Guide · Data Protection

Crisis management in companies: the legal roadmap for the first 48 hours

Data breach, search and seizure, product crisis, or media scandal: the steps taken in the first 48 hours determine the fate of the case. An actionable legal crisis protocol for companies.

10 February 20264 dk okumaBy Sven Köksal · Data Protection
Köksal Attorney Partnership — meeting room for litigation, arbitration and dispute resolution
Summary · At a glance
  • The first losses in a crisis are usually losses of evidence and of time; neither can be recovered.
  • A single spokesperson and an approved messaging framework speed up communication while reducing litigation risk.
  • Notification obligations (KVKK, insurance, regulatory) involve deadlines measured in hours.
  • A pre-written crisis protocol is the most effective insurance for the first 48 hours.

Why is a crisis won or lost in the first 48 hours?

The common feature of corporate crises is that legal outcomes are shaped less by the event itself than by the initial reactions to it. A deleted log record, a hastily published apology, a missed insurance notification — these come back to confront you months later in litigation, in an audit, or at the damages table. In the first 48 hours, the aim is not to “solve” the crisis but to protect your decision-making space.

Practical guidance

If you do not have a crisis protocol, even a one-page “first-call list” makes a difference: who will be called, which system records will be frozen, who will speak.

Let us build your crisis protocol together

We map the crisis scenarios specific to your company and prepare the first-48-hour plan and the contractual infrastructure.

Request a consultation

Step 1: The incident map and a single command centre

In the first hours, information is scattered and everyone sees a different piece. What must be done is to gather the knowns, the unknowns, and the assumptions into a single incident map, and to ensure that decisions issue from a single crisis table. The legal team must sit at this table from the very beginning, because every step to be taken has an evidentiary, liability, and notification dimension.

Step 2: Securing evidence and records

E-mails, system logs, camera footage, and messages are the raw material of both your defence and your potential claims. To guard against the risks of deletion and overwriting, records must be frozen immediately; this must be done within the limits of KVKK, upon written instruction, and with a record of who accessed what and when. Access to data on personal devices, in turn, requires a separate legal assessment.

Step 3: Inventory of notification obligations

Depending on the type of crisis, time-bound notifications come into play: in a personal data breach, the practice of notifying the Board is built on 72 hours; insurance policies often require “immediate” notification; regulated sectors such as the stock exchange, banking, and energy carry additional obligations. Within the first day, a complete notification inventory should be drawn up and the deadlines tracked on a single calendar.

Step 4: Communication discipline

There are two rules in crisis communication: a single spokesperson and approved text. Employees are given not an instruction to stay silent but to redirect: “X will make the statement.” Every sentence given to the press should be written as though it will later be read as evidence; even an innocent “we are sorry” can, in some legal systems, come close to an admission of liability.

Step 5: Recovery and liability analysis

Once the acute phase has passed, it is time for damage assessment: contract breaches, recourse options, employee proceedings, and, where necessary, criminal complaints. The quality of this phase depends on the evidence gathered in the first 48 hours — this is how the circle closes.

Priorities by type of crisis

The first 48 hours of every crisis are not the same. In a data breach, the priority is containing the leak, identifying the affected data categories, and notifying the Board — we address the details of this scenario separately in our Cybersecurity focus area. In a search and seizure, the priority is checking the scope of the decision, discipline in the record of proceedings, and protecting systems outside that scope. In a product crisis, documenting the recall decision and notifying the insurer; in a media crisis, the timing of access blocking, rebuttal and reputation-repair tools comes to the fore. The crisis table must know how to reorder this list of priorities according to the scenario.

After the crisis: turning the case into value

When the acute phase closes, you are left with two things: a damage table and a list of lessons. The damage table is turned into litigation and collection proceedings against contract breaches, into recourse against faulty suppliers or service providers, and, where necessary, into internal investigation and criminal complaint steps. The list of lessons, in turn, flows into updating the protocol: which notification was late, which authority was unclear, which record was missing. The company that comes out of a crisis should not be the same as the one that went into it.

The Köksal approach

In crisis matters, our Crisis Management focus area coordinates legal, communication and management actions from a single centre. For our ongoing-advisory clients, a crisis protocol is a standard part of preventive advisory: the initial call list, the evidence-freezing instruction, the notification inventory, and approved communication templates are prepared in advance. For scenarios that require an internal investigation, you can take a look at our step-by-step investigation guide.

Conclusion

Crisis management in companies leaves no room for improvisation. A pre-written protocol, an up-to-date set of communication templates, and an evidence-security instruction more than pay for themselves in the first crisis that occurs. The capacity for crisis management is built not on the day of the crisis but today.

This content is for general information purposes only and does not constitute legal advice. Please get in touch with our team for an assessment regarding your specific situation.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all

Both together; but statements should not be released without passing through a legal filter. A wrong sentence can become an admission in litigation.

The IT team, on the written instruction of the legal department; the scope and method should be documented so as to preserve the chain of custody.

No; this is general information. Contact our team for your specific crisis scenario.

Knowledge Centre

Let us build your crisis protocol together

We map the crisis scenarios specific to your company and prepare the first-48-hour plan and the contractual infrastructure.