Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Business continuity resources»ISO 22361:2022 – Crisis Management Guidelines: a closer look (Page 6)
Business continuity resources

ISO 22361:2022 – Crisis Management Guidelines: a closer look

In November 2022 ISO released a new guidance standard, ISO 22361:2022, to provide a structured approach to crisis management. Here, Hilary Estall MBCI, IRCA BCMS Principal Auditor reviews ISO 22361.
October 30, 20239 Mins Read
Crisis management using ISO 22361

“Crisis? What crisis?” This phrase has been used in music titles and political books amongst other things. In this article, I take a look at the definition of ‘crisis’, its application and how ISO 22361 walks us through developing a structured approach to crisis management by applying a set of principles on which a crisis management framework can be developed.

Crisis management has been considered in previous ISO and BS documents, notably PD CEN/TS 17091:2018 and BS 11200:2014. ISO 22361:2022 supersedes both of these aforementioned documents, which have now been withdrawn. It has drawn on previous content, in particular from 17091:2018, applying existing methodologies but taking into consideration the broader perspective that many management system standards / guidance documents apply today. It is not the aim of this article to provide a gap analysis between the two documents and accepts that a number of elements overlap.

What’s the difference between a crisis and an incident?

The term ‘crisis’ is often muddled with ‘incident’. The number of crisis management plans I’ve been presented with, only to find they are in fact incident management plans, is alarming. Why are people, or their organizations, so quick to call an incident, a crisis? Are we all hard wired to have a fatalistic approach to life?

For clarification, here are the definitions of both ‘crisis’ and ‘incident’ according to ISO 22361.

A crisis is an “abnormal or extraordinary event or situation that threatens an organization or community and requires a strategic, adaptive and timely response in order to preserve its viability and integrity.”

Various notes follow this definition which include terms such as; “complexity, instability, uncertainty, capability, flexible and dynamic”. You get the picture.

An incident is an “event or situation that can be, or could lead to, a disruption, loss, emergency or crisis.”

The difference between an incident and a crisis is clear.

Another definition I want to include is crisis management because it has altered from 17091. It is now defined as “coordinated activities to lead, direct and control an organization with regard to crisis”. 17091 defines it as “development and application of the process, systems, and organizational capability to deal with crises”. This enhancement into leadership is seen throughout ISO 22361 and again, is a reflection of the shift in focus and expectation of management system standards.

Crisis management – context, core concepts and principles

ISO 22361 includes a helpful table defining the characteristics of both incidents and crises. The characteristics are broken down into; Predictability, Onset, Urgency and pressure, Impacts, Scrutiny by public, media and other interested parties and Manageability through established plans and procedures. The differences are clear and can be summarised as follows:

Incidents are generally more predictable, provide little or no notice of occurring as well as potentially being the result of a gradual failure. They tend to instil a high sense of urgency, rarely have long term impacts on an organization or render it defunct. If managed successfully, an incident is less likely to attract significant or long term attention. Existing plans and procedures are generally adequate to manage and curtail the long term impact of an incident.

Crises on the other hand are generally unique or rare events, may emerge from an incident as well as occur without prior warning, will always require urgent attention, can impact an entire organization thus potentially having a catastrophic and/or finite impact on it. Crises will undoubtedly attract significant interest and scrutiny from multiple parties and may prove beyond the reach of predefined plans and procedures.

Having, hopefully, clarified the differences between incidents and crises, from here on in, I will focus solely on crises and how to identify and manage them.

Crisis identification, response, and management

As well as strong leadership, responding to a crisis requires flexibility. Being able to consider and apply a response which may fall far outside a ‘normal’ reaction to a situation is critical. Decisiveness, a clear mind, as well as maintaining the organization’s strategic vision, are imperative. Decisions may need to be taken which have uncomfortable consequences but may still be the best solution, or have the least fallout, given the circumstance. Decisions need to be made quickly and with confidence and always based on solid information and situational awareness. Individuals with a responsibility to respond and manage a crisis situation must be competent and have undergone suitable training to be able to endure the pressures of the crisis. The ability to respond to a crisis and obtain the best outcome should not be under estimated.
What might be the source of a crisis? It could;

  • Originate from within or outside the organization;
  • Be a purposeful act; malice, breach of safety regulation, spreading of miss-information;
  • Be politically motivated;
  • Result from action taken by a competitor or a takeover threat; or
  • Result from a previous incident not managed effectively or caused by an underlying, undiscovered issue.

A crisis may occur following one or more trigger points.

The Principles for crisis management have been clearly laid out for us in ISO 22361 and should be taken as being the bedrock of sound crisis management. They are fairly self-explanatory but come with brief commentary. In summary, they are:

  • Governance – the need for clearly understood structures, roles, responsibilities, and competence.
  • Strategy – Leadership, clear objectives, allocated resource.
  • Risk Management – requires an acute awareness of risk and ability to assess and respond appropriately.
  • Decision Making – based on sound information.
  • Communication – accurate, credible, and timely information to interested parties.
  • Ethics – response should be driven by an organization’s core values and ethical expectations.
  • Learning – exercise, training, and learning through experience.

Building a crisis management capability

Clause 5, is by far the most detailed section of ISO 22361. It focuses on the principles, framework, and process for building a crisis management capability.

When reading this section, the words previously used to describe the context, core concepts, and principles are seen again and I can’t help but feel there is an element of padding. That said, further ‘meat on the bones’ is generally considered a good thing if you are starting out in unfamiliar territory and I am sure many readers will find this section helpful. To emphasise my point some of the key phrases we see again are;

  • Strategic direction and core values
  • Objectives (what and how to be used to manage a crisis)
  • Roles, responsibilities, authorities and accountabilities
  • Risk awareness
  • Organizational awareness
  • Competence
  • Timeliness
  • Value awareness (ethics, sustainability and codes of conduct)
  • Information management (identify, filter, prioritize etc.)
  • Situational awareness.

Of particular value are the sections covering the Crisis Management Plan (5.3.4.2) and CMT Response (5.3.5.2) which provide the reader with clear guidance to follow in terms of what a Plan should include (and importantly, that it should NOT include specific scenarios), suggested composition of the CMT, (which is likely to be similar to an Incident Management Team i.e. Strategic decision makers and representatives from key business functions). Again, the bullet points for ‘Response’ focus on the need for situational awareness, applying a formulaic approach to meetings, information dissemination, and issuing communications that are easy to digest and follow.

Crisis leadership

Helpfully, we are reminded that organizational status does not automatically transfer into suitable crisis management skills. The need for confidence and to instil a stabilizing effect on those around are key. A comprehensive set of crisis management skills is set out in Figure 4, broken down into four skill sets;

  • Tasks
  • Interpersonal
  • Personal
  • Stakeholder Management.

Nothing too surprising here but by breaking it down it helps to reinforce the competencies and should be applied wherever possible to ensure the best fit. It should be the starting point in identifying suitable training, if required.

Thereafter, we have a list of responsibilities for a crisis leader. Helpful, in theory, and possibly a good starting point for a CM exercise, but how easy it is to keep an appointed leader in check during an unfolding crisis I’m not sure. It comes back round to the selection process. Of course it’s not just about the crisis leader. The CMT members all have an important part to play and the effects of a crisis on them must not be underestimated. Suitable support, including training, well-being, fatigue management, and psychological support need to be available and should be extended beyond immediate responders, as required.

Strategic crisis decision-making

This is a particularly useful section when trying to understand what’s behind someone’s ability to make critical decisions in a timely manner whilst trying to avoid a bad outcome. It may be that such a decision doesn’t exist and the best decision available will still lead to a bad outcome, just not the worst outcome.

I won’t try to paraphrase Clause 7 as it’s worthy of your full attention. Needless to say, strategic decision-making should form a significant part of any exercise, crisis management training and learning lessons from real life crises.

Crisis communication

Not surprisingly, this clause contains an assessment of what good crisis communication should look like. We’re used to seeing requirements such as holding statements, approved media channels, and media relations and spokespeople in incident and business continuity management requirements. These are similarly described here, along with other useful pointers such as crisis communication flow, adopting clear and consistent messaging, and identifying barriers to effective communication (avoidable if you develop a good communication strategy).

There is a reminder that use of social media and the opportunities and threats it presents to an organization should, wherever possible, be used to its advantage.

Preparation and practice of crisis communication plans is key. We know one wrong word, sentence, or inflection can cause untold harm.

Training, validation and learning from crises

As well as providing a list of skills crisis team members should be trained in, the most telling statement in this section (in my opinion) is “the strategic crisis management training provided by the organization should address the ability to improvise, innovate and should be flexible when a situation is not addressed by current plans.”

Human instinct is to follow procedures and known paths. We are not easily manipulated and practising these skills, through training, exercising or other means, will be vital to a successful outcome.

The author

Hilary Estall MBCI, IRCA BCMS Principal Auditor is a business continuity practitioner and seasoned management system standard professional. Hilary is a member of the BSI (UK) Technical Committee responsible for input into ISO 22301 and other, business continuity and resilience related management system standards and guidance documents, including ISO 22361. https://pslinfo.co.uk/

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleRansomware trends: changes in approach are leading to greater potential for reputational damage
Next Article Cloud concentration is now a significant emerging risk says Gartner

Related Posts

DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Three wheels with the same design but three distinct colours - blue, red, and green.

The silo problem: why resilience disciplines keep reinventing each other’s wheels

August 26, 2026
A female network operator wearing a headset sits at a desk facing three large computer monitors. The screens display a global network map, an IT infrastructure diagram with a red warning, and a system status dashboard showing a network outage alert.

Business continuity and operational resilience: why both are only as strong as the infrastructure behind them

August 20, 2026
Rear view of a large container ship being discharged by massive orange quay cranes at a port terminal during sunset.

Strengthening supply chain resilience: how business continuity professionals can support procurement teams

August 20, 2026
DRI International presents its Awards of Excellence

The 2027 DRI Awards are now open for nominations

August 19, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Graphic showing a range of risks from green to red grades.

2026 update to the UK National Risk Register published

July 15, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?