The Crisis Playbook You Write Before the Bad Day, Not During It
Synergised Consulting Ltd
Last Updated: 24 September 2026
A new owner should write the crisis playbook inside the first 100 days, not after the first bad day arrives: sort the plausible crises into severity classes, give every class one named owner, write down who is told what and in which order, and test the whole thing once in a tabletop exercise before day 100. Without those four decisions made in advance, the first real incident in the business you just bought is run by whoever happens to notice it first.
Why the First Response Is Improvised
In an acquired business, the response to a serious incident is improvised by default, because the previous owner held the playbook in their head and the sale transferred the problem, not the preparation. Serious incidents are common enough to plan for, yet formal incident response plans are rare at the smaller end of the market, which is exactly where a newly acquired firm sits until the new owner writes one.
The scale of the exposure is not marginal. According to DSIT's Cyber Security Breaches Survey 2025/2026, 43% of UK businesses identified a cyber security breach or attack in the last 12 months, roughly 612,000 businesses [1]. A new owner inherits email, payments, booking systems and vendor relationships whose behaviour under failure is completely unknown, and the same improvisation gap applies well beyond cyber incidents: a supplier collapse, a premises problem or the sudden loss of a key employee all demand the same thing, which is a decision made quickly by someone who knows they are allowed to make it.
The Gap Is Widest at the Smallest Sizes
According to the same DSIT release, only 25% of businesses have a formal incident response plan, and among micro businesses the figure falls to 21%, against 57% of medium and 76% of large businesses [1]. The Databarracks Data Health Check, a survey of around 500 UK organisations, found that 85% of polled organisations now hold a business continuity plan, up from 56% a decade ago, but only 58% of smaller organisations do [2]. Two independent surveys, one direction of travel: the small firm a first-time acquirer buys sits in the least prepared band by both measures, and the acquisition itself does not close that gap, because none of the paperwork in a deal includes a page describing what to do when the booking system dies on a Monday morning.
Sort Severity Before Anything Else
The first page of a crisis playbook is not a list of disasters, it is a sorting rule: which events stop the business serving customers outright, which degrade it or put trust at risk, and which are serious but survivable with a decision deferred. Three severity classes are usually enough for a small firm. The classification matters more than the scenario list, because it decides who is contacted, how fast, and with what authority, and once the classes are written the exotic scenarios mostly sort themselves.
Class | The test | The first hour belongs to |
|---|---|---|
1, revenue stopped | Customers cannot order, pay or be served | Restore service or switch to the fallback |
2, degraded or exposed | Service runs, but money, data or trust is at risk | Contain first, assess second |
3, serious but slow | The harm is real but not same-day | Diagnose without stopping the business |
A Worked Classification
This example is illustrative. Suppose you have bought a 20-person maintenance firm. On Monday the booking system will not start, and nobody can take jobs: class one, the first hour belongs to restoring service, and the fallback is a shared phone and a paper diary that nobody has checked still exists. On Wednesday a team member reports emails requesting a change to supplier bank details: class two, containment first, which means the account is frozen for changes until verified, not after someone checks whether it was genuine. On Friday the longest-serving engineer resigns, holding client relationships in his head: class three, genuinely serious, but the right first hour is a conversation and a handover plan, not an all-hands. Three events, three classes, three completely different correct responses, and the sorting rule decided each one before the day arrived.
The observation from our own discovery workshops is that the list of what matters gets built in the conversation, task by task through a normal week, and owners rarely arrive with it written down; which systems the business cannot serve customers without is exactly the kind of answer that lives in the owner's hands until someone makes it a document.
One Owner per Class, Decided Now
Every severity class needs one named owner decided in advance, because under stress a business defaults to whoever is loudest, most senior or simply nearest, and in a recently acquired firm that person is usually you. Naming the owner for each class, with a stated threshold for escalating to you, converts an improvised scramble into a routing decision made calmly months before the incident, by someone who is not standing in the middle of it.
What the Owner Actually Holds
The named owner holds three things for their class: the first action, written as a sentence a stressed person can follow; the spend authority, meaning a stated amount they may commit without asking anyone; and an escalation path to you with a response window, so silence has a meaning and a deadline. The pipeline we run Synergised's own content through taught us the same lesson from the other direction: it runs unattended on a schedule, so every run is built with a failure route that reports to a named person when it stops, because escalation has to be defined before the incident when there is nobody watching at the moment things break. A business that only escalates well during office hours has not written an escalation path, it has written a hope.
Write the Communication Path Before It Is Needed
The communication path decides who is told what, in which order, and who may speak to customers and suppliers, and it belongs in the playbook before any incident because it cannot be reconstructed mid-crisis. Internal first is the discipline. DSIT's survey found internal reporting was the most common response following a breach [1], and the reasoning generalises: staff who hear about an incident from a customer, or from rumour, learn in the same moment that the business does not control its own story. The path is short to write. One place where incident messages live so they do not scatter across personal inboxes, a plain briefing note for staff that states what happened, what is being done and what they should say if asked, and one named voice for customers and suppliers, with a holding statement drafted in advance for each severity class. None of that requires an incident to exist, and all of it is far harder to write during one.
Test It Once Before Day 100
An untested playbook is a document, not a control, and the test is deliberately cheap: sit the named owners down, read out one scenario per severity class, and record how long each class took to reach its first decision and its first communication. One tabletop exercise before day 100 exposes the missing phone numbers, the overlapping owners and the thresholds nobody can state, all of which cost nothing to fix on a Tuesday and are expensive to discover during the real thing.
The survey evidence says testing is where preparedness actually lives. In the Databarracks Data Health Check, nine in ten organisations had tested elements of their recovery process in the past year, and nine in ten of those that experienced a cyber attack said their recovery could have been more effective [2]. Testing is also not a large-firm luxury: DSIT's release records that the perceived cost of the most disruptive breach reached the 95th percentile at £4,000 for all businesses and £10,000 for medium and large ones [1], which means the expensive tail of a bad day arrives at small firms too, and rehearsal is how the first hour stops being spent discovering facts that should already have been written down.
What the First Test Looks Like
A single meeting, with only the named owners in the room. Read one scenario per class, time the first decision and the first communication in each, and write down everywhere the playbook was silent. The corrections go into the document the same day, each one dated, because dated corrections are what make it a maintained document rather than a decorative one. At day 100, run it again with a scenario nobody in the room has seen before.