• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to footer

Before Header

About Us | Articles | Free Resources | Podcast | YouTube Channel

Contact Us Subscribe

Bryghtpath

Business Continuity and Crisis Management Consultants

  • Start
        • Start your Resilience Journey

          Moving your organization – or your career – forward on your resilience journey can be a difficult and scary proposition.  Often, we find that prospective clients aren’t quite sure where to start.

          To help you along your journey, we’ve outlined below four curated collections geared towards momentum-building action and advice perfectly paired with your organization’s current stage of resilience.

        • I want to learn more about Resilience

        • We’re just getting started with our resilience program

        • We’re seeking to optimize & mature our resilience program

        • I’m a Resilience Professional seeking to further develop my skills

  • Company
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity as a Service (BCaaS)
          • Business Continuity Software
          • Coaching
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
  • Courses & Training
        • Courses & Training

          We’ve created a number of free and premium courses that have helped thousands improve their skills, build more resilient organizations, and lead through organizations through difficult critical moments successfully.

        • Coaching
          • 1-on-1 Coaching Call
          • Private Backchannel
          • Private Coaching Program
        • Free Intro Courses
          • Overview
          • Business Continuity 101
          • Crisis Communications 101
          • Crisis Management 101
        • Premium Courses
          • Overview
          • Custom Training
          • 5-Day Business Continuity Accelerator
          • Communicating in the Critical Moment
          • Crisis Management Academy®️
          • Preparing for Careers in Resilience
  • Expertise
        • Our Expertise
        • Here at Bryghtpath, in our core values, we state that we are humbly confident in our resiliency expertise.

          We write, publish, speak, and train others constantly – striving to share our thought leadership publicly to advance our industry and exercise our curiosity by interacting with other leaders in our practice domains.

        • Ultimate Guide to Business Continuity

        • Ultimate Guide to Crisis Management

        • Case Studies & Results

        • Free Resources & Frameworks
          • Overview - Free Resources
          • Bryghtpath Frameworks
            • Bryghtpath Business Continuity Lifecycle
            • Bryghtpath Crisis Management Framework
            • Bryghtpath Exercise Maturity Model
            • Bryghtpath Global Security Framework
            • Bryghtpath Long-Term Recovery Framework
            • Bryghtpath Professional Reading List
            • Bryghtpath Workplace Violence & Threat Management Toolkit
          • Resiliency Professionals Facebook Group
          • Resource Library
          • Webinars & Videos
          • Whitepapers & Reports
        • Our Thoughts & Insights
          • Articles
          • Lead Through Disruption. Stay Ahead with Bryghtpath.
          • Managing Uncertainty Podcast
          • Media & Professional Appearances
          • YouTube Channel
        • Whitepapers & Reports
          • Global Security Operations Centers & Resilience
          • Managing the Whole Crisis: The Ransomware Challenge
          • Mastering Uncertainty: Strengthening Organizational Resilience
          • Social Activism Campaigns
          • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
        • Our Industry Expertise

          Bryghtpath has extensive experience in a number of industries working with clients of all sizes, geographical locations, and business models. As a team, we possess, deep global operating experience on every continent around the world.

        • Industries Overview

        • Case Studies

        • Start your Journey

        • Education

          Education Icon
        • Finance

          Financial Services 800x800
        • Government

          Government Icon
        • Healthcare

          Healthcare Icon 800x800
        • Hospitality & Leisure

          Hospitality & Leisure Industry Icon 800x800
        • Life Sciences

          Life Sciences 800x800
        • Logistics

          Transportation & Logistics Industry Icon 800x800
        • Manufacturing

          Manufacturing Industry Icon 800x800
        • Non-Profits

          Non-Profit Industry Icon 800x800
        • Retail

          Retail Industry Icon 800x800
        • Tech & Media

          Communications Industry Icon 800x800
        • Utilities

          Power & Utilities Icon
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • From Panic to Poise: Crisis Management in the Modern World
          • The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • Start
  • Company
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity as a Service (BCaaS)
      • Business Continuity Software
      • Coaching
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Other Capabilities
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
  • Courses & Training
    • Coaching
      • 1-on-1 Coaching Call
      • Private Backchannel
      • Private Coaching Program
    • Free Intro Courses
      • Overview
      • Business Continuity 101
      • Crisis Communications 101
      • Crisis Management 101
    • Premium Courses
      • Overview
      • Custom Training
      • 5-Day Business Continuity Accelerator
      • Communicating in the Critical Moment
      • Crisis Management Academy®️
      • Preparing for Careers in Resilience
  • Expertise
    • Our Expertise
    • Our Thoughts & Insights
      • Articles
      • Lead Through Disruption. Stay Ahead with Bryghtpath.
      • Managing Uncertainty Podcast
      • Media & Professional Appearances
      • YouTube Channel
    • Free Resources & Frameworks
      • Overview – Free Resources
      • Bryghtpath Frameworks
        • Bryghtpath Business Continuity Lifecycle
        • Bryghtpath Crisis Management Framework
        • Bryghtpath Exercise Maturity Model
        • Bryghtpath Global Security Framework
        • Bryghtpath Long-Term Recovery Framework
        • Bryghtpath Professional Reading List
        • Bryghtpath Workplace Violence & Threat Management Toolkit
      • Resiliency Professionals Facebook Group
      • Resource Library
      • Webinars & Videos
      • Whitepapers & Reports
    • Whitepapers & Reports
      • Global Security Operations Centers & Resilience
      • Managing the Whole Crisis: The Ransomware Challenge
      • Mastering Uncertainty: Strengthening Organizational Resilience
      • Social Activism Campaigns
      • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
  • Products
    • Books
      • From Panic to Poise: Crisis Management in the Modern World
      • The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Managing Uncertainty Podcast – Episode #59: All roads lead to one – Crisis Management Framework

You are here: Home / Episode / Managing Uncertainty Podcast – Episode #59: All roads lead to one – Crisis Management Framework
Managing Uncertainty Website Graphic

August 5, 2019 By //  by Bryan Strawser

 Managing Uncertainty Podcast - Episode #59: All roads lead to one - Crisis Management Framework
Managing Uncertainty
Managing Uncertainty Podcast - Episode #59: All roads lead to one - Crisis Management Framework
icon-loader Managing Uncertainty Podcast - Episode #59: All roads lead to one - Crisis Management Framework
00:00 / 00:14:31
Apple Podcasts Stitcher
RSS Feed
Share
Link
Embed

Download file | Play in new window | Duration: 00:14:31 | Recorded on August 5, 2019

Subscribe: Apple Podcasts | Stitcher

We’ve talked on several previous episodes about the need for a single, defined crisis management framework in an organization.

In Episode #59 of the Managing Uncertainty Podcast, Bryghtpath Principal & CEO Bryan Strawser and Consultant Bray Wheeler go deeper into this need – and talk about the need to integrate all of an organization’s various incident management processes into a single unified crisis management framework.

Relevant previous episodes about the Crisis Management Framework:

  • #1 – Shouldn’t we have a plan for alien invasion?
  • #23 – Crisis Management is not a pickup game

Other Resources

  • Journal Article:  From crisis prone to crisis prepared: a framework for crisis management (1993)
  • Journal Article: Crisis management: an extended reference framework for decision-makers (2013)

WAYlTTcSWclkeF68_kk1yRqwLwHjcCH2N7Zryifeshn-r77UHUUE0moHk-UehUjkC-V3KQGy-qU6edOZdD0xZzY=s0 Managing Uncertainty Podcast - Episode #59: All roads lead to one - Crisis Management Framework

Episode Transcript

Bryan Strawser: Hello and welcome to the Managing Uncertainty podcast. This is Bryan Strawser, principal and CEO here at Bryghtpath.

Bray Wheeler: Hi, this is Bray Wheeler, consultant at Bryghtpath.

Bryan Strawser: And today we’re going to be talking about having a single, unified crisis management framework. And I guess I’ll sum the problem up because Bray and I were talking about this on the ride back from lunch today as we were struggling to figure out what to talk about on the podcast. And one of the things that we hit on is that we often see the issue in organizations that organically, for all the reasons that seem like the right reason at the time, a lot of companies wind up having siloed incident and crisis management processes that are totally rooted in the kind of problem that a single organization and the company has to deal with.

Bray Wheeler: Yes.

Bryan Strawser: And, over time they come to realize that they need other teams involved in that process. So what happens is, and I’m just going to pick on my two favorite people to pick on, physical security or corporate security and information security or cybersecurity, that they probably have in most companies, separate incident management processes, and then almost are definitely going to have separate crisis management processes. And generally, they won’t have a crisis management framework.

Bray Wheeler: Most likely.

Bryan Strawser: And let’s say that both things happen in the same week. So the physical security, the corporate security team is dealing with a homicide, the cybersecurity team is dealing with some type of data breach. They’re probably sending out two different communications that are not coordinated, that have different templates, that have different people at the table to make decisions, maybe not the right people, and not everyone is being informed in a consistent manner. And at the top of that food chain is a CEO who is getting one set of comms from here about one incident and a different set of comms from here about a different incident, and says the infamous WTF, what’s going on here?

Bray Wheeler: Yep. They look different.

Bryan Strawser: They look different.

Bray Wheeler: They talk differently. They’re using different language.

Bryan Strawser: Maybe one informed me and maybe one didn’t.

Bray Wheeler: Asking me things or not asking me things.

Bryan Strawser: And I don’t know, what’s my role supposed to be?

Bray Wheeler: Yep.

Bryan Strawser: You can’t see me because I’m raising my arms up in the like, “What?”

Bray Wheeler: He’s gesticulating.

Bryan Strawser: What? What’s going on? So, how do we solve this problem? What do we want companies to do?

Bray Wheeler: I think the big thing is, it’s not inherently bad to have different response systems to, as we’re picking on physical security and information security because they’re inherently different types of problems.

Bryan Strawser: Absolutely.

Bray Wheeler: However, when we get up into a certain threshold, and however that’s defined within the organization, and probably one of the challenges is defining things similarly, you have a threshold that when it is crossed there, that it becomes an enterprise problem, an enterprise response to something. So that way it has a consistent look and feel. It has a consistent inform process, an escalation process, a de-escalation process, a review after-action process that all those things walk and talk similarly, regardless of what the problem is so that the C-suite, the execs, all know, “Okay, I understand what’s going on. Okay, I understand what’s being asked of me. Okay, I understand what’s coming next, even if I’m not in it day-to-day.” And throughout the organization, it starts to build that culture of, “We know what to do,” because of a lot of times, to your earlier point, it’s not even just the execs that are called in. A lot of times these processes could be pinging the same communications person.

Bryan Strawser: Well, yeah I was about to say, I mean it’s all-

Bray Wheeler: It’s an HR person.

Bryan Strawser: All of these crises, all these incident types, there’s a communications element to the whole thing, and so comms is going to get pulled in multiple different directions as you go through that. I mean, what we preach I think consistently, and we try to guide our clients towards is that you want a single, unified crisis management process for the organization. You may have some debates about what’s an incident and what’s a crisis or what’s an event, what’s an incident, what’s a crisis if I use the kind of ITIL terms for IT incidents, but, or even disaster comes into play in a term, in the world that we live in.

Bryan Strawser: But just think about in the generic discussions we have with companies when we teach how to build a crisis management framework, we talk about five types of incidents, just kind of generically. That companies have operational incidents, so there are disruptions to your business. There are IT or information systems incidents. Those could be cyber incidents, or they could be a tech problem. You have security incidents, physical security incidents, you have may have a financial incident like a liquidity problem. And don’t tell me that’s not a crisis, that is a huge crisis for companies. And then all of these have reputational components, but you also have a reputational incident. You could have executive misconduct, you could have some 2-year-old intern, got the keys to your Twitter account and posted something dumb. I mean, there’s a lot of things that can happen there, but there alone are five types of incidents before we even get to what industry sector are you in and does that generate particular types of issues? All of those can become a crisis.

Bray Wheeler: They can. And it’s one of those things where if you’re not, this is where culture matters with a lot of this stuff, and having some unification of how you’re defining things, how you’re organizing yourselves, how you’re building on each other matters because it’s, as things come through, it may manifest as, to pick on reputation a little bit, it may manifest as a security incident. Security incident’s resolved through the process, it escalates up kind of in that response, but how the company handles it, something that happens, some statement somebody makes, all of a sudden makes it a reputational issue.

Bray Wheeler: Who’s running that? Physical security isn’t going to feel equipped, and they’re going to feel like their job is done and now all of a sudden it’s a reputational piece. Who’s on point? Does it start over? Does somebody have to now pick this ball up from scratch and go? Whereas if you have that unified, if you have a consistent escalation process within the company, there’s kind of a sense of, I don’t want to say comfort, but a sense of confidence in terms of, “Hey, the security part of this is over, but we’re still all engaged and still responding to the reputational component of this, and still managing that through its conclusion,” in air quotes.

Bryan Strawser: Well, and I think some of these situations have multiple dimensions to them anyway, which is why we always talk about having a cross-functional crisis team. But I remember years ago when I was at my last employer where we had a reputational issue going on that led to in-person protests at locations, at the company’s locations. That’s no longer just a communications problem. That’s now disrupting the business, endangering customers. It requires physical security to be at the table, but it was difficult to get a seat at the table because everyone perceived this as, “Well, this is the reputational issue.”

Bray Wheeler: Yeah.

Bryan Strawser: It’s bigger than that.

Bray Wheeler: You start to put other functions of the business at risk. Or you’re putting it in their hands because you’re so focused on trying to manage media or manage a conversation with another organization that you’re ignoring kind of those folks on the ground that are just trying to run the business, but now they’re speaking for the business. And if they’re not armed, if they’re not aware, if they’re not feeling confident in what the organization’s trying to do or what they should be saying, it starts spinning. And now not only do you have a localized, or not only do you have kind of a bigger issue, but you have also localized issues. Or you have a feeder into that bigger issue that just keeps compounding itself.

Bryan Strawser: Yeah, I think we keep preaching the idea that a crisis is a crisis. How you got to be in the crisis doesn’t really matter. The general processes that you’re going to use to collaborate across the organization, across the silos, right? To make the right decision, to communicate the results of those decisions, to get buy-in from your executive leadership or to escalate an issue to executive leadership, those are, to me, those are unchangeable regardless of how you got to the crisis, right? You may have specific actions that you want your crisis team to take based on the type of incident that you started with.

Bray Wheeler: And that’s important.

Bryan Strawser: And you will. You will. If it’s a cyber incident, you’ve got regulatory requirements regardless of what industry you’re in. You may have a data breach notification provider you need to spin up. There are things you’re probably gonna have to do that are unique to that type of crisis. The same way that if you’re dealing with an active shooter incident, there are some things you’re going to need to do that are unique to that type of scenario. But that process of getting together and making decisions and communicating those decisions, it doesn’t differ.

Bray Wheeler: No, I mean at the basic level, it’s the right people in the right room able to make the right decisions.

Bryan Strawser: Yep. Clearly defined roles and responsibilities, escalation pathway to senior executives. The same things we always have talked about when it comes to a crisis framework.

Bray Wheeler: And I think that’s part of what we touched on too, and to get into some of that is there’s a couple of different things at play, too. There’s assuming positive intent with some of this too, that some of these functions, if there is a sense that, “Hey, this process doesn’t really account for my kind of business area and what we deal with,” they’re feeling obligated to put something into play. Or if there is a sense that, “Oh, well there’s a perception that that team only deals with hurricanes,” because that has been the big issue for the last three or four months. There’s been three or four big hurricanes and weather and things like that. “Oh, they just do the weather. They don’t do all that other stuff.” So there’s that sense of positive intent, too, that people are just trying to solve those problems, but it can’t just live in that world. And I think a lot of those functions have to be open to the fact that there are lines. There does need to be some common definitions, even if they differ a little bit in terms of the specific area that we’re talking about. You do have to reach some thresholds of, “When it hits here, we’re going to get together in the room and figure out, is that where it is? Does it need to go higher?” Or, “Your organization’s got it? Great. We’ll just be on standby.”

Bryan Strawser: Totally agree with that. Totally agree with that.

Bray Wheeler: I will say, part of what I think especially bigger organizations run into, because they are big, they’re more complex. There’s more just inherent bureaucracy, organizational kind of spread in terms of people’s focus areas. It’s important if your company does have a crisis management or response focus that those teams are not only talking to each other but if there is one kind of master process, that it’s constantly kind of refreshing itself and evolving to what those risks are within the business. That it’s constantly raising awareness to, “Hey, this company has this process and this is what we do for X company.” That way you’re building that awareness, you’re building that culture, you’re building that, “Oh, something happened. I bet you that team is on it. I bet you that function is on it. Oh, I know they’re responding to it.” Or if you’re in a different organization, “I know where to go. I know what’s going to be expected of me when we raise something up.”

Bray Wheeler: I think it’s just as important as kind of bringing everybody to the room. It’s kind of constantly reinforcing that, because if you don’t have an incident for awhile that raises to kind of your upper levels, out of sight, out of mind. People start forgetting. And then you start running into, “Well, we got to create something,” or, “what does it we do?” And you get out of practice.

Bryan Strawser: Yeah, I agree. I think that the broader base of crisis situations is a better approach in terms of having those things flow into your crisis process and that you’re seeing that consistency in how this is getting handled, how it’s being communicated, and the value that places on kind of your centralized crisis team or command center, security operation center, whatever is kind of at the heartbeat of making this place happen, making this process happen.

Bray Wheeler: Yeah.

Bryan Strawser: So that’s it for this edition of the Managing Uncertainty podcast. We’ll be back at you next week with two episodes. Our BryghtCast episode focusing on recent events and what it means for private sector organizations, and a deep-dive into another topic. Thanks for listening.

Tag: bray wheeler, Bryan Strawser, bryghtpath, bryghtpath llc, crisis consultant, crisis framework, crisis management, crisis management consultant, crisis management framework, Managing Uncertainty, managing uncertainty podcastPodcast: Managing Uncertainty

About Bryan Strawser

Bryan Strawser is Founder, Principal, and Chief Executive at Bryghtpath LLC, a strategic advisory firm he founded in 2014. He has more than twenty-five years of experience in the areas of, business continuity, disaster recovery, crisis management, enterprise risk, intelligence, and crisis communications.

At Bryghtpath, Bryan leads a team of experts that offer strategic counsel and support to the world’s leading brands, public sector agencies, and nonprofit organizations to strategically navigate uncertainty and disruption.

Learn more about Bryan at this link.

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity as a Service (BCaaS)
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Premium Courses

5-Day Business Continuity Accelerator

Communicating in the Critical Moment

Crisis Management Academy®️

Preparing for Careers in Resilience

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model™
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.