when the full situation emerged, and the silence that allowed speculation to fill the vacuum. These patterns are not character flaws; they are normal human responses to threatening circumstances. But they are responses that preparation and training can modify, replacing instinctive reactions with deliberate practices that produce better outcomes.

The application of these principles to organizational preparation involves several concrete steps that Canadian organizations of all sizes can implement. First, identify the stakeholder groups who would need information during the types of disruptions most relevant to your operations. For most organizations, this includes employees, customers or clients, suppliers, regulators, and potentially the general public depending on the nature of operations. Understand what each group would need to know and how quickly they would need to know it. Second, establish the communication channels through which you would reach each group during a disruption, and consider whether those channels would remain available if your primary systems were affected. A company whose employee communication depends entirely on a corporate email system faces obvious problems if a cyber incident takes that system offline. Alternative channels such as personal mobile numbers, text message lists, or third-party communication platforms should be established before they are needed. Third, designate and train the individuals who will serve as spokespersons. For smaller organizations, this may be the owner or executive director; for larger organizations, it may involve multiple individuals speaking to different audiences. Training should cover both the substantive matters the spokesperson may need to address and the principles of effective crisis communication. Fourth, develop template communications that can be adapted to specific situations. These need not be elaborate documents; even a simple holding statement acknowledging that an incident has occurred, that the organization is responding, and that updates will follow can be adapted to most situations more quickly than composing from scratch under pressure.

Fifth, understand your notification obligations before an incident tests them. Organizations handling personal information should be familiar with their obligations under applicable privacy legislation, including what triggers notification, who must be notified, and within what timeframe. Organizations in regulated industries should understand their sector-specific reporting requirements. This understanding should not reside solely with legal counsel; operational personnel who would detect incidents need to know when to escalate matters for notification assessment. Sixth, exercise your communication protocols periodically. Tabletop exercises that walk through a hypothetical incident and require participants to identify what they would communicate, to whom, and how, reveal coordination problems and template gaps before real incidents expose them. Seventh, after any actual incident, conduct a communication review as part of your broader post-incident analysis. Assess what worked, what did not, and what should change for future incidents. This learning function is essential for continuous improvement but is often neglected when organizations are eager to move past an uncomfortable experience.

The questions that organizational leaders should ask themselves as they assess their crisis communication readiness include the following. If a serious incident occurred tomorrow morning, who would be responsible for communicating with each of our key stakeholder groups? Do those individuals know they have that responsibility, and have they been prepared for it? What channels would we use to reach stakeholders, and are those channels independent of the systems that might be affected by the incident itself? Do we have any pre-drafted communication templates that could be adapted, or would we be composing under pressure? Do we understand our notification obligations under applicable legislation and regulations? Have we ever tested our communication protocols through an exercise or simulation? The answers to these questions will reveal either readiness or gaps, and addressing the gaps before an incident occurs represents one of the highest-value investments an organization can make in its overall resilience. Crisis communication done well does not merely limit damage; it can actually strengthen stakeholder relationships by demonstrating competence, honesty, and genuine concern for those affected. Crisis communication done poorly, by contrast, can transform a manageable operational disruption into an existential threat to organizational reputation and survival. The choice between these outcomes is substantially within organizational control, but only if the preparation occurs before the pressure arrives.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options