The 6 Key Steps + Ready-to-Use Template | Wayden

Mélanie

En charge des projets marketing chez WAYDEN, je suis passionnée par les sujets de management de transition, gestion de projets, marketing automation, community management, et de stratégie marketing.

Article mis à jour le 3 August 2026

What is a crisis management plan?

A crisis management plan — sometimes called a crisis management manual or emergency plan — is a reference document that lists and standardizes the best practices to be activated in a critical situation. It lists the scenarios likely to affect the company and associates each one with a precise action plan: priority actions, resources that can be mobilized, decision-making circuits, communication plan, indicators for exiting the crisis.

It is a roadmap drawn up in times of stability to prepare for the management of possible crises in advance. The Ministry of Ecological Transition, in its summary of good practices in crisis management plans, insists on its purpose: to improve organizational security by capitalizing on past crisis analyses.

The crisis plan is often articulated with two complementary documents:

  • the Business Continuity Plan (BCP), which guarantees the maintenance of essential activities;
  • the Disaster Recovery Plan (DRP), which organizes the return to normality.

Why a crisis plan has become essential

Exposure to risk that is becoming widespread

The figures paint an unequivocal picture. On the cyber side, cyberattack statistics published on data.gouv.fr indicate that one in three companies is affected each year, and that 53% of companies have suffered an attack according to the Hiscox 2023 Report, compared to 48% the previous year — an increase of 5 points in twelve months.

On the financial side, the DGE points out that in 2024, 66,000 companies went bankrupt, including 32,000 with at least one employee. No organization, regardless of size or sector — including those that need to consider restructuring — is immune today.

The concrete benefits of a structured plan

  • Immediate responsiveness as soon as the event is triggered, without improvisation phase;
  • Pragmatic decisions, thought out coldly, sheltered from the stress of the emergency;
  • Reduction of financial, human, logistical and legal impacts;
  • Preservation of employee engagement and stakeholder trust;
  • Operational continuity or accelerated recovery of critical activities;
  • Long-term brand and reputation protection;
  • Sustainably building resilience and operational agility.

The 6 key steps to developing a crisis plan

Step 1 — Analyze the potential risks

The first step is to identify all the risks that are likely to affect the company. Some structuring families:

  • Technological risks : cyberattack, data leak, major IS failure;
  • Natural and industrial risks : flooding, fire, on-site accidents;
  • Financial risks : tight cash flow, falling markets, default of a key customer;
  • Human risks : work accidents, unexpected departure of a manager, social conflict, wave of resignations;
  • Logistics risks : supply chain disruption, critical supplier failure;
  • Operational and reputational risks : sudden drop in activity, media crisis, product recall.

To draw up an exhaustive list, mobilize the business units and ask each manager about the short, medium and long-term risks. Analyzing the company’s past crises and those affecting competitors makes it possible to identify recurring patterns.

Step 2 — Map the risks

Once identified, these risks must be prioritized according to two axes: probability of occurrence and severity of impact. A 5×5 matrix is enough to visualize priorities. Three questions to ask yourself for each scenario:

  • Does it jeopardize the continuity of operations?
  • Does it threaten financial survival, the brand or customer satisfaction?
  • What would be the time before irreversible impact?

Risks classified as “critical” (high probability × major impact) become a priority in the deployment of protocols.

Step 3 — Identify crisis management protocols

For each risk mapped, a precise protocol must be formalized. It includes:

  • the priority actions to be taken in the first hours to contain the event;
  • the instructions for mobilising the crisis unit and the operational teams;
  • the necessary financial, human, logistical and technical resources ;
  • the expected response times for each action;
  • the internal and external crisis communication plan ;
  • the criteria for exiting the crisis and the modalities for switching to the BCP.

Each scenario must lead to a response that is marked out over time. Once the immediate threats have been ruled out, structured feedback (RETEX) is conducted to feed into the next version of the plan.

Step 4 — Compose a crisis unit

The crisis unit is the steering body in degraded mode. It must be put together cold, with roles, substitutes and contact details validated. The typical composition:

  • A crisis director (often the manager or a member of the Executive Committee);
  • An operational coordinator who orchestrates the actions;
  • A communication manager in charge of internal, press, customer messages;
  • Business referents (CIO, HRD, CFO, legal, supply chain);
  • A crisis secretary who holds the handrail of decisions and timestamps.

In its recommendations on cyber crisis management, the ANSSI recalls that resilience is based on maintaining the organization’s essential activities — which requires a trained cell, equipped with redundant means of communication (emergency telephones, physical and virtual crisis room).

Step 5 — Prevent risks

The best crisis plan is the one that never serves. Prevention actions must be deployed in parallel:

  • strengthen IT security (immutable backups, network segmentation, generalized MFA);
  • optimize cash flow and diversify funding sources;
  • diversify critical suppliers and strengthen supply chain resilience;
  • Invest in change management and quality of life at work to limit disengagement.

Simulation exercises are essential. The national barometer of the cyber maturity of VSEs and SMEs highlights the persistent gap between the level of awareness and the actual implementation: blank exercises (red team, table top, ransomware simulation) are the best indicator of blind spots.

Step 6 — Identify external reinforcements (including interim management)

No internal team, even a well-prepared one, covers all the fields alone. Listing in advance the partners that can be mobilized in an emergency saves precious time: specialized lawyers, cyber experts (ANSSI qualified PRIS), insurers, crisis communicators, and seasoned interim managers .

The interim manager brings a triple value in crisis management: operational experience in comparable situations, neutral view of the organization, and immediate availability. Wayden identifies and mobilizes, sometimes within 48 to 72 hours, managers with proven expertise to manage a turnaround, a restructuring or the exit from a reputational crisis.

Ready-to-use crisis plan template

Here is a structured framework that you can adapt to your organization. Each section must be completed, validated by the Executive Committee, and revised at least once a year.

1. Cover Page and Governance

  • Document version, date of last revision, next audit;
  • Owner of the document (often Risk Manager or Corporate Secretary);
  • Validation and dissemination circuit (restricted distribution list).

2. Scenario mapping

  • Table of identified risks × probability × severity × status (covered / partially covered / not covered);
  • For each scenario: triggers, weak signals, warning indicators.

3. Organization of the crisis unit

  • Organizational chart with incumbents and alternates;
  • Crisis directory (personal numbers, redundant lines, emergency emails);
  • Physical meeting place and virtual fallback solution;
  • Delegations of authority and decision thresholds activated in crisis mode.

4. Operational Protocols by Scenario

  • Reflex sheets (1 page per scenario): actions H+0, H+1, H+4, H+24;
  • Isolation, containment and eradication checklists (for cyber scenarios);
  • Evacuation and safety procedures (for industrial scenarios).

5. Crisis communication plan

  • Pre-validated key messages (employees, customers, suppliers, press, authorities);
  • Designated spokesperson and back-up;
  • Regulatory notification procedure (CNIL within 72 hours in the event of a data breach, sectoral authorities).

6. Continuity plan and recovery

  • List of essential activities (with RTO and RPO);
  • Fallback solutions (secondary sites, emergency service providers, degraded modes);
  • Conditions for lifting the crisis mechanism.

7. Appendices

  • Templates for press releases, handrails, records of decisions;
  • External contacts: Cybermalveillance.gouv.fr, ANSSI, insurers, lawyers, communicators;
  • History of the exercises carried out and action plan resulting from the RETEX.

Concrete examples of recent crises

Ransomware cyberattack: the case of a Normandy SME

France Num documents the feedback of a Normandy SME that overcame a ransomware-type cyberattack in a few days. This case illustrates an operational truth: it is not the tools that save the company, but the preparation, the execution discipline and the decision-making chain activated as soon as it is detected.

More broadly, France Num warns of the acceleration of the cyber threat in 2025, which is now structurally affecting French SMEs and mid-caps. For these structures, outsourcing certain IT security projects to a transitional PMO makes it possible to industrialize protection without increasing the payroll in the long term.

Financial crisis and corporate failure

The DGE explains that insolvencies reached 66,000 companies in 2024, a level well above the pre-pandemic average. For managers facing financial difficulties, Service-Public.fr details the procedures for dealing with the crisis that eligible structures can benefit from. A financial crisis plan anticipates these measures, identifies the cash flow alert thresholds and provides for the activation of advice (ad hoc representative, conciliation, safeguard).

Systemic crisis: lessons from the 2020-2022 period

The cost to public finances recalled by the Ministry of the Economy gives the measure of the shock wave that a systemic crisis can cause. For companies, the lesson is clear: single-scenario crisis plans are no longer enough. We must now think in terms of a polycrisis — a simultaneous combination of several risks (health + energy + supply chain + cyber).

Best practices and mistakes to avoid

 

✅ Things to doTest the plan once or twice a year via realistic exercises. Update the crisis directory quarterly. Document each crisis via a formalized RETEX. Involve the Executive Committee in the validation and at least one annual exercise.

 

❌ What to avoidWrite a plan that sleeps in a binder without testing. Focusing knowledge on one person. Underestimating the communication dimension (internal, press, authorities). Confusing crisis plan and BCP: the two are complementary, not substitutable. Strategic landmark. A crisis plan is only valuable because of its ability to be executed under pressure. The maturity of an organization is not measured by the volume of its manual, but by the speed with which its crisis unit makes documented decisions in the first 60 minutes.

Call on Wayden to manage your crisis system

Wayden mobilizes experienced interim managers to intervene at decisive moments: designing a complete crisis plan, leading an active crisis unit, leading a restructuring, operational recovery or overhaul of a critical function. Our profiles have led comparable situations in industry, finance, healthcare, retail and services.

A crisis to be anticipated, managed or unraveled?

In a few days, our teams mobilize an interim manager who is tailored to your challenge.

Talk to a Wayden expert

FAQ — Crisis plan

What is the difference between a crisis plan and a BCP?

The crisis plan organizes the response to a disruptive event (who decides, who communicates, what immediate actions). The Business Continuity Plan (BCP) guarantees the maintenance of essential activities in degraded mode, and the DRP organises the recovery. The three documents are complementary and must be articulated.

Who should make up the crisis unit?

At least: a crisis director (often a manager or member of the Executive Committee), an operational coordinator, a communication manager, business referents (CIO, HRD, CFO, legal) and a crisis secretary. Each role must have an alternate identified.

How often should the plan be tested?

At least once or twice a year, via table-top exercises or realistic simulations. The ANSSI insists on the importance of training to maintain operational resilience in the face of cyber crises.

What are the first risks to cover as a priority?

Cyber risks have become a priority: according to data.gouv.fr’s cyberattack statistics, 53% of companies have suffered an attack (Hiscox Report 2023). Financial risks and supplier failures are also critical, in a context where the DGE lists 66,000 insolvencies in 2024.

Can an interim manager intervene in the middle of a crisis?

Yes. It is even one of the major use cases of interim management: taking charge of a critical situation, structuring the crisis unit, securing decisions and preparing for the exit. Wayden usually mobilizes a profile within a few days.


© Wayden 2026 - All Rights Reserved - Legal