August 15, 2026
Crisis Response Plan Presentation Template
A crisis response plan exists for one reason: when a crisis hits, decision-making quality degrades. People revert to instinct, organizational hierarchy collapses, and contradictory messages reach different stakeholders simultaneously. A documented, rehearsed crisis response plan replaces improvisation with procedure.
This presentation template is designed for internal use — training the crisis response team, briefing new executives, and conducting tabletop exercises. It is not a public-facing communications document.
When to Use a Crisis Response Plan
Not every adverse event is a crisis. Before activating a full crisis response, classify the incident:
Tier 1 — Operational Incident: Affects normal operations but is contained and resolvable without external communication. Handled by operational teams following standard procedures.
Tier 2 — Significant Incident: Affects customers, partners, or employees in a material way. Requires proactive communication to affected stakeholders. May attract limited media attention. Requires crisis lead involvement.
Tier 3 — Crisis: Threatens the company's reputation, business continuity, financial stability, or legal standing. Requires executive-level response, legal involvement, and proactive external communications. May involve regulatory notification requirements.
Tier classification should happen in the first 30 minutes after an incident is reported. The rest of the response plan activates based on the Tier.
Slide Structure
Slide 1: Crisis Response Plan — Overview
- Effective date and version
- Crisis response team members and roles
- Plan review and update schedule
- How to activate this plan (who calls the crisis lead and how)
Slide 2: Crisis Response Team
Define roles and accountabilities. Common structure:
| Role | Accountable For | Backup | |---|---|---| | Crisis Lead (typically CEO or COO) | Final decisions, executive communications | [Backup name] | | Communications Lead | All external messaging, media relations | [Backup name] | | Legal Lead | Regulatory notifications, legal liability assessment | [Backup name] | | Operations Lead | Incident containment and remediation | [Backup name] | | HR Lead | Employee communications and safety | [Backup name] | | IT Lead | Cybersecurity incidents, system restoration | [Backup name] |
The crisis team should be small enough to make decisions quickly. Every additional stakeholder in the core group slows response time.
Slide 3: First 30 Minutes
The actions taken in the first 30 minutes determine the entire arc of a crisis response. Make them procedural.
- Incident reported to [specific role/channel]
- Tier classification completed by [Crisis Lead and Communications Lead]
- Crisis team assembled via [communication channel — dedicated Slack channel, phone tree, etc.]
- Initial facts documented on the incident log
- Decision: proactive communication or hold pending more information
- Holding statement drafted (see communication templates)
- Regulatory notification assessment completed by [Legal Lead]
Slide 4: Communication Sequencing
Define the order in which stakeholders are informed. Getting this wrong — especially informing press before employees or regulators — causes significant secondary damage.
Typical sequence:
- Regulatory agencies (if required — timing often dictated by law)
- Board of Directors
- Employees
- Directly affected customers
- Partners and suppliers (if affected)
- Media (reactive or proactive depending on Tier)
- General public / social media
Slide 5: Spokesperson Guidelines
Define who is authorized to speak to the press, investors, regulators, and social media.
- Authorized spokespersons: [Names and roles]
- All other employees: Refer to [Communications Lead contact] — no independent responses to media or public inquiries
- Social media: Personal accounts should not address the crisis; direct followers to official channels
Include the single most important spokesperson principle: say what you know, acknowledge what you don't know, and commit to providing updates on a specific timeline. "We are investigating and will provide an update by [time]" is always appropriate. Speculation and minimization are not.
Slide 6: Communication Templates
Pre-drafted templates for the most likely crisis scenarios:
- Holding statement: "We are aware of [situation] and are investigating. We will provide an update by [time]. [Contact information for inquiries]."
- Customer notification (data breach): Structure per applicable breach notification laws — varies by jurisdiction
- Employee communication: What happened, what we are doing, what employees should do if they receive external inquiries
- Media statement: Facts known, actions taken, expression of appropriate accountability, commitment to transparency
Templates should be customized to the specific incident — they are starting points, not final documents.
Slide 7: Escalation Criteria
Define when to escalate from Tier 2 to Tier 3, and from a contained crisis to an existential one. Triggers might include:
- Media inquiry received (moves any Tier 2 to at least a heightened state)
- Regulatory inquiry or investigation initiated
- Litigation threatened or filed
- Social media viral spread beyond a defined threshold
- Executive team member named in the incident
Slide 8: Post-Crisis Review
Every crisis — regardless of outcome — should be reviewed within 30 days. The review covers:
- Timeline of the incident and response
- What worked in the response
- What failed or was delayed
- Gaps in the plan that were exposed
- Plan updates required based on findings
A crisis response plan that is never updated after real-world experience becomes stale and misleading.
Common Gaps in Crisis Response Plans
No Tier classification system. Without clear criteria for Tier 1 vs. Tier 3, every incident either gets over-escalated (burning out the crisis team on minor issues) or under-escalated (exposing the company to avoidable reputation damage).
No backup spokespersons. If the designated spokesperson is unavailable, unreachable, or themselves involved in the incident, the plan fails.
No regulatory notification procedures. Breach notification laws (GDPR, CCPA, HIPAA, SEC disclosure rules) have strict timelines. A plan that does not address regulatory notification will be scrambled when the legal team identifies the deadline.
Never rehearsed. A plan that has never been exercised in a tabletop simulation will not perform as written when real pressure hits. Tabletop exercises should be run at least annually.
Create your crisis response plan presentation with slide-deck.io. Build internal response documentation with role tables, communication templates, and escalation criteria — then distribute to your crisis team in a secure, accessible format.
Build your next presentation with AI
Generate editable .pptx decks in minutes. Free to start — no card required.
Try it free →