Hour three of a ransomware response. Someone on the call says what someone always says.
“Didn’t we work through this in the spring?”
They did. There was a tabletop in April that ran this exact scenario. The team reached a decision on the payment question, wrote down the criteria, and named who owned the call. It is documented.
Nobody on the bridge can find it.
That is not a documentation problem. Your organization has plenty of documentation. That is a retrieval problem, and it is a resilience control that almost nobody tests.
Crisis management documentation is a recovery capability, not a filing exercise
Every crisis runs on a decision clock. The question is never whether your team will eventually reach a good decision. It is how much of the response window gets consumed reaching it.
Rediscovery is dead time. When a team spends forty minutes reconstructing a judgment it already made, that is forty minutes of the recovery window spent on work that was already finished. The plan was not the failure. The memory was.
I hear the symptom constantly, and clients describe it in almost identical language. Crap is all over the place. There are two crisis plan documents with overlapping content. Nobody can figure out what is tied to what. Program leaders do not know their own program.
Notice that none of those are complaints about missing information. They are complaints about unreachable information.
The obvious fix is the one that keeps failing
Somebody proposes it every year. Let’s put everything in one place.
Consolidate into SharePoint. Move it all into the GRC platform. Buy the BC tool with the document repository. Run the migration, retire the shadow copies, and finally get a single source of truth.
I have watched this project start many times. I have never watched it finish.
The reason is not poor execution. It is that people create information wherever it is convenient to create it. Decisions get made in a Teams thread because that is where the team already was. Context lands in an email because someone was on a phone. Exercise observations go in a facilitator’s notebook. The recovery runbook lives with the engineer who wrote it.
You can mandate a destination. You cannot mandate where a decision gets made at 2am.
A chip company solved this and did not consolidate anything
Cerebras published an engineering post recently on the internal knowledge base they built. Their people ask it more than 15,000 questions a day. They add hundreds of new employees a year across chip design, data center operations, and cloud infrastructure, and those people kept asking the same three questions: where do I find this, who is the expert, what does this mean.
Different industry, same failure mode we see in resilience programs.
What they did is the interesting part. They explicitly refused to consolidate. They note that every quarter or so someone proposes recording everything in one platform, and that the single-source-of-truth dream “rarely works in practice.” So they left every system exactly where it was and built retrieval across the sprawl instead. Read their write-up here.
Three things they learned translate directly to crisis management documentation.
They do not index raw text. Before anything becomes searchable, they distill each source down to a one-line question someone would actually search for, a short summary, and the resolution. Their reported accuracy improved significantly once records were normalized into a consistent shape.
Apply that to your AARs. “Discussed the ransomware payment decision” is not retrievable. “We decided not to pay, on these three criteria, approved by the CFO, on April 9” is. Both are documentation. Only one is institutional memory.
Exact wording matters as much as meaning. They run keyword matching alongside meaning-based search, because when someone pastes a literal error string, nothing should outrank an exact match. In our world that is the application name, the vendor, the standard, the ticket number, the plan version. Your team searches literally under pressure. Preserve the strings.
Old answers expire. They deliberately downrank age, because a six-month-old answer may describe infrastructure that no longer exists.
That is a mild annoyance in software. In crisis management it is a live hazard. A 2023 recovery runbook describing a data center you exited last year will send a team down a path that no longer exists, at hour three, while the clock runs. Clients name this one themselves: as IT migrations happen, the plans get updated manually, one at a time, if at all.
Undated guidance is worse than no guidance during a response. No guidance sends people looking. Confident, stale guidance sends them the wrong way.
Old view, new view
| Old view | New view |
| We need a single source of truth | We need a single point of retrieval |
| Documentation is a compliance artifact | Documentation is a recovery capability |
| The plan holds our institutional memory | The decision history holds our institutional memory |
| Scattered information is a filing problem | Unretrievable information is a response problem |
| If it is written down, it is captured | If it cannot be found in four minutes, it is not captured |
Four moves, none of which require a migration
Run a retrieval test. Not a documentation audit. Pick a real decision from your last incident or exercise. Hand it to someone who was not in the room and give them ten minutes to tell you what was decided and who decided it. Time it. Whatever number you get is your actual baseline, and it will be worse than you expect. Run it again in two quarters.
Normalize the record where it already lives. Every AAR, exercise, and incident debrief captures five things in a consistent shape: the question, the decision, who made it, the date, and what stayed open. Five fields. Do not move the source material. Add the layer that was missing.
Date everything and mark what is superseded. When newer guidance replaces older guidance, say so explicitly in the old document. Staleness that is visible is manageable. Invisible staleness is what hurts you.
Stop funding the consolidation project. Redirect that budget and that political capital to retrieval. You will get more resilience per dollar, and unlike the migration, it will actually finish.
We built this on ourselves first
We just did this at Bryghtpath, on our own institutional memory, and I would rather tell you what went wrong than pretend it was clean.
Our first version created one record per meeting. That failed immediately. A weekly client status call covers five unrelated threads, and forcing it into one searchable summary means four of the five become unfindable. We had to break each source into one record per topic before anything worked.
We also found something worth flagging. When we pulled a client status meeting to test the design, the raw notes were genuinely detailed: every application under test, ticket numbers, named owners. The summary field was blank. The blockers section was an untouched template.
The information was there. The record of what we decided was not.
If that is true of a firm that does this for a living, be honest about whether it is true of your program.
The question worth asking this week
Where does your crisis decision history live, and can you retrieve it under pressure?
If the answer involves a person’s memory, that person is a single point of failure. If the answer involves a folder nobody can name, you do not have a decision history. You have an archive.
The next crisis will ask you a question you have already answered. Whether that helps depends entirely on whether you can find the answer.
Keep Going
A few ways to go deeper if this was useful.
- Read more. Resilience, crisis management, and continuity writing at Bryghtpath Insights, or the structured Ultimate Guide to Crisis Management.
- Build the decision record into your program. Our Crisis Management services cover the framework, the plan, and the after-action discipline that turns a response into something your team can retrieve next time.
- Get a maturity score. Our Resiliency Diagnosis® is a standards-based review that produces a maturity score and a prioritized roadmap.
- Talk to us. Set up a call to think through your program with us.


Crisis Leadership When the Playbook Fails: Dutch Leonard’s Framework, Six Years Later