What this is, and where it stops
Crisis management and incident reporting are different products solving different problems, and
being sold one when you needed the other is a bad afternoon. Here is the split, plainly.
| The question | Answered by | Which product |
| Is this an incident or a crisis? Who do we convene? | Activation and severity matrix | This pack |
| Who may decide what, without waking someone up? | Pre-authorised decision rights | This pack |
| How do we tell clients, staff and the public? | Stakeholder matrix + 56 drafted messages | This pack |
| Is this incident major under Article 18? | The seven classification criteria | Free incident analyzer |
| What goes in the 4h / 72h / 1-month report? | The reporting technical standards | Incident Report Generator |
| How do we prove the plan works? | Exercise programme and after-action review | Crisis Exercise Programme |
| How mature are our arrangements? | 30-question assessment | Assessment toolkits |
The activation workbook tells
you when to start the Article 18 assessment and deliberately refuses to perform it. One
manual input starts the regulatory clock. That refusal is the boundary, made mechanical rather than
merely promised.
Decision rights, agreed cold
Delay in a crisis is almost never ignorance. It is uncertainty about who may decide. The
framework carries a table of pre-authorised decisions with monetary and duration limits, so the
response does not queue behind an approver who is asleep.
Criteria you can test, including for coming down
Four levels with propositions rather than adjectives, and: the part almost every template
omits: written de-escalation and stand-down criteria. Without them incidents stay nominally
open for weeks and nobody ever learns anything.
A log that survives the review
Options considered. Information known to be missing. What was not chosen, and why.
Those three columns are what turn a diary into evidence of reasonable judgement, and they are
the three always left out.
We do not ship the same file under two products, and we would rather tell you before you
buy than after.
Policy & Procedures Pack (€69)
It contains a crisis communication procedure. This pack does not replace it: it is the
operating annex that procedure assumes: the stakeholder register, the statement library,
the spokesperson Q&A and the decision log.
See the premium library →
Operational Resilience Assessment (€79)
Its last five questions told you your crisis arrangements have gaps. This is what closes them.
The assessment measures; this builds.
See the assessment toolkits →
Business Impact Analysis Toolkit (€149)
The BIA tells you which services matter and how fast they must come back. This pack tells you
what happens when one of them stops.
See the BIA Toolkit →
Is this certified against ISO 22361 or ISO 22320?
No, and nothing can be. Both are guidelines documents, not requirements standards. Neither
contains a conformity clause, so there is nothing for a certification body to audit against.
Some non-accredited providers advertise "ISO 22320 certification in seven days"; that
certificate is not recognised by any accreditation body and would not survive a supervisory
conversation. What a practitioner can do is follow the process the standards set out. That is
what this pack does, and "structured on" is meant literally.
Why one pack rather than one per standard?
Because the most valuable artefact in the whole line is the escalation ladder: the threshold at
which the operational incident commander hands up to the strategic crisis cell, what the cell
may decide that the commander may not, and how it hands back at stand-down. That artefact only
exists if both altitudes are in the same set. Split them and you have two halves of a broken
chain, and the break is exactly where real organisations fail.
Does DORA require a crisis management function?
Yes, for entities other than microenterprises. Article 11(7) requires one which, when the
ICT continuity or the response and recovery plans are activated, sets out clear procedures to
manage internal and external crisis communications in accordance with Article 14. What it
does not do is say how that function is staffed or separated: the segregation
duty in DORA is Article 6(4), and it concerns ICT risk management, control and internal
audit, not crisis management. The framework document therefore presents its separation of
roles as your own control choice rather than as a requirement, which is the distinction a
supervisor will care about.
Will this write our supervisory incident report?
No, deliberately. See the boundary table above. This pack decides whether you are in a crisis,
who commands and who must be told. The content of the initial, intermediate and final reports is
governed by the reporting technical standards and is a different product.
Does it tell us whether to pay a ransom?
No. That engages sanctions screening, law enforcement and legal counsel, and it is explicitly out
of scope. What the pack does is stop your spokesperson answering the question badly.
Do we need macros or a recent Excel?
Neither. No macros, and the formulas avoid dynamic arrays, so the workbook behaves identically in
LibreOffice Calc and older versions of Excel.