In the first hours of a major incident, the organisation's fate depends less on the event itself than on how fast someone with authority takes charge. Crisis management exists so that this moment is not improvised: it defines who declares a crisis, who leads the response and how decisions are made when information is incomplete. The executive decision that hangs on it is the earliest and hardest one — whether to treat the event as a routine incident or to activate the full crisis structure. Get that call wrong in either direction and the organisation pays, in losses or in credibility.
In practice, crisis management rests on three documents: a crisis management plan, role cards for each member of the crisis team, and an escalation procedure with thresholds. When a ransomware attack locks the ERP system at 02:00, the on-duty manager checks the threshold — say, any outage of a critical system expected to exceed 4 hours — and convenes the crisis team within 30-60 minutes, physically or by a pre-agreed call bridge. The team then works to a simple rhythm: assess, decide, communicate, review, typically in cycles of 60-90 minutes. In the Gulf, regulators such as the UAE's NCEMA expect exactly this level of defined structure from organisations in vital sectors.
The classic failure is a crisis structure that exists on paper but has no authority in the moment: a team that must ask permission to spend money or shut a system down loses the hours that matter most. Another is the plan that names departments instead of people, so at 02:00 nobody knows who to call. In the ERGP programme, this discipline is the subject of module M4, Crisis management and decision making.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme