Incident vs Crisis

What’s the difference between an incident and a crisis?

Not every incident/event is a crisis, but it can have the potential to become a crisis if not handled appropriately.

For example, a stolen laptop that is quickly excluded from connecting to the network would be classified as an incident. 

If the laptop were to be used to connect to the network and steal personal customer data you could very quickly be in “crisis mode” and dealing with a very damaging event in public.

CEN / TS 17091 defines a crisis as an “unprecedented or extraordinary event or situation that threatens an organization and requires a strategic, adaptive, and timely response in order to preserve its viability and integrity”.

The standard includes a section on principles for crisis management which serve as a good guide for the management of any incident that has the potential to become a crisis. 

They are:

  1. a) seek understanding of the situation.
  2. b) achieve control as soon as possible.
  3. c) communicate effectively, both internally and externally.
  4. d) be prepared with clear, universally understood structures, roles, and responsibilities.
  5. e) build situational awareness through good information management and coordinated working.
  6. f) have a clear and well-rehearsed decision-making and action-driving process in line with the core values and objectives of the organization.
  7. g) implement effective leadership at all levels of the organization.
  8. h) ensure people with specific crisis management roles are competent through appropriate training, exercising, and evaluation of their knowledge, skills, and experience.

 

Incident Management starts well before an incident occurs. You need to consider what types of incidents are likely to occur and develop “trigger criteria” which if met will mean specific plans to address that type of incident are invoked.

 

Summary

Hopefully you now have a better understanding of the key differences between an incident and a crisis, and the potential impacts of both on your business.

To find out more about incident management and how best to prepare yourselves in the event of crises, request a copy of our free White paper on Risk Management and Operational Resilience.

Recent News

6 things you need to know about the Individual Accountability Framework (IAF)

The Central Bank of Ireland has recently released regulations and guidance on the Individual Accountability Framework (IAF). Here ...
Read More

Paysend chooses CalQRisk as their Risk Management Solution

Paysend, a next generation integrated global payment ecosystem, has recently implemented the CalQRisk solution in order to enhance ...
Read More

ESG and Sustainability Reporting

The practice of businesses promoting sustainability and social responsibility in their operations can be traced back to the ...
Read More

CalQRisk Wins Best RegTech Solution at National Fintech Awards

CalQRisk, a leading provider of Governance, Risk & Compliance solutions has won the ‘Best Regtech Solution Award’ at ...
Read More

CalQRisk shortlisted in National Fintech Awards

The CalQRisk solution is shortlisted for ‘Best Regtech Solution Award’ at the inaugural National Fintech Awards. The National ...
Read More

CalQRisk shortlisted in 2023 CIR Risk Awards

Having won ‘Risk Management Product of the Year’ at the 2022 CIR Risk Management Awards, CalQRisk is now ...
Read More

From Risk Capacity to Risk Appetite

Risk Capacity is the maximum amount of risk that an organisation is technically able to assume before breaching ...
Read More

SMT automates their approach to Risk Management with CalQRisk

SuMi TRUST Global Asset Services (“SMT”), a subsidiary of Sumitomo Mitsui Trust Bank Limited, one of the largest ...
Read More

Digital Operational Resilience for the Financial Sector Act (DORA)

The Digital Operational Resilience Act (DORA) entered into force on 16th  January 2023. It outlines EU regulations for information ...
Read More
Database

8 Things to Consider in a Data Breach Response

A data breach can lead to reputational damage, financial losses and much more. By effectively preventing and investigating ...
Read More