For New Jersey businesses, crisis preparedness should be viewed as a legal and operational function, not simply an emergency-management exercise. A well-designed crisis response plan can help preserve evidence, protect confidential communications, meet reporting obligations, limit unnecessary exposure, and prevent an already difficult situation from becoming a larger legal problem.
Key Takeaways
- Build the crisis team before a crisis occurs. Identify the people responsible for legal, operational, communications, HR, IT, and executive decisions.
- Establish clear escalation procedures. Employees should know which incidents require immediate attention and who to notify.
- Preserve evidence and protect communications. Early steps involving document preservation, investigations, and notifying legal counsel can have significant consequences later.
- Understand reporting and insurance obligations. Regulatory deadlines, contractual requirements, and insurance notice provisions may apply quickly.
- Stress-test the plan. Hypothetical exercises can identify gaps in decision-making and communication before an actual crisis exposes them.
A serious crisis rarely arrives at a convenient time. A workplace accident, data breach, government investigation, executive misconduct allegation, cyberattack, or sudden regulatory issue can require an organization to make consequential decisions within hours, often before all the facts are known. The organizations that navigate these events most effectively are not necessarily those that avoid crises altogether. They are the ones that have already decided who will respond, who has authority to act, and how information will move when circumstances are changing quickly.
Start With a Designated Crisis Response Team
The first step is identifying the people who will take charge when a potentially significant event occurs. Depending on the organization, the team may include members of senior management, in-house counsel, outside counsel, human resources, information technology, communications, risk management, and security.
Not every crisis requires every team member. The objective is to establish a core group that can quickly assess the situation and bring in the appropriate personnel. The organization should also identify who has authority to make key decisions. During a crisis, uncertainty about who can authorize an investigation, engage outside vendors, notify regulators, communicate with employees, or issue a public statement can create costly delays. A written protocol should address these questions before the pressure is on.
Establish Legal Counsel’s Role Early
One of the most important decisions is determining when counsel should become involved. In some situations, the organization should contact counsel immediately. In others, management may initially address an operational issue without legal involvement. The organization’s plan should establish clear criteria for escalating an incident to counsel.
Counsel can help the organization evaluate legal obligations while the facts are still developing. Depending on the circumstances, that may include assessing regulatory reporting requirements, employment issues, contractual obligations, insurance coverage, evidence preservation, potential litigation, and communications with government agencies or third parties.
When an internal investigation may be necessary, involving counsel at the appropriate stage can also help the organization structure the investigation and determine how to handle communications and investigative materials. Attorney-client privilege and work-product protection are important considerations, but they should not be treated as automatic shields for everything generated during a crisis. How an investigation is structured and who is directing the work can matter.
Create a Clear Escalation Protocol
Employees cannot be expected to make sophisticated legal judgments in the middle of an emergency. They should, however, know when to escalate an incident.
Events That Require Immediate Escalation
A crisis protocol should identify events that require immediate escalation, such as:
- A serious workplace injury or fatality;
- A suspected data breach or significant cybersecurity incident;
- Allegations of executive or employee misconduct;
- A subpoena, search warrant, or regulatory inquiry;
- Threatened or filed litigation;
- A significant environmental incident;
- A product defect or safety issue;
- A material contractual dispute;
- Theft, fraud, or other suspected financial misconduct; and
- A significant incident likely to attract media or public attention.
The protocol should also establish practical reporting channels. Employees should know whom to contact, what information to provide, and what not to do, such as deleting files, conducting an informal investigation, making public statements, or communicating with regulators without authorization.
Protect Evidence Before It Disappears
One of the most common mistakes organizations make during a crisis is focusing on what happened without first considering what evidence must be preserved.
Electronic evidence can disappear quickly. Emails may be deleted, surveillance footage may be overwritten, text messages may be lost, and employees may continue using devices that contain potentially relevant information. A crisis response plan should therefore include procedures for issuing litigation holds or other preservation instructions when appropriate.
Preservation should be proportionate to the circumstances, but the organization should err on the side of identifying potentially relevant information early. IT personnel and outside vendors may need specific instructions regarding backups, cloud systems, messaging platforms, access logs, security footage, and employee devices. The legal team should also consider whether to suspend normal document-retention practices for particular information.
Control Communications
During a crisis, an organization can create significant problems by communicating too much, too little, or inconsistently. Accordingly, the crisis response plan should designate who is authorized to communicate with employees, customers, regulators, the media, insurers, business partners, and other outside parties. Employees should understand that an instinct to “explain what happened” can create problems if information is incomplete or inaccurate.
Internal communications require the same attention. Organizations should discourage speculation and remind employees to preserve relevant information. At the same time, employees need enough information to continue operating safely and appropriately. A communications plan should also account for social media. An employee’s personal post can attract attention to an incident even when the organization has not made a public statement. Having a process for monitoring and responding to public communications can help the organization avoid reacting impulsively.
Know the Regulatory and Reporting Landscape
Crisis response is often complicated by overlapping legal obligations. Depending on the nature of an incident, a New Jersey business may have obligations under federal law, New Jersey law, industry-specific regulations, contractual provisions, or insurance policies.
For example, a cybersecurity incident may trigger notification obligations involving affected individuals, regulators, law enforcement, contractual counterparties, or other stakeholders. Under New Jersey’s data breach notification law, a business that experiences a breach of personal information must report it to the Division of State Police before notifying affected customers. A workplace incident may require consideration of federal or state workplace-safety requirements. An environmental event may implicate state and federal reporting requirements.
The response team should maintain a current list of the regulatory agencies, contractual contacts, insurers, and other parties that may need to be notified. The organization should not assume that the same notification timeline applies to every type of incident.
Coordinate With Insurance
Insurance carriers can play an important role in a crisis, especially when the organization may face significant defense costs, property damage, business interruption, cyber losses, or third-party claims. Organizations should know what insurance policies they maintain and understand the basic notice requirements under those policies. Depending on the circumstances, coverage may involve commercial general liability, directors and officers liability, employment practices liability, cyber insurance, property coverage, or other specialized policies.
The crisis plan should also identify who is responsible for notifying the appropriate carrier or broker and should account for policy requirements concerning consent to defense counsel, settlements, remediation expenses, and other costs.
Conduct a Tabletop Exercise
A crisis plan sitting in a binder, or buried in a shared drive, is unlikely to be effective when an actual emergency occurs. Organizations should periodically test their plans. The exercise does not need to replicate every possible crisis. A hypothetical scenario can expose gaps in decision-making authority, communication channels, vendor relationships, data preservation, insurance procedures, and regulatory response.
Sample Scenario: A Friday Afternoon Ransomware Attack
Management might be given a scenario involving a ransomware attack that occurs late on a Friday afternoon. The exercise can then test basic questions:
- Who is contacted first?
- Who has authority to shut down systems?
- When is outside counsel engaged?
- Who contacts the insurer?
- Who communicates with employees?
- What information must be preserved?
- What happens if the incident becomes public?
The objective is not to produce a perfect response. It is to identify weaknesses while there is still time to fix them.
Review the Plan After Every Significant Incident
Crisis preparedness should be an ongoing process. Laws and regulations change, employees change roles, vendors change, technology changes, and organizations restructure. A plan that worked two years ago may no longer reflect how the business operates.
After a significant incident, the organization should conduct a post-event review. What worked? Where did decisions stall? Were the right people involved? Did employees understand their responsibilities? Were there unexpected legal or contractual obligations? The organization should incorporate those lessons into the plan rather than discuss them and forget them.
Frequently Asked Questions
What is a crisis response plan?
A crisis response plan is a written framework that establishes who will respond to a significant incident, who has authority to make key decisions, and how information will be communicated, preserved, and reported. For New Jersey businesses, it functions as both a legal and an operational tool.
Who should be on a crisis response team?
Depending on the organization, the team may include senior management, in-house counsel, outside counsel, human resources, information technology, communications, risk management, and security. The goal is a core group that can quickly assess a situation and bring in the right people.
When should a business involve legal counsel in a crisis?
Some incidents, such as a data breach, a subpoena, or allegations of executive misconduct, may call for contacting counsel immediately. The crisis response plan should set clear criteria for when to escalate an incident to counsel, so the decision is not made under pressure.
Does attorney-client privilege protect everything created during a crisis?
No. Attorney-client privilege and work-product protection are important, but they are not automatic shields. How an internal investigation is structured and who directs the work can affect whether materials are protected.
What is a tabletop exercise?
A tabletop exercise is a hypothetical crisis scenario that management works through to test the organization’s plan. It can reveal gaps in decision-making authority, communication channels, evidence preservation, insurance procedures, and regulatory response before a real incident does.
How often should a crisis response plan be updated?
Review a plan regularly and after every significant incident. Changes in laws, personnel, vendors, technology, and corporate structure can make an older plan outdated.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.
[View Source]