Work Related Concerns

.png)
Written by
Aarohi Parakh,
Psychologist and Content Writer

Reviewed by
Sanjana Sivaram,
Psychologist and Clinical Content Head

In March 2020, a mid-sized IT services company in Pune had no working-from-home policy, no remote access infrastructure, and no documented plan for what to do if their office became inaccessible. Within 72 hours of the first national lockdown announcement, their HR head was fielding 400 employee queries on a single WhatsApp number, coordinating laptop dispatches from the office while maintaining social distance, and managing client escalations over email from her living room floor.
They survived. But not because they had a plan. They survived because a handful of people made very good decisions under enormous pressure, without any framework to fall back on.
That is not crisis management. That is crisis improvisation. And the difference matters enormously.
Workplace crisis management is the structured, organisation-wide capability to prepare for, respond to, and recover from events that threaten operations, employee safety, or organisational reputation. In simple terms, it means having a clear process for deciding what to do, who takes charge, and how to keep people informed when normal operations are disrupted.
It is not a document you file away. It is a living capability that must be built, practised, and maintained.
This guide explains what crisis management means, the types of workplace crises Indian organisations may face, how to build a practical crisis management plan, and how HR can support employees before, during and after a crisis.
Crisis management is the structured, organisation-wide approach to anticipating, responding to, and recovering from events that threaten operations, employee safety, or organisational reputation.
So, what is crisis management in the workplace? It is the process of preparing an organisation to deal with unexpected events that create immediate instability, while protecting people, maintaining essential operations and managing stakeholder trust.
It is worth distinguishing this from risk management. Risk management happens before a threat materialises. It identifies vulnerabilities, maps probability and impact, and puts mitigation measures in place. Crisis management activates when a threat has already arrived. The two functions are complementary, not interchangeable.
In the workplace context, a crisis could be a ransomware attack that locks an organisation's systems at 9 am, a key executive departure announced over social media before the board is informed, a factory fire on the night shift, or a sexual harassment complaint that escalates into public media coverage. The common thread is urgency, uncertainty and consequence.
The crisis management meaning is therefore broader than emergency response alone. It includes preparedness, decision-making, communication, recovery and learning.
The stakes are significant. According to PwC's Global Crisis Survey, 69% of business leaders reported experiencing at least one significant crisis in the preceding five years, while 95% expected to face another. PwC research has also highlighted an integration gap, with only 23% of respondents saying their organisational resilience functions were very well integrated.
Indian organisations face a particularly layered risk environment. Monsoon-related disruptions, industrial accidents, rapid digital transformation creating cybersecurity exposure, and sector-specific regulatory requirements can create a complex mix of operational, legal and human challenges.
The organisations that manage crises best are not necessarily the ones that face fewer of them. They are the ones that prepare as if a crisis is possible, understand their vulnerabilities, and know how to respond when normal operations are disrupted.
Not all crises look alike. Understanding the range of crises relevant to Indian organisations is the first step towards building a response that is specific rather than generic.
A crisis may begin with a technology failure, a natural disaster, a workplace incident, a financial shock or a reputational issue. The right response depends on the nature of the event, its potential impact and the people or functions affected.
The following crisis management examples illustrate the main categories Indian organisations should consider when developing their crisis management plans.

A brief note on each category that deserves specific Indian context:
Cybersecurity and data breaches are not a distant threat for Indian organisations. Ransomware, phishing, unauthorised access and other cyber incidents can disrupt operations while creating financial, legal and reputational consequences.
India's digital data protection framework includes specific requirements relating to personal data breaches. Organisations should also consider separate cybersecurity incident reporting obligations, including applicable requirements under CERT-In directions. Because regulatory requirements and implementation timelines can change, organisations should verify the current requirements relevant to their sector and incident before relying on a crisis playbook.
For organisations handling significant volumes of personal data, a data breach response playbook should therefore cover containment, internal escalation, evidence preservation, stakeholder communication, legal review and applicable regulatory reporting.
Natural disasters are particularly relevant for manufacturing, logistics and businesses operating in regions vulnerable to flooding, cyclones or other extreme weather events. The Chennai floods of 2015 demonstrated how quickly infrastructure disruption can affect entire business districts, while disasters such as the 2023 Sikkim floods and landslides highlighted the vulnerability of regional supply chains.
For Indian organisations, crisis management planning should therefore consider not only employee evacuation and safety, but also alternative work locations, remote access, supplier dependencies, emergency communication and business continuity.
Labour and industrial crises remain a significant consideration for organisations operating in India's manufacturing and industrial hubs. Strikes, lockouts, workplace accidents and unresolved employee grievances can disrupt production and quickly become wider operational or reputational issues.
Clear communication, escalation protocols and defined decision-making responsibilities can help organisations respond before a localised issue becomes a wider business crisis.
POSH-related incidents that escalate into reputational crises represent a category that organisations should not underestimate. When a sexual harassment complaint is mishandled, delayed or communicated inappropriately, the issue may extend beyond the internal process and create wider consequences for employee trust and organisational reputation.
The response must balance confidentiality, due process, employee safety and legal compliance. A crisis management plan should therefore clearly establish who is responsible for escalation, communication and legal advice when a sensitive workplace complaint develops into a wider organisational crisis.
Financial crises can hit Indian MSMEs and startups particularly hard. Cash flow disruptions, investor withdrawal, sudden revenue loss or loss of a major client can move from a serious concern to an existential threat within weeks.
Business crisis management should therefore include financial contingency planning, access to emergency funding where appropriate, insurance considerations and clear authority for emergency expenditure.
Each of these situations requires a different response playbook. A natural disaster protocol and a data breach protocol share very little procedural overlap, and that is precisely why scenario-specific planning matters.
A strong crisis management plan does not attempt to predict every possible event. Instead, it identifies the scenarios most relevant to the organisation and gives people a tested framework for responding to them.

Crisis management is not a single event. It is a continuous cycle with three distinct phases: prepare, respond and recover. Together, these phases form the crisis management process, helping organisations move from anticipating potential threats to responding effectively and learning from what happened.
This is where most of the real work happens, long before any crisis arrives.
Indian organisations in the IT and BPO sectors learned many of these lessons during COVID-19. The post-pandemic standard is that remote readiness is part of crisis readiness, not separate from it.
When a crisis is confirmed, the response phase activates.
The aim of the response phase is not to solve everything immediately. It is to protect people, establish control, reduce uncertainty and stabilise the organisation.
Recovery is the phase that organisations can most easily overlook. Once the immediate threat passes, there is often a temptation to declare the crisis over and return to normal. However, recovery is where organisational resilience is strengthened or neglected.
Although prepare, respond and recover form the core crisis management cycle, the learning that follows recovery should feed directly back into preparedness.
A crisis, serious incident or simulation should therefore lead to changes in the plan, training, communication protocols or response playbooks where necessary. This creates a continuous improvement loop rather than treating crisis management as a one-off exercise.
Prepare → Respond → Recover → Learn → Prepare again
This is what turns crisis management from a document into an organisational capability.

A Crisis Management Plan (CMP) is a documented strategy that defines who acts, what they do, how they communicate, and in what sequence when a crisis occurs. Without one, responses tend to be reactive, slow and inconsistent, which can turn a manageable incident into a much larger organisational crisis.
Effective crisis management planning does not mean trying to predict every possible emergency. It means identifying the scenarios most relevant to the organisation and creating clear responsibilities, escalation routes, communication protocols and response actions before they are needed.
Here are six practical crisis management steps organisations can follow:
Identify the most likely and highest-impact crises for your specific organisation, sector and geography. Do not do this in isolation from the people who see risk up close. Involve frontline employees, department heads, and the legal and compliance team. They routinely spot vulnerabilities that leadership may miss.
Map identified risks on a simple grid of likelihood versus impact. Prioritise the top five to seven scenarios for detailed planning.
The first step of crisis management planning is therefore not writing the document. It is understanding what the organisation actually needs to prepare for.
Assign specific roles with clear authority, not just job titles. Each role should have a documented deputy because a crisis does not wait for key people to become available.
The core roles typically include the Crisis Manager, HR Representative, Communications Lead, Legal Counsel, IT or Security Lead, Operations Representative and Finance Director.
The team should also understand who has authority to activate the plan, who communicates externally and who takes over if a key decision-maker is unavailable.
Not every disruption constitutes a crisis. Agree on clear, pre-set thresholds so the CMT is not convened for minor incidents, while genuine crises are not downplayed into routine operational issues.
Depending on the organisation, activation triggers might include:
The exact thresholds should reflect the organisation's size, sector, risk profile and legal obligations.
Vague triggers create hesitation at precisely the moment when speed matters.
Design communication infrastructure assuming that your office may be inaccessible, your primary systems may be down and your team may be working from different locations.
For internal communication, consider cloud-accessible HR platforms, emergency SMS cascades, designated WhatsApp groups for the CMT, employee helplines and pre-approved email templates.
For external communication, prepare media contact lists, holding statements, regulator notification checklists and customer communication workflows.
For listed organisations, regulatory communication should also reflect applicable disclosure requirements.
The single biggest communication mistake organisations make in a crisis is trying to build these systems after the crisis has started.
For each top-priority risk scenario, create a dedicated response playbook.
Each playbook should include:
A natural disaster playbook and a data breach playbook share very little content. That is by design. Each should reflect the risks, decisions and stakeholders relevant to that scenario.
A plan that has never been tested is a hypothesis, not a plan.
Conduct tabletop exercises, where the CMT works through a simulated scenario without activating the full emergency response. Run live drills where appropriate, including evacuation exercises and IT failover tests.
Debrief after every exercise and document what needs to change. Update the plan rather than letting the same weaknesses show up in the next simulation.

These six steps of crisis management create the foundation of a practical crisis management plan. But the plan only becomes useful when people know how to use it under pressure.
Before considering the plan ready, check that it includes:
Treat a crisis management plan as a living document. Review it regularly and update it whenever there is a significant organisational, operational, technological or regulatory change.

A Crisis Management Team (CMT) is only as effective as its people, roles and preparation. The team brings together leaders from different functions who can make decisions quickly, coordinate the response and communicate clearly when it matters most.
A strong CMT is central to an organisation's crisis management strategy because it establishes clear ownership when normal reporting structures may not be sufficient. Members should be selected not only for their seniority, but also for their ability to make sound decisions with incomplete information and under significant time pressure.
The Crisis Manager has overall coordination authority and final decision-making responsibility. This role typically falls to the CEO or COO in smaller organisations and to a senior operations, risk or business continuity leader in larger organisations.
The Crisis Manager must remain composed under pressure, communicate clearly and keep the team focused on action rather than analysis paralysis.
HR manages employee safety, wellbeing communications and workforce-related decisions. In an Indian context, the HR lead should understand the workplace laws and requirements relevant to the organisation and the crisis, including applicable labour, workplace safety and POSH obligations.
HR also plays an important role in employee communication, workforce continuity and access to wellbeing support.
The Communications Lead is responsible for crisis messaging across internal and external channels. This includes coordinating employee updates, media statements, customer communications and social media monitoring.
The communications function should work closely with the Crisis Manager and Legal Counsel to ensure information is accurate, timely and consistent.
Legal advises on regulatory compliance, liability exposure and external communications. Depending on the organisation and nature of the crisis, this may include disclosure requirements, employment law, data protection obligations and other sector-specific regulations.
IT / Security Lead
The IT or Security Lead manages cybersecurity incidents, system recovery, data protection and technical containment. For a data breach, this role works closely with Legal and Communications to establish what happened, what information may have been affected and what actions are required.
The Operations Representative maintains business continuity by managing facilities, suppliers, vendors and critical operational processes. This role helps determine which business functions can continue, which must pause and what alternatives are available.
The Finance Director manages crisis-related cash flow, insurance claims, emergency procurement and financial impact assessment. During a major disruption, Finance also helps leadership understand the organisation's financial capacity to sustain operations and recovery.
CMT members must be able to make decisions with incomplete information, collaborate across functions and remain effective under pressure. These are trainable skills, but they should be developed before a crisis through tabletop exercises, simulations and regular drills.
A CMT should be small enough to make decisions quickly, but broad enough to represent every function that may be critical to the response. Every key role should also have a documented deputy so that the crisis management process does not depend on one individual being available.

If one capability can significantly influence how a crisis unfolds, it is communication. In a crisis, employees, customers, regulators and the public need accurate information quickly. Poor communication creates uncertainty, while silence allows rumours and speculation to fill the gap.
This is where crisis management public relations becomes particularly important. Organisations need to manage not only the crisis itself, but also how information is communicated and understood by different stakeholders.
The rule is simple: communicate early, even when not all the facts are available.
This does not mean speculating or sharing unverified information. It means acknowledging what has happened, explaining what is known, outlining what is being done, and committing to a time for the next update.
Silence is rarely neutral during a crisis. When employees and stakeholders do not receive information from the organisation, they may seek it elsewhere.
Employees should receive important information before they hear about the crisis through news reports or social media.
Use multiple channels simultaneously, depending on the nature of the crisis:
Never rely on a single communication channel. If the crisis has affected office infrastructure or IT systems, the organisation must still have a way to reach employees.
1. Be factual.
Share what is confirmed and avoid speculation.
2. Be empathetic.
Acknowledge the impact on employees and other affected people, not just the operational consequences.
3. Be clear.
Explain what is happening, what the organisation is doing and what employees need to know or do.
4. Be honest about uncertainty.
It is acceptable to say, "We do not yet know X, and we will provide an update by 5pm." This is more effective than vague reassurance.
5. Commit to the next update.
Give people a clear timeframe for when they can expect further information. Predictable communication can reduce uncertainty and maintain trust.
Customers, regulators, partners and the media may also require timely and factual updates.
For listed organisations, communication should take account of applicable SEBI disclosure requirements. For data-related incidents, organisations should also follow the regulatory and reporting requirements relevant to the incident.
For media-facing situations, prepare a holding statement as early as possible. It does not require complete information. It should acknowledge the situation, confirm that the organisation is responding, communicate concern for employee or customer safety where relevant, and provide a timeframe for the next update.
For example:
"We are aware of the situation and are actively investigating. Employee safety is our top priority. We will provide a further update by [time]."
This is not an attempt to avoid difficult questions. It is a responsible way to communicate while facts are still being established.
In India, a crisis can surface on LinkedIn, X or WhatsApp groups before traditional media reports it. Organisations should therefore assign responsibility for monitoring relevant social channels during an active crisis.
The objective should not be to delete criticism or suppress discussion. Instead, organisations should monitor emerging concerns, correct factual inaccuracies where appropriate, direct people towards official information and ensure that responses remain consistent with the approved communication strategy.
Crisis communication does not end once the immediate threat has passed.
Employees, customers and other stakeholders should receive updates about recovery, changes made as a result of the incident and any relevant next steps. Where the organisation made mistakes, acknowledging them and explaining what is being done differently can help rebuild trust.
Effective crisis management in PR is therefore not simply about protecting reputation during an incident. It is about communicating responsibly throughout the entire crisis management process.
HR is the most critical function in workplace crisis management. Not because of systems or processes, but because every crisis, regardless of its nature, has a human dimension.
Before a Crisis
HR's pre-crisis responsibilities are often the least visible and the most impactful.
During a Crisis
HR carries a set of responsibilities that no other function can absorb.
After a Crisis
The post-crisis HR role is where most organisations fall short.
Research from HR Planning for Crisis Management (ResearchGate, 2018) found that organisations which incorporated employee welfare into their crisis management plans were significantly more likely to achieve full operational recovery than those focused exclusively on protecting systems and infrastructure.
Post-COVID, major Indian organisations including TCS, Wipro, and HCL have formalised HR crisis playbooks as a standard capability. For smaller organisations, this remains a meaningful gap that forward-thinking HR leadership can address.
Crises create fear, uncertainty, and anxiety. These are not soft concerns. They directly affect decision-making capacity, productivity, and the pace of recovery. Leaders who ignore the emotional dimension of a crisis do not protect their organisation from it. They extend it.
Employees need to hear that what they are feeling is understood and that their safety matters more than operational metrics. This does not mean abandoning urgency. It means communicating in a way that treats people as people, not as operational variables.
Phrases that work: "We understand this is an anxious time." "Your safety is our first priority." "We do not have all the answers yet, but we are committed to keeping you informed."
Employee Assistance Programmes (EAPs) offer confidential counselling, mental health support, and practical guidance. In a crisis, passive availability is not sufficient. EAPs need to be actively promoted, with direct links, helpline numbers, and a clear message from senior leadership that using them is encouraged, not stigmatised.
In India, where mental health stigma remains a genuine barrier, the way leadership communicates about EAPs during a crisis can meaningfully affect uptake. Access to professional counselling support during and after a crisis is not a benefit add-on. It is a recovery tool.
Where operationally possible, offer remote work, flexible hours, or reduced targets during the acute phase. This is not a productivity concession. It signals genuine care and reduces the anxiety load employees are already carrying.
Uncertainty is a significant driver of anxiety. Even a message that says "we have no new updates yet but will communicate again at 6pm" is better than silence. Regular, predictable communication, even when there is little new information to share, maintains trust and reduces the fear that something is being withheld.
The risk period does not end when the crisis resolves. PTSD indicators, burnout, and significant engagement drops often surface weeks after normal operations resume. Build a structured post-crisis monitoring period into HR planning. Track engagement signals, absenteeism patterns, and informal manager reports over the first six to eight weeks.
Managers are the frontline of employee wellbeing in any crisis. They need training in recognising distress signals, having conversations about mental health without inadvertently stigmatising them, and knowing how to direct employees to appropriate support. In India, where direct conversation about mental health is still evolving in professional settings, this training is particularly valuable.

Recovery is not simply returning to normal. It is an opportunity to understand what happened, address weaknesses and strengthen the organisation's ability to respond to the next disruption.
Within two to four weeks of resolution, bring the Crisis Management Team together for a structured Post-Crisis Review (PCR).
Review:
The 5 Whys framework can help teams move beyond immediate triggers and identify underlying weaknesses.
Treat a crisis management plan as a living document. Update scenarios, communication templates, responsibilities, and escalation procedures after significant incidents and serious drills.
An outdated plan can create false confidence because employees may assume they are prepared when the information and processes they rely on are no longer relevant.
Trust is rebuilt through consistent action, not announcements alone.
Organisations should communicate honestly about what happened, explain what has changed and demonstrate those changes over time. Where mistakes were made, acknowledging them can be an important part of rebuilding credibility.
Resilience is developed between crises, not during them. Organisations can strengthen resilience by:
ISO 22301 can provide a useful international reference point for business continuity management, while organisations should also consider applicable Indian regulatory and sector-specific requirements.
Every organisational crisis is also a human experience.
Systems can be restored, data can be recovered and operations can resume. But employees who felt uninformed, unsupported or unprotected may carry that experience long after the immediate crisis has ended.
Effective workplace crisis management therefore needs more than a contingency document. It requires clear leadership, tested processes, responsible communication and meaningful support for employees throughout the crisis management process.
The goal is not to predict every crisis. It is to build an organisation that can respond with clarity, compassion and confidence when the unexpected happens.
Support your employees before a crisis becomes a crisis
An Employee Assistance Programme can give employees confidential access to professional support when they are dealing with workplace stress, personal challenges or the emotional impact of a difficult event.
Explore 1to1help's Employee Assistance Programme
For organisations looking to strengthen employee wellbeing and crisis preparedness, 1to1help provides EAP solutions including confidential counselling, crisis support, manager support and wellbeing resources.
Disclaimer: This guide is intended for HR professionals, business leaders, and organisational risk practitioners. It does not constitute legal advice. For regulatory compliance specific to your industry or organisation, consult qualified legal counsel familiar with Indian law.
Workplace crisis management is the structured approach an organisation uses to prepare for, respond to and recover from events that threaten its people, operations or reputation. It includes planning, crisis response, communication, recovery and continuous improvement.
The main crisis management steps are:
After a real crisis, a Post-Crisis Review should be used to identify lessons and update the plan.
Effective crisis management starts before an incident occurs. Organisations should have a documented plan, trained decision-makers, clear escalation procedures and tested communication channels. During a crisis, prioritise safety, activate the CMT, communicate confirmed information and establish clear decision-making authority. Recovery should include employee support and a formal review.
A crisis management plan (CMP) defines who does what, when they act, how decisions are made and how information is communicated during a crisis.
It helps reduce confusion and delays by giving employees and leaders a tested framework to follow when normal processes are disrupted.
HR plays a key role in the human side of crisis management. Its responsibilities can include employee safety and communication, workforce continuity, applicable legal and policy requirements, access to EAP support and post-crisis wellbeing. HR also helps managers support employees while maintaining appropriate professional boundaries.
Crisis communication should be fast, factual, empathetic and consistent. Communicate internally before employees learn about the situation through external sources, use more than one communication channel and clearly distinguish confirmed information from what is still being investigated.
Always tell people when they can expect the next update.
Common examples include:
Each crisis requires a response appropriate to its specific risks, stakeholders and regulatory requirements.