Skip to content

105. Crisis Management

A crisis is a moment when the normal operating rhythm is no longer enough. Cash may be running out, the product may be down, a security issue may appear, a key person may leave, customers may churn, founders may fight, or fundraising may fail.

The founder’s job in a crisis is not to look fearless. It is to stabilize reality, communicate clearly, protect customers and people, preserve cash, and make the next right decision.

This chapter is practical orientation. For legal, security, employment, regulatory, or financial crises, bring in qualified professionals quickly.

The core crisis-management question is: what must be stabilized now, who owns each workstream, and how do we tell the truth without creating panic?

CrisisFirst question
Cash crisisHow many weeks of real runway remain if we stop pretending?
Product outageWhich customers are affected, what is the workaround, and who owns communication?
Security incidentWhat data, systems, users, and obligations are involved?
Founder conflictCan the founders still make decisions in the company’s interest?
Key employee exitWhat knowledge, customer trust, or execution risk leaves with them?
Customer churnIs this normal churn or a signal that value is breaking?
PR issueWhat is true, what is unverified, and who should speak?
Legal issueWhat must be preserved, disclosed, paused, or escalated?
Fundraising failureWhat plan lets the company survive without the expected round?

Different crises need different experts, but the founder pattern is similar: face facts, assign owners, communicate, and review.

The first hour of a crisis should create control, not perfection.

Use this sequence:

  1. Name the incident: give it a short label so everyone refers to the same thing.
  2. Assign one incident owner: not five people, not a committee.
  3. Create a source of truth: a doc, channel, or incident room where updates live.
  4. List known facts: separate facts from assumptions and rumors.
  5. Identify affected parties: customers, employees, vendors, investors, regulators, partners.
  6. Stop additional damage: pause risky actions, preserve evidence, protect customers, secure systems, or freeze spending.
  7. Set update cadence: decide when the next internal and external update will happen.

Do not try to solve every root cause in the first hour. Your first job is to prevent the crisis from expanding.

Not every problem is a crisis. Founders should classify severity quickly.

SeverityDescriptionFounder role
LowLocal issue with limited customer, cash, or team impact.Ensure owner and follow-up.
MediumImportant issue affecting customers, deadlines, or trust.Review response and communication.
HighSerious risk to revenue, security, runway, compliance, or team stability.Lead decision-making and communication.
ExistentialThreat to company survival, legal standing, customer trust, or founder control.Create war room, bring advisors, communicate frequently.

Severity can change. A small bug can become a trust crisis if communication is poor. A missed payment can become a payroll crisis if the founder delays cash action.

First, stop the bleeding.

  • Preserve cash.
  • Restore service.
  • Secure systems.
  • Pause risky actions.
  • Protect customers.
  • Keep the team safe.
  • Stop misinformation.

Do not begin with blame. Blame can wait. Stabilization cannot.

Stabilization depends on crisis type:

CrisisStabilize by
CashFreeze non-critical spend, verify collections, update runway, prepare options.
OutageRestore service, communicate impact, protect data, create workaround.
SecurityContain access, preserve logs, involve security/legal help, communicate carefully.
Founder conflictPause irreversible decisions, create decision protocol, involve trusted advisor or counsel.
Churn spikeSpeak to affected customers, identify pattern, protect renewals, assign recovery owners.
PR issueVerify facts, choose spokesperson, avoid speculation, prepare customer/team message.

Too many people in a crisis creates noise. Too few creates blind spots.

Define:

  • Incident owner.
  • Founder decision owner.
  • Customer communication owner.
  • Technical or operational owner.
  • Legal/security/finance advisor if needed.
  • Single source of truth.

Everyone should know where updates live and when the next update happens.

The war room should be small enough to act and broad enough to see reality. A typical setup:

RoleResponsibility
Incident ownerCoordinates workstreams and update cadence.
Founder decision ownerMakes tradeoffs and approves high-risk communication.
Customer ownerHandles customer segmentation, updates, and escalations.
Technical or operations ownerDiagnoses and fixes the underlying issue.
Finance/legal/security advisorGuides obligations and risk when relevant.
ScribeMaintains timeline, decisions, owners, and open questions.

The scribe role is underrated. In a crisis, accurate memory becomes a company asset.

Bad news does not improve by being hidden. Communicate with the right level of certainty.

Use:

  • What happened.
  • Who is affected.
  • What is known.
  • What is unknown.
  • What we are doing now.
  • What customers or employees should do.
  • When the next update will come.

Do not overpromise. Do not speculate. Do not disappear.

Use three levels of certainty:

  • Known: facts verified by the team.
  • Believed: strong working hypothesis, clearly labeled.
  • Unknown: questions still under investigation.

Saying “we do not know yet” is better than inventing confidence. Customers and employees can handle uncertainty if the company shows ownership and cadence.

In many startup crises, cash determines options. Update the cash view immediately:

  • Current bank balance.
  • Expected collections.
  • Must-pay obligations.
  • Payroll exposure.
  • Vendor exposure.
  • Tax/compliance obligations.
  • Runway under current burn.
  • Runway under emergency burn.

If you need to cut costs, do it with seriousness and humanity. Slow half-measures can create repeated trauma.

Cash crises deserve special attention because they reduce every other option.

When cash becomes tight:

  • Rebuild runway from bank balance, not old forecasts.
  • Separate committed expenses from optional expenses.
  • Confirm collections customer by customer.
  • Identify payments that cannot be missed: payroll, tax, statutory dues, critical infrastructure, legal obligations.
  • Freeze new hiring and discretionary spend until the plan is clear.
  • Model base, conservative, and emergency cases.
  • Decide whether the company needs revenue acceleration, cost reduction, bridge capital, sale, shutdown, or some combination.

Do not hide the cash reality from the leadership team. They cannot help manage the company if they are managing a fantasy.

If layoffs or salary delays become possible, get proper legal and HR advice. Handle people with dignity. A startup’s reputation is built not only in growth but in how it behaves under pressure.

In a crisis, memory becomes unreliable. Document major decisions:

  • Decision.
  • Owner.
  • Time.
  • Rationale.
  • Alternatives considered.
  • Expected outcome.
  • Follow-up.

This helps with learning, accountability, legal clarity, and team trust.

Document a timeline too:

  • When the first signal appeared.
  • When the team noticed.
  • When leadership was informed.
  • When customers or employees were informed.
  • What actions were taken and when.
  • When the issue stabilized.

The timeline reveals whether the company has a detection problem, escalation problem, decision problem, or execution problem.

After the crisis stabilizes, run a review:

  • What happened?
  • When did we first know?
  • What signals were missed?
  • What worked?
  • What failed?
  • What will we change?
  • Who owns the changes?

The point is learning, not theatre.

After-action reviews should produce changes:

  • Monitoring or dashboard changes.
  • New escalation rules.
  • Updated customer communication templates.
  • Cash controls.
  • Security or access improvements.
  • Product reliability work.
  • Hiring or ownership changes.
  • Legal, compliance, or documentation improvements.

If the review produces no owner and no date, the company has performed learning instead of learning.

Here is what happened. Here is what we know. Here is what we do not yet know. Here is who owns each workstream. Here is what changes for today. Here is when you will hear from us next.

We are aware of the issue affecting X. The impact is Y. We are working on Z. You can do A for now. We will update you by B. We are sorry for the disruption.

We are dealing with X. Current impact is Y. Immediate actions are Z. Cash/customer/team implications are A. We need help with B. Next update at C.

We are investigating a security/data issue involving X. We have taken Y containment steps. At this stage, we know Z and are still verifying A. We have engaged B support/advisors. We will update affected parties by C.

Only send this after legal/security review when required. Security communication must be accurate, careful, and timely.

We are tightening the operating plan because X changed. Current runway is Y under the updated plan. Immediate actions are Z. Payroll/customer commitments are being handled as follows. We will share the next update by A.

Do not use vague phrases like “market conditions” when the team needs operational truth.

The founder’s behavior sets the emotional temperature.

Helpful behavior:

  • Calm urgency.
  • Precise language.
  • Fast escalation.
  • Clear ownership.
  • Respect for facts.
  • Care for affected people.
  • Willingness to bring in experts.

Unhelpful behavior:

  • Disappearing.
  • Performing confidence.
  • Blaming.
  • Rage messaging.
  • Randomly changing priorities.
  • Talking to everyone privately and creating multiple realities.
  • Making promises before checking facts.

The founder does not need to be emotionless. The founder needs to be trustworthy.

In India, crisis management often includes additional trust and relationship dynamics. Customers may expect phone calls, WhatsApp updates, founder involvement, or local support. Employees may worry about family obligations if payroll is at risk. Vendors and customers may rely on personal relationships to resolve issues.

Use relationships responsibly. Do not hide behind them. A founder call can calm a customer, but only if the facts and follow-up are real.

For India-based companies, also pay attention to statutory, payroll, tax, data, and employment obligations. Informal handling can create long-term damage. If the issue touches compliance, employee exits, customer contracts, financial reporting, security, or regulated industries, get professional advice early.

Relationship-led communication is useful when paired with documentation. A phone call can calm the customer; a written follow-up creates shared memory. A WhatsApp update can move quickly; the official incident log should still be updated.

  • Hiding facts because the founder is embarrassed.
  • Waiting for perfect information before saying anything.
  • Having no owner.
  • Letting everyone create their own version of truth.
  • Making emotional decisions to feel in control.
  • Blaming people before stabilizing the issue.
  • Ignoring legal, security, or compliance obligations.
  • Failing to review after the crisis passes.
  • Letting the founder become the only source of truth.
  • Over-communicating emotion and under-communicating facts.
  • Solving symptoms while the root system remains unchanged.
  • Keeping the team in suspense because the founder wants to appear certain.
  • Continuing growth spending while cash reality has changed.

Prepare before you need it:

AreaPreparation
CashCurrent runway dashboard, emergency burn plan, collections view.
CustomersCustomer communication owner, support escalation rules, status page or update process.
SecurityAccess controls, incident contacts, log retention, backup and recovery basics.
Legal/complianceCounsel contact, company documents, contract repository, statutory calendar.
PeopleEmergency contact process, payroll visibility, sensitive communication plan.
ProductOn-call ownership, rollback process, known critical dependencies.
Investors/advisorsWho to call for bridge financing, hiring, legal, security, or PR help.

This is not pessimism. It is operational maturity.

In a crisis, memory becomes unreliable. People are tired, anxious, and moving quickly. Keep a simple decision log from the first hour.

TimeDecisionOwnerWhyEvidence usedWho was informedReview later
10:30Pause new deploymentsEngineering leadProduct outage still under investigationError rate, customer reportsTeam, supportDid pause help recovery?
11:00Inform top affected customersCustomer ownerCustomers are already noticing impactSupport tickets, account listAffected customersWas timing and message right?
12:00Freeze discretionary spendCEO/financeRunway risk increasedCash dashboard, pipeline viewLeadership teamWhich spend should restart?

The log should capture decisions, not every conversation. It helps with:

  • Avoiding contradictory instructions.
  • Showing customers and investors that the company acted responsibly.
  • Giving legal, security, finance, or board advisors a clean history.
  • Running a better after-action review.
  • Protecting the team from blame based on incomplete memory.

Keep the log in one place. In a product or security crisis, include timestamps, affected systems, customer impact, communication sent, and recovery actions. In a cash or people crisis, include cash assumptions, headcount decisions, legal advice sought, and communication timing.

After the crisis, review the log with two questions: which decisions were sound given what we knew then, and which operating system weakness made those decisions necessary?

Do not wait for a real crisis to discover that nobody knows who owns what. Run lightweight drills.

Quarterly drills:

DrillScenarioWhat to test
Cash drillExpected funding slips by three months.Runway dashboard, expense freeze, collections plan, communication plan.
Outage drillProduct is unusable for top customers for six hours.Incident owner, customer list, status updates, rollback process.
Security drillSuspicious access or data exposure is reported.Containment, access review, logs, legal/security escalation.
People drillKey leader resigns suddenly.Knowledge transfer, customer coverage, team communication, interim owner.
Churn drillThree important customers signal cancellation.Account plan, executive outreach, product diagnosis, renewal risk view.

Keep drills short. Thirty to sixty minutes is enough to expose missing owners, missing data, unclear communication, and weak escalation paths.

End every drill with:

  • What broke in the plan?
  • Which information was hard to find?
  • Which decision owner was unclear?
  • Which communication template is missing?
  • What will we fix this week?

Preparedness is not pessimism. It is respect for the company, customers, employees, and investors.

During a crisis, founders often communicate to whoever is loudest. Use a stakeholder map instead.

StakeholderWhat they needCommon mistake
CustomersImpact, workaround, timeline, ownership, next update.Waiting too long or using vague language.
EmployeesTruth, priorities, role clarity, emotional steadiness.Hiding facts and creating rumor.
LeadershipFull context, decision rights, owner map.Making them execute without real information.
Investors/advisorsSituation, impact, plan, asks, next update.Sending panic or only polished optimism.
Vendors/partnersOperational impact, payment or dependency updates.Letting side channels create confusion.
Legal/security/finance expertsFacts, timeline, documents, obligations.Asking too late after evidence or options are lost.

For each stakeholder, decide:

  • Who communicates?
  • What can be said now?
  • What must wait for verification or advice?
  • When is the next update?
  • Where is the record kept?

Different audiences can receive different levels of detail, but they should not receive conflicting truths.

Many crises eventually become cash crises. Install emergency cash controls before fear takes over.

Emergency controls can include:

  • Daily bank balance and collections review.
  • Pause on non-critical hiring, tools, travel, agencies, and experiments.
  • Approval threshold for new spend.
  • Customer-by-customer collections owner.
  • Vendor renegotiation list.
  • Scenario plan for base, downside, and survival cases.
  • Payroll, tax, statutory, infrastructure, and legal obligations marked separately.

The founder should know which expenses are truly optional, which are painful but possible to reduce, and which are dangerous to miss. Guessing during a cash crisis destroys options.

Use professional advice when payroll, statutory dues, employment actions, taxes, investor obligations, debt, or customer contracts are involved.

The after-action review should produce operating changes, not only insight.

Track:

FindingSystem changeOwnerDue dateProof complete
Customers were informed late.Create affected-customer list and update template.CS owner7 daysTemplate used in next drill.
Founder was only decision owner.Define severity levels and incident owner role.COO/founder10 daysIncident doc updated.
Cash runway was unclear.Weekly cash dashboard and collections view.Finance owner7 daysReviewed in leadership meeting.
Logs were hard to access.Improve retention and access process.Engineering owner14 daysTested in security drill.

A crisis should make the company more robust. If the same crisis pattern repeats, the first incident was not fully learned.

After a serious crisis, the founder often wants to rush back to normal. Do not skip recovery.

Review:

  • Which people carried unusual load?
  • Which customer relationships need repair?
  • Which team members need clarity or reassurance?
  • Which founder behaviors helped or hurt?
  • Which strategic assumptions changed?
  • Which work should pause because the team is depleted?

The founder also needs to process the crisis with a trusted advisor, coach, co-founder, or peer. Carrying unprocessed stress into the next operating cycle often creates overcorrection: micromanagement, avoidance, fear-based decisions, or fake optimism.

Calm recovery is part of leadership. The goal is not to pretend nothing happened. The goal is to convert the crisis into a stronger company.

Founders often lose time debating whether something is “really a crisis.” Define thresholds before emotions rise.

Example trigger thresholds:

AreaTriggerResponse
CashRunway drops below six months or expected fundraise slips by 30 days.Emergency runway review, hiring pause, collections plan, board/advisor update.
PayrollPayroll cannot be met with high confidence.Founder-led cash war room, legal/HR advice, immediate options review.
ProductCritical workflow unavailable for important customers.Incident owner, customer communication, rollback or workaround, postmortem.
SecurityPossible unauthorized access to customer or company data.Contain, preserve logs, involve security/legal help, communicate carefully.
CustomerTop customer or important cohort signals churn.Executive outreach, root-cause review, save plan, product/CS owner.
PeopleCo-founder or key leader conflict blocks decisions.Decision protocol, advisor/mediator/counsel input, written responsibilities.
ReputationPublic claim, complaint, or media issue can affect customer trust.Fact verification, spokesperson, holding statement, customer/internal note.

Thresholds reduce founder denial. They also prevent overreaction. The response is matched to the trigger.

A payroll crisis is one of the most serious founder moments. Employees make life decisions around salary. Families may depend on it. Handle it with speed, legal care, and humanity.

If payroll is at risk:

  1. Verify cash-in-bank, expected collections, and unavoidable obligations.
  2. Stop non-critical spend immediately.
  3. Identify all legal, statutory, tax, and employment obligations with proper advice.
  4. Create options: collections acceleration, founder bridge, investor bridge, cost reduction, sale, shutdown, or salary plan.
  5. Communicate with leadership before rumor fills the gap.
  6. Do not make promises you cannot meet.
  7. Document decisions and advice.

Avoid:

  • Telling employees “money is coming” when it is not committed.
  • Using delayed salary as an informal financing tool.
  • Paying selectively without advice and clear rationale.
  • Hiding statutory obligations.
  • Waiting until the payroll date to decide.

A cash crisis becomes a trust crisis when founders hide. Even painful truth is better than last-minute surprise.

Some crises damage trust even after the operational issue is fixed. Reputation repair needs its own plan.

Use three stages:

StageWork
AcknowledgeSay what happened, who was affected, and what you are doing.
RepairFix customer impact, compensate where appropriate, support employees, close obligations.
Prove changeShow the system change that prevents repeat failure.

Do not confuse apology with repair. Customers and employees judge the company by what changes after the apology.

  • Who was harmed or inconvenienced?
  • What promise did we break?
  • What will we do to make affected people whole?
  • What root cause allowed this?
  • What operating change proves we learned?
  • Who needs a personal founder call?
  • What should be written publicly, privately, or not at all?

In India, reputation often travels through private networks before it becomes public. A founder’s direct call to the right customer, employee, investor, or partner can matter. But the call must be backed by action.

The crisis system should evolve with the company.

Company sizeMinimum crisis system
Founders onlyOne founder owns incident, one owns communication, one doc tracks facts and decisions.
5-15 peopleNamed incident owner, customer owner, technical/ops owner, founder decision owner.
15-50 peopleSeverity levels, incident channel, communication templates, after-action tracker.
50+ peopleTrained incident leads, legal/security/finance escalation, customer segmentation, regular drills.

Do not wait until scale to create basics. The earliest version can be a one-page doc. What matters is that people know who decides, where facts live, and when the next update comes.

Pressure reveals ethics. Founders may be tempted to hide facts, blame juniors, delay salary truth, mislead customers, pressure vendors, or tell investors a cleaner story than reality allows.

Use an ethics check:

  • Would I be comfortable if the affected customer saw our internal reasoning?
  • Are we giving employees enough truth to make personal decisions?
  • Are we preserving evidence and records?
  • Are we shifting risk to someone who did not consent to carry it?
  • Are we using legal caution as an excuse for silence?
  • Are we protecting the company or protecting founder ego?

Ethical crisis management is not only moral. It is strategic. Trust lost during crisis is expensive to regain.

Run four drills per year, even if each is only 30 minutes.

QuarterDrill
Q1Cash and runway shock.
Q2Product outage or data/security incident.
Q3Key customer churn or public complaint.
Q4Key leader exit or founder conflict.

For each drill, test:

  • Who owns the incident?
  • Where is the source of truth?
  • What data is needed?
  • What message goes to customers, employees, and investors?
  • What expert help is required?
  • What decision must be made in the first hour?

Prepared companies still suffer crises. They suffer less confusion.

During a real crisis, do not run the company through scattered calls, chat threads, and emotional updates. Create a temporary command center with one source of truth.

The command center should include:

ElementPurpose
Incident ownerOne person accountable for coordination.
Decision ownerPerson who can make final tradeoffs. Often the founder/CEO.
Situation logWhat happened, when, current facts, unknowns.
Stakeholder mapEmployees, customers, investors, vendors, regulators/advisors, public.
Communication ownerPerson drafting and sending updates.
Expert ownerLegal, security, finance, technical, HR, or domain expert contact.
Action trackerOwner, action, deadline, status.
Next update timePrevents silence and repeated “any update?” interruptions.

Use this rhythm:

  1. Stabilize immediate harm.
  2. Establish facts and unknowns.
  3. Assign owners.
  4. Communicate what is known, what is being done, and when the next update will come.
  5. Keep a decision log.
  6. Close the incident only after customer, employee, finance, legal, and technical loose ends are checked.

Rules for the founder:

  • Do not speculate publicly.
  • Do not blame before facts are clear.
  • Do not let five people send five versions of the truth.
  • Do not delay all communication until every detail is known.
  • Do not make irreversible decisions while tired and emotionally flooded unless the delay is more dangerous.

A crisis command center is not bureaucracy. It is a way to reduce panic and preserve judgment when the company most needs judgment.

The general crisis pattern is stable, but founders need different first moves depending on the crisis. The mistake is treating every crisis as a generic “we need to work harder” problem. Cash, security, people, customers, and public trust each require different operating behavior.

A cash crisis becomes dangerous when founders keep using old forecasts after reality has changed.

First moves:

  • Rebuild runway from bank balance, not hope.
  • Confirm receivables customer by customer.
  • Freeze discretionary spend immediately.
  • Identify must-pay obligations: payroll, tax, statutory dues, critical vendors, hosting, legal commitments.
  • Create three scenarios: base, conservative, emergency.
  • Decide whether the plan is revenue recovery, cost reduction, bridge funding, strategic sale, shutdown, or a combination.
  • Inform the leadership team enough to help.

Founder questions:

  • How many weeks of cash remain if no new money arrives?
  • Which payments cannot be missed without serious legal or trust damage?
  • What cost cuts create real runway, not symbolic savings?
  • Which customers can pay faster if asked directly and respectfully?
  • Which investor, lender, acquirer, or strategic partner should know early?

Do not hide payroll risk until the last moment. If employee livelihoods are at risk, get proper legal and HR advice and communicate with seriousness.

An outage is not only a technical event. It is a trust event.

First moves:

  • Identify affected customers and severity.
  • Stop further damage.
  • Assign technical owner and customer communication owner.
  • Create an internal incident log.
  • Send customer updates on a fixed cadence.
  • Prepare workaround if possible.
  • After resolution, publish a plain-language explanation proportionate to customer impact.

Founder questions:

  • Which customers are affected most?
  • What can we say truthfully now?
  • When is the next update?
  • What customer commitments or SLAs are involved?
  • What engineering work prevents recurrence?

If the founder only asks “when will it be fixed?” the team may hide uncertainty. Ask for facts, options, customer impact, and next update time.

Security incidents need speed and discipline. Do not improvise publicly.

First moves:

  • Contain access or affected systems.
  • Preserve logs and evidence.
  • Bring in security and legal expertise quickly.
  • Identify data, users, systems, jurisdictions, and obligations.
  • Avoid speculation in writing.
  • Communicate internally on a need-to-know basis until facts are verified.
  • Prepare customer or regulatory communication with expert review when required.

Founder questions:

  • What data may be affected?
  • What is confirmed versus suspected?
  • What systems need containment?
  • What obligations may apply?
  • What must be preserved for investigation?
  • Who is authorized to speak?

Security is not an area for founder bravado. Move quickly, but with expert help.

Customer trust crises come from outages, missed promises, churn spikes, billing mistakes, implementation failures, or a founder overcommitting during sales.

First moves:

  • Segment affected customers by severity and revenue/risk.
  • Assign owners to high-risk accounts.
  • Write a truthful customer message.
  • Stop making new promises until the recovery plan is clear.
  • Identify the promise, process, or product gap that caused the issue.
  • Decide whether compensation, credit, extra support, or contract changes are appropriate.

Founder questions:

  • What did we promise?
  • Where did expectation and delivery diverge?
  • Which customers need founder-level outreach?
  • What are we changing so this does not repeat?
  • Are we trying to save revenue while ignoring broken value?

The founder should join high-trust conversations, but not become the entire recovery system. Customer trust is restored through ownership and follow-through, not only apology.

People crises are often delayed until they explode: co-founder disagreement, senior leader failure, harassment allegation, sudden resignation, culture breakdown, or repeated conflict between functions.

First moves:

  • Protect affected people and company obligations.
  • Separate facts from interpretations.
  • Involve HR/legal/advisor help when needed.
  • Stop gossip by defining who owns communication.
  • Avoid making emotional promises in private conversations.
  • Document decisions and follow-up.

Founder questions:

  • Is anyone unsafe, exposed, or unfairly treated?
  • What facts do we know?
  • What process is required legally and ethically?
  • What must be communicated to whom?
  • What decision are we avoiding because the relationship is uncomfortable?

Indian startups can under-handle people issues because relationships feel personal, early employees feel like family, and founders want harmony. But ambiguity is not kindness. Clear process protects people and the company.

Public criticism, social media complaints, customer accusations, employee posts, legal notices, press questions, or investor rumors can push founders into defensive communication.

First moves:

  • Verify facts before responding.
  • Decide whether a response is needed now.
  • Choose one spokesperson.
  • Avoid attacking customers, employees, or critics.
  • Prepare internal message before the team reads external speculation.
  • Keep records.
  • Get legal or communications advice if the risk is material.

Founder questions:

  • What is true?
  • What is unverified?
  • Who is affected?
  • Would silence create more harm?
  • Would a response increase attention without helping?
  • What can we say without violating privacy, law, or trust?

Do not confuse speed with posting. Sometimes the right first move is internal alignment and customer outreach, not a public statement.

After the crisis is no longer expanding, the founder has a second job: recovery.

Recovery has five layers:

LayerQuestion
Customer recoveryHave affected customers been made whole or given a clear path?
Team recoveryDoes the team understand what happened without blame theatre?
System recoveryWhat process, product, finance, security, or ownership change prevents recurrence?
Trust recoveryWho needs a follow-up from the founder or accountable owner?
Strategy recoveryDoes this crisis reveal a deeper business model, culture, product, or market issue?

Many founders stop after the fire is out. Good CEOs ask what the fire revealed.

The first 72 hours decide whether a crisis becomes contained, chaotic, or defining. Founders often lose those hours to panic, fragmented updates, private side calls, and premature explanations. Use a timeline.

The first job is to stop damage and create command.

ActionOutput
Confirm crisis typeCash, product, security, customer, people, legal, PR, founder conflict, or mixed
Assign incident commanderOne person owns coordination
Assign communication ownerOne person owns internal/external updates
Stop further damageContainment action
Start crisis logTimeline, decisions, facts, owners
Separate confirmed from unconfirmedFact list and unknown list
Set next update timeInternal cadence

Do not spend this window writing the perfect explanation. Create control first.

The second job is to understand enough to act.

AreaQuestions
ImpactWho or what is affected? Customers, cash, data, employees, legal obligations, public trust?
SeverityIs this existential, material, serious, or contained?
ObligationsAre there contract, payroll, tax, regulatory, security, HR, or legal requirements?
OwnersWho owns technical, customer, finance, legal, people, and investor workstreams?
CommunicationWho needs an update before the next public or customer message?
DecisionsWhat must be decided now, today, this week?

Write a short crisis brief:

Situation:
Confirmed facts:
Unknowns:
Current impact:
Owners:
Immediate actions:
Next update:
Decision needed:

By now the company needs a working plan.

Actions:

  • Send internal update with facts, owners, and escalation rules.
  • Communicate with affected customers if needed.
  • Inform investors/advisors if the crisis is material.
  • Get legal, security, HR, finance, or PR help where relevant.
  • Freeze non-critical work if focus is needed.
  • Decide what the founder personally owns and what must be delegated.
  • Update the crisis log after every major decision.

The founder should avoid two opposite mistakes: disappearing into private worry or joining every workstream. The CEO’s role is to maintain truth, priorities, communication, and decision quality.

24-72 Hours: Move From Firefighting To Recovery

Section titled “24-72 Hours: Move From Firefighting To Recovery”

After the first day, ask whether the crisis is still expanding.

If still expandingIf stabilizing
Increase cadence, bring stronger help, simplify priorities, preserve cash/trust.Begin recovery plan, customer follow-up, team debrief, root-cause review.

By hour 72, the company should have:

  • A clear owner for every workstream.
  • A current impact assessment.
  • A communication cadence.
  • A recovery plan or next decision date.
  • A list of customers, employees, investors, vendors, or family stakeholders needing follow-up.
  • A first view of what system failed.

Keep a command log from the beginning.

TimeFact/decisionOwnerNext actionUpdate due

The log protects memory. It also helps later if there are customer, investor, legal, security, insurance, or employee questions.

  • Do not send angry messages.
  • Do not speculate publicly.
  • Do not hide material facts from people who need them to act.
  • Do not make every update sound final.
  • Do not let WhatsApp become the only crisis record.
  • Do not promise timelines without owner confidence.
  • Do not punish the messenger who brings bad news early.

Crisis leadership is not calm theatre. It is disciplined truth under pressure.

In a crisis, founders are tempted to calm people by promising too much: exact timelines, root causes, refunds, product changes, security conclusions, hiring changes, or future guarantees. Overpromising may reduce anxiety for one hour and damage trust for months.

Control promises with this table:

Promise typeSafe version
Timeline”We will update you by 6 PM” instead of “It will be fixed by 6 PM” unless verified.
Root cause”We are investigating” until facts are confirmed.
Customer impactState known impact and what is still being checked.
Refund/creditExplain review process before committing commercial terms.
Security/dataDo not guess. Use verified facts and advisor/security input.
Product fixCommit to owner and review, not instant roadmap promises.
People actionAvoid blaming individuals publicly; communicate process and accountability.

Use this rule:

In crisis, promise the next truthful update before promising the final outcome.

Customers, employees, and investors can handle uncertainty better than they can handle false certainty. The founder’s job is to reduce chaos without inventing facts.

A crisis is not over when the immediate fire is out. It is over when trust is repaired, systems are changed, and owners are accountable for follow-through. Many startups survive the first crisis and then lose credibility because the recovery work drifts.

Create a recovery owner map:

Recovery areaOwnerOutputDue date
Customer follow-upCustomer-specific communication, credits, success plan, churn risk review.
Team follow-upInternal note, Q&A, morale/support actions, workload reset.
Investor/advisor follow-upFacts, impact, corrective action, ask if needed.
Product/technical fixRoot-cause fix, monitoring, release plan, incident prevention.
Process fixNew checklist, escalation rule, owner, drill, or control.
Legal/finance/complianceRequired notices, documentation, cash/legal impact review.

Run a recovery review:

Crisis:
Current status:
Who is still affected:
What trust repair is needed:
What system failed:
What must change:
Owner for each change:
Communication still owed:
Review date:

Use this rule:

Do not close the crisis until every external promise and internal system fix has an owner and date.

The visible crisis may end quickly. The trust crisis ends later. Founders earn credibility by finishing the recovery work after the drama fades.

Create a one-page crisis plan before you need it. Include emergency contacts, incident owner, customer communication owner, investor communication owner, legal/security/finance advisors, cash dashboard location, and where crisis decisions will be documented.

Then run a 30-minute tabletop exercise: pretend your top customer churns, payroll is at risk, or the product is down for six hours. Walk through who owns what, what you would say, what data you would need, and where the plan breaks.