Back to Trust Center
    Crisis Response

    Crisis Communications Protocol

    Structured crisis communications framework ensuring measured, accurate, and compliance-aware responses to institutional incidents.

    Crisis Level Classification

    I

    Routine Incident

    Minor operational disruption with no external impact. Handled through standard operating procedures with Communications Office notification.

    II

    Elevated Incident

    Operational disruption with potential external visibility. Requires Communications Office coordination and leadership awareness.

    III

    Significant Incident

    Material incident affecting stakeholders, customers, or public safety. Requires executive-level response and controlled external communications.

    IV

    Critical Incident

    Major incident with potential regulatory, safety, or institutional consequences. Full crisis response activation including board notification and regulatory engagement.

    Response Phases

    Phase 1: Containment

    Immediate incident containment and assessment. Activation of crisis response team. Communication hold on external channels until verification is complete.

    Phase 2: Verification

    Fact-finding and root cause assessment. Verification of incident scope, impact, and affected stakeholders. Coordination with relevant technical and legal teams.

    Phase 3: Regulatory Notification

    Required notifications to regulatory bodies as applicable (FAA, DoD, NASA, NIST). Notifications follow established reporting timelines and formats.

    Phase 4: Customer Notification

    Direct notification to affected customers, partners, and prime contractors. Notifications include verified facts, impact assessment, and remediation timeline.

    Phase 5: Controlled Public Statement

    Authorized public statement through designated spokesperson. Statement reviewed for accuracy, compliance, and export sensitivity before release.

    Phase 6: Post-Incident Review

    Formal post-incident review including root cause analysis, lessons learned, and corrective action implementation. Results integrated into ERM framework.

    Specialized Response Protocols

    Cybersecurity Incident Communication

    Cybersecurity events follow NIST Cybersecurity Framework incident response guidelines. External communications are coordinated with security team and legal counsel. CUI exposure assessment conducted before any public disclosure.

    Export-Control Event Communication

    Incidents involving potential export control violations require immediate legal review. External communications are withheld pending ITAR/EAR compliance assessment. Voluntary disclosures follow DDTC or BIS procedures as applicable.

    Investor Notification Protocol

    Material incidents that may affect institutional valuation or strategic direction are communicated to investors through established reporting channels. Notifications are factual, measured, and compliant with applicable disclosure requirements.

    Media Engagement During Crisis

    All media engagement during crisis events is coordinated exclusively through the Communications Office. Designated spokespersons provide authorized statements only. No employee is authorized to make independent media statements during crisis periods.

    Root Cause & Lessons Learned

    Every crisis event, regardless of severity level, concludes with a formal root cause analysis. Findings are integrated into the Enterprise Risk Management framework, Safety & Mission Assurance Charter, and institutional training programs.

    Protocol Governance: This Crisis Communications Protocol is maintained under the Enterprise Risk Management framework and reviewed quarterly. Protocol activation is authorized by the Crisis Response Team Lead in coordination with executive leadership.

    EmailXLinkedinInstagramYoutube