Crisis Communications Protocol
Structured crisis communications framework ensuring measured, accurate, and compliance-aware responses to institutional incidents.
Crisis Level Classification
Routine Incident
Minor operational disruption with no external impact. Handled through standard operating procedures with Communications Office notification.
Elevated Incident
Operational disruption with potential external visibility. Requires Communications Office coordination and leadership awareness.
Significant Incident
Material incident affecting stakeholders, customers, or public safety. Requires executive-level response and controlled external communications.
Critical Incident
Major incident with potential regulatory, safety, or institutional consequences. Full crisis response activation including board notification and regulatory engagement.
Response Phases
Phase 1: Containment
Immediate incident containment and assessment. Activation of crisis response team. Communication hold on external channels until verification is complete.
Phase 2: Verification
Fact-finding and root cause assessment. Verification of incident scope, impact, and affected stakeholders. Coordination with relevant technical and legal teams.
Phase 3: Regulatory Notification
Required notifications to regulatory bodies as applicable (FAA, DoD, NASA, NIST). Notifications follow established reporting timelines and formats.
Phase 4: Customer Notification
Direct notification to affected customers, partners, and prime contractors. Notifications include verified facts, impact assessment, and remediation timeline.
Phase 5: Controlled Public Statement
Authorized public statement through designated spokesperson. Statement reviewed for accuracy, compliance, and export sensitivity before release.
Phase 6: Post-Incident Review
Formal post-incident review including root cause analysis, lessons learned, and corrective action implementation. Results integrated into ERM framework.
Specialized Response Protocols
Cybersecurity Incident Communication
Cybersecurity events follow NIST Cybersecurity Framework incident response guidelines. External communications are coordinated with security team and legal counsel. CUI exposure assessment conducted before any public disclosure.
Export-Control Event Communication
Incidents involving potential export control violations require immediate legal review. External communications are withheld pending ITAR/EAR compliance assessment. Voluntary disclosures follow DDTC or BIS procedures as applicable.
Investor Notification Protocol
Material incidents that may affect institutional valuation or strategic direction are communicated to investors through established reporting channels. Notifications are factual, measured, and compliant with applicable disclosure requirements.
Media Engagement During Crisis
All media engagement during crisis events is coordinated exclusively through the Communications Office. Designated spokespersons provide authorized statements only. No employee is authorized to make independent media statements during crisis periods.
Root Cause & Lessons Learned
Every crisis event, regardless of severity level, concludes with a formal root cause analysis. Findings are integrated into the Enterprise Risk Management framework, Safety & Mission Assurance Charter, and institutional training programs.
Protocol Governance: This Crisis Communications Protocol is maintained under the Enterprise Risk Management framework and reviewed quarterly. Protocol activation is authorized by the Crisis Response Team Lead in coordination with executive leadership.