Corporate Crisis Media Response: Rapid-Response Intake & Clearance Protocol

1. Section 1: Incident Overview & Media Query Metadata

Capture the foundational incident details and media inquiry context to inform strategic response positioning and urgency triage.

 

Crisis Incident Reference ID

Primary Incident Classification

 

Data Breach Subtype (select all applicable)

 

Operational Disruption Root Cause

 

Describe Other Incident Classification

Incident Detection Timestamp

Media Query Received Timestamp

Media Outlet/Journalist Name

Journalist's Publication Reach & Influence Tier

Journalist's Response Deadline

Original Media Query Text (verbatim or summary)

Has the journalist indicated they are on deadline for breaking news?

 

Breaking News Deadline Countdown (hours/minutes remaining)

Crisis Severity Score (1=Minor, 5=Catastrophic)

Media Urgency Score (1=Routine Inquiry, 5=Immediate Publication Threat)

Current Narrative Control Status

Has the incident been referenced on social media or public forums?

 

Provide Social Media Intelligence Summary (platforms, reach, sentiment, key influencers)

Have internal stakeholders been formally notified?

 

Acknowledge that proceeding without internal notification increases reputational and legal risk

2. Section 2: Fact Verification & Technical Impact Assessment

Systematically verify incident facts, quantify operational impact, and assess stakeholder exposure to ensure statement accuracy and proportionality.

 

Fact Verification Matrix

Fact Statement

Verification Status

Verified By (Name/Role)

Verification Timestamp

Evidence Source/Methodology

A
B
C
D
E
1
Incident occurred as described
Unverified
TBD
 
Forensic analysis pending
2
Customer data was accessed
Partially Verified
CISO Team
6/15/2025, 2:30 PM
Server logs show anomalous queries
3
 
 
 
 
 
4
 
 
 
 
 
5
 
 
 
 
 
6
 
 
 
 
 
7
 
 
 
 
 
8
 
 
 
 
 
9
 
 
 
 
 
10
 
 
 
 
 

Are all critical facts verified and documented?

 

Document unverified elements and associated communication risks

Estimated Number of Affected External Stakeholders (customers, partners, public)

Estimated Number of Affected Internal Stakeholders (employees, contractors)

Categories of Affected Stakeholders (select all applicable)

Operational Impact Assessment by Business Function

No Impact

Minimal Impact

Moderate Impact

Severe Impact

Complete Disruption

Customer Service Operations

Core Product/Service Delivery

Financial Processing

Supply Chain Logistics

Employee Productivity

Brand Reputation

Has the incident resulted in quantifiable financial loss?

 

Estimated Financial Impact (USD)

Technical Root Cause Analysis Summary (non-technical language for PR use)

Is the technical root cause fully understood and remediated?

 

Acknowledge that public statement may require contingency language for unresolved technical issues

Containment Status

Expected Full Resolution Timestamp

3. Section 3: Proposed Public Statement & Q&A Talking Points

Develop and refine the public-facing narrative, ensuring alignment with verified facts, stakeholder expectations, and brand voice under crisis conditions.

 

Proposed Public Statement (Main Body)

Proposed Statement Tone & Voice

Key Message Pillars (3-5 core messages)

Does the statement include an explicit apology?

 

Legal Review Comment: Justify apology language and mitigate admission of liability risk

Does the statement include forward-looking commitments or promises?

 

Detail Specific Commitments Made and Associated Delivery Accountability

Anticipated Q&A Matrix

Potential Question

Approved Response

Response Confidence Level

Requires Legal Pre-Approval?

Escalation Contact for Follow-up

A
B
C
D
E
1
How many customers were affected?
We are finalizing our investigation and will communicate precise numbers within 48 hours.
Medium
Yes
Chief Privacy Officer
2
Who was responsible for the breach?
We are focused on remediation and prevention, not attribution at this time.
High
 
 
3
 
 
 
 
 
4
 
 
 
 
 
5
 
 
 
 
 
6
 
 
 
 
 
7
 
 
 
 
 
8
 
 
 
 
 
9
 
 
 
 
 
10
 
 
 
 
 

Recommended Distribution Channels

Proposed Statement Release Date/Time

Will this statement be part of a multi-phase communication strategy?

 

Outline Phase 2 and Phase 3 Communication Plan

4. Section 4: Legal Liability, Regulatory Disclosure & SEC/PR Alignment Audit

Conduct comprehensive legal and regulatory risk assessment to ensure public statements do not create unintended liability, violate disclosure obligations, or misalign with formal regulatory filings.

 

Legal Risk Assessment by Jurisdiction

No Risk

Low Risk

Medium Risk

High Risk

Critical Risk

Data Privacy Violation Risk

Securities Law Disclosure Risk

Contractual Breach Risk

Consumer Protection Risk

Employment Law Risk

Competitive Intelligence Leakage Risk

Does the incident trigger mandatory regulatory disclosure obligations?

 

Applicable Regulatory Frameworks (select all that may apply)

Is the company subject to public securities reporting requirements?

 

SEC/Equivalents Filing Coordination: Describe alignment with Form 8-K or equivalent material event disclosure requirements

Has a Material Adverse Effect (MAE) been triggered?

 

Detail MAE implications for ongoing M&A, financing, or contractual obligations

Does the proposed statement contain any forward-looking statements?

 

Draft Safe Harbor Language for Forward-Looking Statements

Could the statement be construed as admitting legal liability?

 

Legal Counsel Recommended Language Modifications to Mitigate Admission Risk

Have all statements been reviewed for privilege and work-product protection?

 

I confirm that this form and attachments may be subject to legal privilege and should be marked accordingly

Cross-Border Communication Considerations

Legal Hold & Preservation Orders: Status and Implications for Public Commentary

Are there pending or threatened lawsuits related to this incident?

 

Case Reference Number(s) and Preliminary Legal Strategy Impact on Public Statements

I confirm that the proposed statement aligns with all internal legal guidance and does not waive any legal defenses

5. Section 5: Chief Legal Counsel & VP of Global Communications Clearance Sign-Off

Final executive clearance and accountability documentation. All approvals must be secured before external release.

 

Has the VP of Global Communications reviewed and approved the final statement?

 

VP Global Communications Digital Signature

Has the Chief Legal Counsel reviewed and approved the final statement?

 

Chief Legal Counsel Digital Signature

Has the CEO or designated executive spokesperson been briefed and approved the statement?

 

Justify proceeding without executive spokesperson approval

Final Clearance Status

Final Clearance Timestamp

Does this require Board of Directors notification or approval?

 

Board Notification Status and Resolution

Post-Release Monitoring Plan (media tracking, stakeholder feedback loops, escalation triggers)

Is this statement cleared for immediate release?

 

Specify conditions for final clearance or escalation path

Crisis Response Team Lead Name & Role

24-Hour Contact Number for Post-Release Inquiries

I confirm that all required clearances have been obtained and the statement is approved for release according to corporate crisis communication protocol

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.