Most crisis playbooks begin at the wrong moment, once something has already gone wrong. But the cases that compound rather than resolve tend to share a different feature: the first failure was not necessarily the decisive one. What mattered was what failed to change afterwards. A useful model therefore has to begin before the crisis exists, and it has to account for a distinctly newer problem too: fabricated evidence, rather than simply false claims.

Readiness is the strategy, not the response. Boeing’s 737 MAX offers the clearest illustration. Lion Air Flight 610 was lost in 2018 following a flight-control fault; five months later, Ethiopian Airlines Flight 302 crashed following the same unresolved problem. The second crash was not an entirely new crisis. It was the first crisis repeating itself. Readiness also means deciding how and when to disclose before the pressure arrives, rather than improvising under it. Uber’s 2016 data breach illustrates the cost of doing the opposite. Without an agreed disclosure policy, caution became concealment, and the company’s former security chief was later convicted of obstructing the resulting investigation.

Containment works best when it is narrow and verifiable. Johnson & Johnson’s 1982 Tylenol recall, in which 31 million bottles were withdrawn before regulators required the company to do so, remains a reference point for good reason. The response centred on specific, checkable information about what had happened and what consumers should do, rather than sweeping reassurances about the safety of the brand as a whole. The discipline mattered, and the company recovered its market position within roughly a year. But there is a genuine tension here that crisis models often smooth over: responding can itself give a story oxygen. Silence can sometimes limit amplification, while a response can make the story larger than it was. There is no universal rule for which instinct is right.

Whoever explains the mechanism first often sets the frame. Facebook’s initial response to the Cambridge Analytica affair, that this was not technically a data breach, was defensible in the narrow sense. Users had consented to the original app permissions. But that distinction quickly became irrelevant once the Guardian’s reporting gave the public a simpler account of what had happened and why it mattered. Facebook was not necessarily wrong about the technical point. It simply lost the argument about what the technical point meant. The framing established then persisted for years, culminating in the FTC’s eventual $5 billion settlement.

Some crises require an entirely different toolkit. The 2024 New Hampshire AI robocalls impersonating Biden were not simply false claims waiting to be rebutted. They were fabricated evidence: an artificial voice presented as something that could plausibly have been real, with no obvious way for the recipient to distinguish the two. The appropriate response was therefore regulatory as much as communicative. The FCC determined that AI-generated voices in robocalls fall within existing consumer-protection rules. The lesson is broader than the particular case. A crisis model needs to establish early whether it is dealing primarily with a rhetorical problem or an evidentiary one, because the two demand fundamentally different responses.

And the cost of failing to change compounds over time. Wells Fargo’s 2016 fake-accounts scandal did not end with the original misconduct being exposed. The consequences included a seven-year, $2.5 billion-a-year asset cap, which was lifted only in 2025 after regulators had verified sufficient change. The initial scandal was costly. Demonstrating that the underlying system had genuinely changed was, in its own way, an even longer exercise.

A more useful working model, then, is five-part and continuous: readiness established in advance; narrow and disciplined containment; a rapid, intelligible explanation before someone else’s framing fills the vacuum; an early judgement about whether the crisis is rhetorical or evidentiary; and verified structural change afterwards, rather than a temporary pause before the same pattern returns.

Most organisations are reasonably good at one or two of these. The more interesting question is whether they can sustain all five. The organisations that genuinely regain control tend to treat them not as separate crisis-management techniques, but as stages of the same discipline: prepare before the failure, contain what has happened, explain it clearly, recognise what kind of problem it actually is, and then change the system sufficiently that the next crisis is not simply the previous one in another form.