पाठशाला Pathshala · संचालन Sanchālan, Operations · Lesson 28 · Scale

Crisis management: the first 48 hours

A breach, a regulator’s notice or a complaint that goes viral is judged on the first two days. Declare early, name one commander and one spokesperson, and work to the clocks the law has already started.

Pathshala, The Founder Library · 11 October 2026 · 7 min read

A lighthouse on a low coast beneath a dark storm cloud over the sea.
Photograph: Dāvis Šimanskis · Pexels

Companies are rarely remembered for the crisis itself. They are remembered for the first two days after it: whether they said something true quickly, whether customers heard it from them, and whether the person in charge looked as if someone was in charge.

This lesson is a plan for those two days, written for three crises a growing Indian company is likely to meet: a data breach, a notice from a regulator or tax authority, and a customer complaint that goes viral. It covers how to declare a crisis and who runs it, the legal clocks that start without asking, how each crisis differs, a checklist for the forty-eight hours, the spokesperson and the first statement, and the rehearsal that makes the plan usable.

Declare it, and name one commander

The most common failure is not a bad decision. It is the hours lost before anyone says that this is a crisis and that normal work stops. Google’s site reliability engineers, who have written down more about running incidents than most, give three tests in their chapter on managing incidents: does fixing it need a second team, is it visible to customers, and is it still unsolved after an hour of concentrated work? If any answer is yes, declare. Declaring early and standing down costs a few people an afternoon. Declaring late costs the clocks below.

Then separate the roles. The same chapter names four: an incident commander who holds the overall state and assigns work, an operations lead who is the only person changing systems, a communications lead who is the public face and sends regular updates, and a planning lead who handles the longer tail, from tracking changes to arranging handoffs. In a company of a hundred people these may be four people or two, but they must be named, and the commander keeps one live document with the facts, decisions and owners at the top. The founder is often more useful as the voice than as the commander, because the commander has to stay in the room and the voice has to be outside it.

The clocks that start without you

Several deadlines begin when the company notices the problem, not when it is ready. CERT-In: under the directions of 28 April 2022, service providers, intermediaries, data centres and body corporates must report the listed cyber incidents, which include data breaches, data leaks and unauthorised access to systems or data, within six hours of noticing them or being told of them; they must also keep logs for a rolling 180 days and have named a point of contact. The DPDP Rules: notified on 13 November 2025, they require a data fiduciary to inform the Data Protection Board of a personal data breach without undue delay and to send a detailed report within 72 hours, unless the Board allows more time on a written request; affected individuals must be told without delay in plain language. Those core obligations take effect on 13 May 2027.

The stakes are written into the Act. The government’s fact sheet on the rules sets out penalties of up to ₹250 crore for failing to maintain reasonable security safeguards and up to ₹200 crore for failing to notify the Board or affected people of a breach. A regulatory notice carries its own clock: the reply date printed on it, which is the one deadline in a crisis the company can often extend by asking early and in writing. A viral complaint has no legal clock at all, which makes it the easiest to mishandle: the deadline is set by how fast the story moves, and that is usually hours.

Make the clocks concrete. An engineer notices at 10 pm on a Friday that a storage bucket holding customer records has been publicly readable and that someone has downloaded from it. The CERT-In report is due by 4 am on Saturday, whoever is asleep. Once the DPDP Rules apply, the Board is told without undue delay that night or the next morning, and the detailed report is due by 10 pm on Monday. Affected customers are told as soon as the company knows who they are. Two more clocks usually sit in drawers: enterprise contracts that require notice of a breach within a set number of hours, and a cyber insurance policy that requires prompt notice for cover to hold. List both in the contract register now, because nobody will find them at midnight.

Three crises, played differently

The breach is an operations problem first and a communications problem second. Contain before you diagnose: revoke credentials, isolate affected systems, stop the leaking process, and preserve logs as you go, because the forensic account will be needed by regulators, customers and perhaps insurers. Do not promise in public what is not yet known; say what is known and when the next update comes. The [DPDP lesson](/library/dpdp-act-what-it-requires-of-your-product) covers the duties that make a breach expensive.

A heavy wave breaking against a lighthouse and sea wall on a stormy day.
The same storm hits a breach, a notice and a viral complaint differently. Know which one has arrived before deciding who answers it. Photograph: Ray Bilcliff · Pexels

The regulatory notice, whether from a tax authority, a sector regulator or a ministry, is a legal problem first. Read it the day it arrives; identify the provision invoked, the facts alleged, the documents asked for and the date. Instruct counsel that day. Reply on time, completely, and in writing, and keep a record of every submission. Most notices become worse through silence or through a hurried reply that admits more than the facts support.

The viral complaint is a trust problem first. Find out what actually happened before replying, but reply publicly within hours with what you know, and move the specific customer to a direct conversation with a named senior person. If the company was wrong, say so plainly and say what changes. If the facts are disputed, do not argue them in public; state the company’s account once, with care for the customer, and resolve the rest privately.

The spokesperson and the first statement

One person speaks for the company, and everyone else, including co-founders and investors, says nothing in public except to point to that person. The first statement follows a fixed shape: what happened, in plain words; what we know and what we do not yet know; what we have done so far; what affected people should do, if anything; when the next update will come. It does not speculate on cause, does not blame a vendor or an employee, and does not use the word incident when people have been harmed. Draft it in the incident document, have counsel read it in minutes rather than hours, and publish it where the affected people will see it first.

Order matters as much as words. Employees should hear from the founder before they read about it, because they will be asked. Affected customers should hear directly before the general public. The board and the largest investors should get a call, then a note. Regulators get what the law requires on time. The press gets the same statement as everyone else, and [telling the company’s story in public](/library/telling-the-companys-story-in-public) on the ordinary days makes this day easier.

In a crisis the company is judged less on what went wrong than on how quickly it said something true.

Keep a log of every public statement and every message to customers, with the time it went out, in the incident document. When a regulator, an auditor or a journalist later asks what the company said and when, the answer should take a minute to find, not a day to reconstruct.

After the forty-eight hours

The SRE chapter’s advice on handoff applies on day three: if the crisis continues, pass command explicitly to a rested person and tell everyone involved. Then write the review within a week, without blame, in the format the company uses for [written decisions](/library/writing-culture-decisions-in-documents): the timeline, what went well, what went badly, the root causes, and a list of fixes each with an owner and a date. Send customers and regulators the follow-up you promised. Track the fixes in the weekly review until they are closed.

Rehearse it twice a year

A plan read for the first time during a crisis is not a plan. Twice a year, run a two-hour tabletop: the leadership team receives a scenario, a breach on a Friday night, a notice with a fifteen-day reply date, a complaint trending by morning, and plays the first six hours against the checklist. Each quarter, check the contact sheet: the CERT-In point of contact, outside counsel, a forensic firm, the insurer, the board, and the person who can publish to the website and social accounts at midnight. Once a year, update the pre-drafted holding statements and confirm logging meets the 180-day rule. After every real incident, change the plan.


Reporting duties and dates were checked on 11 October 2026; the DPDP timeline may change. Nothing here is legal advice.

Sources

  1. CERT-In, Directions under section 70B of the Information Technology Act 2000, 28 April 2022: six-hour reporting, incident types including data breaches and leaks, 180-day logs, point of contact (checked 11 October 2026)
  2. Khaitan and Co, ERGO: Digital Personal Data Protection Rules, 15 November 2025: notified 13 November 2025, breach intimation to the Board and the 72-hour detailed report, core obligations from 13 May 2027
  3. Press Information Bureau, Digital Personal Data Protection Rules 2025: fact sheet, November 2025 (eighteen-month phased compliance; penalties of up to ₹250 crore and ₹200 crore)
  4. Google, Site Reliability Engineering, Managing Incidents (roles, the live incident document, clear handoff, when to declare)