Preparation is the only part of a crisis you can control, and the only part most organisations skip.
Most leaders assume they will know a crisis when they see one. The problem is timing. By the time something looks like a crisis, it has usually been one for hours, and the story has taken shape without you in it. Speed, not messaging, is now the hardest part of crisis communications, and it is the part most organisations have never prepared for.
This is the shift that matters for every board and leadership team in Australia. Crisis communications has moved from something organisations reach for after an incident to something they need in place before one. For small and medium businesses, government teams and not-for-profits alike, it has become core business rather than an optional extra.
Social media does not just report a crisis. It shapes it.
A crisis used to come with a buffer. A problem surfaced, a few journalists called, and you had the rest of the day to establish the facts before it reached the evening news. That buffer has gone. Information moves in real time, and so does public judgement. A complaint, a leaked email or a data breach can be posted, screenshotted and shared thousands of times before an organisation has confirmed internally what happened. The first version of any story is now written by the people watching it unfold, not by the organisation at the centre of it. As Australian communications director Candice Gersun observed after the Qantas breach, “silence or delay creates a vacuum that fuels speculation, misinformation and reputational damage.” When a business stays quiet while it works out what to say, that silence rarely reads as caution. It reads as either incompetence or concealment.
The financial evidence is hard to ignore. Sydney reputation consultancy SenateSHJ analysed more than 300 corporate crises worldwide over 40 years and found that share prices fell by an average of 35.2 per cent after a crisis, earnings per share dropped by an average of 68.6 per cent, and companies took roughly 425 days on average to recover to pre-crisis levels. Close to a third had still not recovered. The lesson underneath those numbers is simple. Trust is expensive to build and quick to lose, and the speed at which it can now be lost has outpaced the way most organisations are set up to respond.
The privacy breach has become the most common crisis of all
If you want to know where a crisis is most likely to start, the data points to your systems. The Office of the Australian Information Commissioner received 1,205 data breach notifications in 2025, the highest number since the Notifiable Data Breaches scheme began in 2018 and an eight per cent increase on the previous year. Most were the result of malicious or criminal activity, and health service providers were the most commonly affected sector. Public concern has climbed with the numbers. Data breaches are now the top privacy concern for Australians, with worry rising from 74 per cent in 2023 to 82 per cent in 2026.
The Qantas breach of 2025 shows both the exposure and the response. In late June, an attacker used a social engineering phone call to trick an offshore contact centre agent into granting access to a third-party customer database, exposing the personal details of around 5.7 million customers. Most of the exposed records held names and contact details, a smaller group also included dates of birth and addresses, and no financial, passport or password information was taken. What Qantas did next is the instructive part. It moved quickly, told affected customers directly what data of theirs was involved, stood up a dedicated support line, reported the incident to the national cyber authorities and the privacy regulator, and went to court to restrain the stolen data from being shared. When the Office of the Australian Information Commissioner completed its inquiry in July 2026, it decided not to pursue a formal investigation, finding that Qantas had taken reasonable steps and could not have reasonably foreseen or prevented an attack of that kind. The regulator was careful to say this was not an endorsement of the company, and separate complaints are still being dealt with. Even so, a fast and transparent response left Qantas largely in control of its own story. Contrast that with a slower, more defensive posture. When Medibank was breached in 2022, its shares fell around 15 per cent in a single day after a week-long trading halt.
This is not only a big-company problem
It would be easy to read those examples and assume crisis planning is for large corporations with the budget for it. The opposite is true, because smaller organisations are targeted precisely because they are less prepared. According to IDCARE, which delivers the Australian Government’s Small Business Cyber Resilience Service, 74 per cent of small businesses have no data breach response plan, and 78 per cent of those that sought help had experienced unauthorised access to their Facebook accounts. Small businesses also take around 20 per cent longer than individuals to respond to an incident, which gives an attacker more time to do damage. The Australian Signals Directorate records a cybercrime report every six minutes, with the average cost to a small business rising to $56,600 in 2024 to 2025. For a not-for-profit running on tight margins and public trust, a mishandled breach is not a line item. It is an existential threat.
Where to start before anything goes wrong
The organisations that come through a crisis with their reputation intact are almost always the ones that did the quiet work beforehand. Preparation is not glamorous, but it is the difference between a manageable event and lasting damage. A practical starting point looks like this.
- Identify what could realistically go wrong. Map the incidents most likely to hit your organisation, from a data breach to a funding scandal to a safety failure, and be honest about your weak points.
- Decide now who speaks and who decides. Agree your spokesperson, your approval chain and how the board is informed, so no one is inventing the structure while the phone rings.
- Write your holding statements in advance. Prepare approved first-response wording for your most likely scenarios. In the first hour you want to edit, not draft from nothing.
- Map your stakeholders and channels. Know who you must reach, in what order, and how, from staff and clients to regulators, funders and media.
- Understand your legal obligations. Know when the Notifiable Data Breaches scheme requires you to report, and to whom, before you are under pressure.
- Practise. Run a short scenario exercise once a year. A plan you have never tested is a document, not a capability.
Crisis communications is not about having the perfect words ready for the worst day. It is about building the judgement, structure and speed to protect the trust you have spent years earning. That work is planned, not improvised, and it is best done while the risk is still on the horizon.
Infodec Communications works with organisations across the SME, government and not-for-profit sectors to build crisis preparedness before it is needed, including risk audits, response protocols, holding-statement banks and spokesperson preparation. To talk through how your organisation would cope, book a conversation at Book a free 30-minute call
