• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to footer

Before Header

Bryghtpath

Business Continuity and Crisis Management Consultants

  • About
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity Software
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Coaching
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
        • Resilience as a Service
          • Business Continuity as a Service (BCaaS)
        • Case Studies & Results
        • Industries
  • Insights
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • Book – From Panic to Poise: Crisis Management in the Modern World
          • Book – The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • About
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity Software
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Resilience as a Service
      • Business Continuity as a Service (BCaaS)
    • Other Capabilities
      • Coaching
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
    • Case Studies & Results
    • Industries
  • Insights
  • Products
    • Books
      • Book – From Panic to Poise: Crisis Management in the Modern World
      • Book – The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Your Crisis Decision History Is a Single Point of Failure

You are here: Home / Crisis Management / Your Crisis Decision History Is a Single Point of Failure
A high-speed conceptual 3D render of a towering paper stack converting into digital data streams, illustrating document scanning, information flow, workflow automation and the shift from paper to cloud storage.

August 5, 2026 By //  by Bryan Strawser

Hour three of a ransomware response. Someone on the call says what someone always says.

“Didn’t we work through this in the spring?”

They did. There was a tabletop in April that ran this exact scenario. The team reached a decision on the payment question, wrote down the criteria, and named who owned the call. It is documented.

Nobody on the bridge can find it.

That is not a documentation problem. Your organization has plenty of documentation. That is a retrieval problem, and it is a resilience control that almost nobody tests.

Crisis management documentation is a recovery capability, not a filing exercise

Every crisis runs on a decision clock. The question is never whether your team will eventually reach a good decision. It is how much of the response window gets consumed reaching it.

Rediscovery is dead time. When a team spends forty minutes reconstructing a judgment it already made, that is forty minutes of the recovery window spent on work that was already finished. The plan was not the failure. The memory was.

I hear the symptom constantly, and clients describe it in almost identical language. Crap is all over the place. There are two crisis plan documents with overlapping content. Nobody can figure out what is tied to what. Program leaders do not know their own program.

Notice that none of those are complaints about missing information. They are complaints about unreachable information.

The obvious fix is the one that keeps failing

Somebody proposes it every year. Let’s put everything in one place.

Consolidate into SharePoint. Move it all into the GRC platform. Buy the BC tool with the document repository. Run the migration, retire the shadow copies, and finally get a single source of truth.

I have watched this project start many times. I have never watched it finish.

The reason is not poor execution. It is that people create information wherever it is convenient to create it. Decisions get made in a Teams thread because that is where the team already was. Context lands in an email because someone was on a phone. Exercise observations go in a facilitator’s notebook. The recovery runbook lives with the engineer who wrote it.

You can mandate a destination. You cannot mandate where a decision gets made at 2am.

A chip company solved this and did not consolidate anything

Cerebras published an engineering post recently on the internal knowledge base they built. Their people ask it more than 15,000 questions a day. They add hundreds of new employees a year across chip design, data center operations, and cloud infrastructure, and those people kept asking the same three questions: where do I find this, who is the expert, what does this mean.

Different industry, same failure mode we see in resilience programs.

What they did is the interesting part. They explicitly refused to consolidate. They note that every quarter or so someone proposes recording everything in one platform, and that the single-source-of-truth dream “rarely works in practice.” So they left every system exactly where it was and built retrieval across the sprawl instead. Read their write-up here.

Three things they learned translate directly to crisis management documentation.

They do not index raw text. Before anything becomes searchable, they distill each source down to a one-line question someone would actually search for, a short summary, and the resolution. Their reported accuracy improved significantly once records were normalized into a consistent shape.

Apply that to your AARs. “Discussed the ransomware payment decision” is not retrievable. “We decided not to pay, on these three criteria, approved by the CFO, on April 9” is. Both are documentation. Only one is institutional memory.

Exact wording matters as much as meaning. They run keyword matching alongside meaning-based search, because when someone pastes a literal error string, nothing should outrank an exact match. In our world that is the application name, the vendor, the standard, the ticket number, the plan version. Your team searches literally under pressure. Preserve the strings.

Old answers expire. They deliberately downrank age, because a six-month-old answer may describe infrastructure that no longer exists.

That is a mild annoyance in software. In crisis management it is a live hazard. A 2023 recovery runbook describing a data center you exited last year will send a team down a path that no longer exists, at hour three, while the clock runs. Clients name this one themselves: as IT migrations happen, the plans get updated manually, one at a time, if at all.

Undated guidance is worse than no guidance during a response. No guidance sends people looking. Confident, stale guidance sends them the wrong way.

Old view, new view

Old view New view
We need a single source of truth We need a single point of retrieval
Documentation is a compliance artifact Documentation is a recovery capability
The plan holds our institutional memory The decision history holds our institutional memory
Scattered information is a filing problem Unretrievable information is a response problem
If it is written down, it is captured If it cannot be found in four minutes, it is not captured

 

Four moves, none of which require a migration

Run a retrieval test. Not a documentation audit. Pick a real decision from your last incident or exercise. Hand it to someone who was not in the room and give them ten minutes to tell you what was decided and who decided it. Time it. Whatever number you get is your actual baseline, and it will be worse than you expect. Run it again in two quarters.

Normalize the record where it already lives. Every AAR, exercise, and incident debrief captures five things in a consistent shape: the question, the decision, who made it, the date, and what stayed open. Five fields. Do not move the source material. Add the layer that was missing.

Date everything and mark what is superseded. When newer guidance replaces older guidance, say so explicitly in the old document. Staleness that is visible is manageable. Invisible staleness is what hurts you.

Stop funding the consolidation project. Redirect that budget and that political capital to retrieval. You will get more resilience per dollar, and unlike the migration, it will actually finish.

We built this on ourselves first

We just did this at Bryghtpath, on our own institutional memory, and I would rather tell you what went wrong than pretend it was clean.

Our first version created one record per meeting. That failed immediately. A weekly client status call covers five unrelated threads, and forcing it into one searchable summary means four of the five become unfindable. We had to break each source into one record per topic before anything worked.

We also found something worth flagging. When we pulled a client status meeting to test the design, the raw notes were genuinely detailed: every application under test, ticket numbers, named owners. The summary field was blank. The blockers section was an untouched template.

The information was there. The record of what we decided was not.

If that is true of a firm that does this for a living, be honest about whether it is true of your program.

The question worth asking this week

Where does your crisis decision history live, and can you retrieve it under pressure?

If the answer involves a person’s memory, that person is a single point of failure. If the answer involves a folder nobody can name, you do not have a decision history. You have an archive.

The next crisis will ask you a question you have already answered. Whether that helps depends entirely on whether you can find the answer.

Keep Going

A few ways to go deeper if this was useful.

  • Read more. Resilience, crisis management, and continuity writing at Bryghtpath Insights, or the structured Ultimate Guide to Crisis Management.
  • Build the decision record into your program. Our Crisis Management services cover the framework, the plan, and the after-action discipline that turns a response into something your team can retrieve next time.
  • Get a maturity score. Our Resiliency Diagnosis® is a standards-based review that produces a maturity score and a prioritized roadmap.
  • Talk to us. Set up a call to think through your program with us.

Category: Business Continuity, Crisis Management

About Bryan Strawser

Bryan Strawser is Founder, Principal, and Chief Executive at Bryghtpath LLC, a strategic advisory firm he founded in 2014. He has more than twenty-five years of experience in the areas of, business continuity, disaster recovery, crisis management, enterprise risk, intelligence, and crisis communications.

At Bryghtpath, Bryan leads a team of experts that offer strategic counsel and support to the world’s leading brands, public sector agencies, and nonprofit organizations to strategically navigate uncertainty and disruption.

Learn more about Bryan at this link.

Previous Post: « Crisis Leadership When the Playbook Fails: Dutch Leonard’s Framework, Six Years Later
Next Post: Executive Buy-In for Business Continuity: Being Liked Is Not the Same as Being Believed »

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Resilience as a Service
    • Business Continuity as a Service (BCaaS)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model®
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.