Crisis Communication for COOs: The First-Hour Playbook

When something breaks badly — a data breach, a product recall, a plant fire, a founder scandal — the damage is rarely the event alone. It is the silence, the mixed messages, and the guesswork that follow while your organisation decides what to say. The COO's job is to close that gap fast, with a message that is accurate, calm, and coordinated across everyone who needs to hear it.
The single most useful thing you can do is decide, before anything goes wrong, exactly who speaks, who approves, and how the first message reaches employees, customers, and the press. A crisis is the worst possible time to invent a process. Teams that improvise send three different versions of the story in the first hour and spend the next week correcting themselves.
This guide is the practical version of that preparation: how to stand up a crisis communication team, what to say in the first sixty minutes, how to choose channels, how to keep internal and external messages aligned, and how to run the review that makes your next crisis smaller.
Build the crisis communication team before you need it
A crisis communication plan lives or dies on named people, not roles on a slide. You want a small standing group — often called a Crisis Management Team — with one person clearly in charge and a designated backup for every seat, because your comms lead will inevitably be on a plane the day it matters.
Strong looks like this: a documented team with a decision-maker (usually the COO or a delegate), a single spokesperson, a communications lead who drafts and coordinates, legal counsel on speed-dial, and an operations owner who knows the actual facts of what happened. Every person has a backup, and the whole group has run at least one drill in the past year so they know the muscle memory. Weak looks like a contact list nobody has opened since it was written, five people who all think they are the spokesperson, and a legal review step that adds two hours because counsel is learning the situation from scratch. If your plan has never been rehearsed, assume it does not work.Set the activation trigger in advance so no one wastes time debating whether this "counts". Activate when an event threatens safety, business continuity, reputation, or legal standing — an operational outage, a security breach, a safety incident, a regulatory action, or anything likely to reach the media. When in doubt, activate; standing the team down is cheap, and a late start is not recoverable. This team-first discipline is the same one that underpins coordinated crisis management more broadly.
The first hour: assess, hold, then update
The opening hour sets the tone for everything that follows. You will not have all the facts, and waiting until you do is how a manageable incident becomes a trust problem. The move is to acknowledge quickly with what you know, then update on a promised schedule.
Run a fast assessment first. A simple checklist keeps a panicked team honest:
- Facts: what is confirmed, and what is still unknown? Write down only what you can verify.
- Audience: who is affected — employees, customers, regulators, the public?
- Channels: where does each audience actually look for information from you?
- Timing: how urgent is this, and when will the next update come?
- Scope: how far does the impact reach, and is it growing or contained?
A usable structure for almost any first message:
We are aware of [situation] affecting [who/what]. Our team activated at [time] and is [immediate action]. The safety of [affected group] is our priority. We will share a further update by [specific time].
The difference between strong and weak here is discipline. A strong first message names a real next-update time — "by 4 PM" — and hits it. A weak one says "we will update you soon", which reads as a stall, or worse, over-commits to a cause ("we believe this was an isolated third-party error") that later turns out to be wrong. State facts, acknowledge unknowns, and never let the first message contain a claim you might have to retract.
Choose channels by audience, not by habit
Different audiences need different channels, and the mistake COOs make under pressure is pushing everything through the one channel they personally trust. Map the primary and backup channel for each group ahead of time, so activation is a matter of pulling a card, not making a decision.
| Audience | Primary channel | Backup channel | First message priority |
|---|---|---|---|
| Employees | Internal messaging / all-hands email | SMS or phone tree | Highest — they hear it from you, not the news |
| Customers | Email + status page on your website | In-app notice, social media | Impact on them, and what to do next |
| Media / public | Press statement from named spokesperson | Verified social account | Verified facts only, single consistent version |
| Regulators / partners | Direct call, then written notice | Secure email | Compliance-accurate, often legally reviewed |
| Investors / board | Direct briefing from the COO/CEO | Secure written summary | Materiality, exposure, and response plan |
Keep a single source of truth. Every channel points back to one canonical, timestamped update — usually a status page or a pinned statement — so that as the story develops, there is one place that is always current and everyone quotes the same words.
Keep internal and external messages aligned
The fastest way to turn one crisis into two is to tell employees one story and the public another. They compare notes within minutes. Your internal and external messages do not need to be identical — staff can handle more operational detail — but they must never contradict each other on the facts, the timeline, or the tone.
Practically, this means one drafting team owns all versions and a single approval chain signs them off together. A workable sequence: operations confirms the facts, the communications lead drafts internal and external versions side by side, legal reviews both in one pass, and the decision-maker approves the set. Releasing the external statement before staff are briefed is a common, avoidable own-goal.
Do-and-don't, drawn from how these situations actually go wrong:
| Do | Don't |
|---|---|
| Brief employees first, or at the same moment | Let staff find out from the press or social feeds |
| Speak through one named spokesperson | Let five managers freelance their own version |
| Share verified facts and name what is unknown | Speculate on cause or fault before you know |
| Commit to a next-update time and hit it | Go silent and hope the story fades |
| Log every message with a timestamp | Rely on memory to reconstruct events later |
Document as you go, then run the review
During the crisis, keep a running log — every message sent, every decision made, who approved it, and when. This is not bureaucracy for its own sake. It protects you legally, it lets a fresh shift pick up the thread without re-litigating the last four hours, and it is the raw material for the review that turns this event into a stronger plan.
Once the immediate danger passes, schedule a debrief quickly — within a day or two, while memory is fresh. The review is not about blame; it is about the process. Look at where the first message was slow, which channel underperformed, where internal and external stories drifted, and which contact in your plan turned out to be wrong. Then actually change the plan — update the templates, fix the contact list, and re-run a drill against the new version.
Strong organisations treat every incident as a rehearsal that fed real data into the system, and their plan visibly improves each time. Weak ones write a report nobody reads and file the same broken template away for next time. The review is where a crisis stops being pure cost and starts building durable operational resilience — and it works best inside a broader business continuity plan that connects communication to the operational recovery happening alongside it.Key takeaways
- Decide who speaks, who approves, and how the first message reaches each audience before a crisis — you cannot design the process while it is burning.
- Stand up a named crisis communication team with a backup for every seat, and rehearse it at least once a year. An unrehearsed plan is a guess.
- Use the first hour to acknowledge with a holding statement — aware, concerned, acting, next update by [time] — not to guess at cause or numbers.
- Map primary and backup channels per audience, and make sure employees hear it from you before they hear it from the news.
- Keep internal and external messages aligned through one drafting team and one approval chain; contradictions turn one crisis into two.
- Log everything in real time and run a fast, blame-free review that actually changes the plan.