Every startup faces a crisis eventually — an outage, a security incident, a PR event, a key departure, a customer defection.
A crisis is any event that threatens the company's ability to keep operating normally: a major security incident, a multi-hour outage, a public PR event, a co-founder departure, a top-customer churn. Every growing company faces at least one per year. The pattern of companies that recover well versus companies that don't is not the severity of the crisis — it's the discipline of the first 72 hours: who leads, what gets communicated, and how honest that communication is.
Every crisis needs a single named person who is running the response — not necessarily the CEO, often not the most senior person, but the person best positioned to coordinate. Their job is to hold the timeline, keep decision-making moving, and prevent the parallel-committee failure mode where five people think they're leading and no one is. Everyone else in the company should know who this person is and defer to them on incident decisions.
The instinct in a crisis is to wait until you have complete information before communicating. This is almost always wrong. Customers, employees, and investors interpret silence as either incompetence or coverup. The pattern that works: initial acknowledgment within 1-2 hours ('we're aware, investigating, will update in X hours'), regular updates on a fixed cadence (every 2-4 hours during active response), post-incident writeup within a week. Say what you know, name what you don't yet know, and hit your update deadlines even if the update is 'still investigating.'
Specific playbook: contain first (revoke keys, rotate credentials, isolate affected systems), investigate second (forensics, scope of exposure), disclose third (regulatory notifications where required, customer notifications within legally-required windows, public disclosure appropriate to severity). Retain outside counsel and a specialized incident response firm on retainer before you need them — trying to onboard both mid-incident costs 24-48 hours you don't have. Never speculate publicly about attribution or impact before forensics are complete.
Whether it's an employee incident, a public accusation, or a product failure that got attention: the first move is understanding whether the underlying facts are true, partially true, or false, before deciding on response. Deny-then-discover-it-was-true is the second-worst outcome (worst is ignore-until-forced). Get the facts internally in 24-48 hours. If the facts are unfavorable: acknowledge, apologize, describe corrective action. If the facts are wrong: correct the record with specifics. Vague non-denials read as confirmation.
Every crisis produces a post-mortem: what happened, what response worked, what didn't, what changes we're making. Blameless format (focus on systems, not individuals). Circulated widely inside the company. Selected post-mortems (security, outage) circulated publicly — this builds trust rather than eroding it. Companies that skip post-mortems get the same crisis twice within 18 months, reliably.
Investor directory · Fundraising library · Articles A–Z · Company funding database