Why is a crisis won or lost in the first 48 hours?
The common feature of corporate crises is that legal outcomes are shaped less by the event itself than by the initial reactions to it. A deleted log record, a hastily published apology, a missed insurance notification — these come back to confront you months later in litigation, in an audit, or at the damages table. In the first 48 hours, the aim is not to “solve” the crisis but to protect your decision-making space.
Practical guidance
If you do not have a crisis protocol, even a one-page “first-call list” makes a difference: who will be called, which system records will be frozen, who will speak.
Let us build your crisis protocol together
We map the crisis scenarios specific to your company and prepare the first-48-hour plan and the contractual infrastructure.
Step 1: The incident map and a single command centre
In the first hours, information is scattered and everyone sees a different piece. What must be done is to gather the knowns, the unknowns, and the assumptions into a single incident map, and to ensure that decisions issue from a single crisis table. The legal team must sit at this table from the very beginning, because every step to be taken has an evidentiary, liability, and notification dimension.
Step 2: Securing evidence and records
E-mails, system logs, camera footage, and messages are the raw material of both your defence and your potential claims. To guard against the risks of deletion and overwriting, records must be frozen immediately; this must be done within the limits of KVKK, upon written instruction, and with a record of who accessed what and when. Access to data on personal devices, in turn, requires a separate legal assessment.
Step 3: Inventory of notification obligations
Depending on the type of crisis, time-bound notifications come into play: in a personal data breach, the practice of notifying the Board is built on 72 hours; insurance policies often require “immediate” notification; regulated sectors such as the stock exchange, banking, and energy carry additional obligations. Within the first day, a complete notification inventory should be drawn up and the deadlines tracked on a single calendar.
Step 4: Communication discipline
There are two rules in crisis communication: a single spokesperson and approved text. Employees are given not an instruction to stay silent but to redirect: “X will make the statement.” Every sentence given to the press should be written as though it will later be read as evidence; even an innocent “we are sorry” can, in some legal systems, come close to an admission of liability.
Step 5: Recovery and liability analysis
Once the acute phase has passed, it is time for damage assessment: contract breaches, recourse options, employee proceedings, and, where necessary, criminal complaints. The quality of this phase depends on the evidence gathered in the first 48 hours — this is how the circle closes.
Priorities by type of crisis
The first 48 hours of every crisis are not the same. In a data breach, the priority is containing the leak, identifying the affected data categories, and notifying the Board — we address the details of this scenario separately in our Cybersecurity focus area. In a search and seizure, the priority is checking the scope of the decision, discipline in the record of proceedings, and protecting systems outside that scope. In a product crisis, documenting the recall decision and notifying the insurer; in a media crisis, the timing of access blocking, rebuttal and reputation-repair tools comes to the fore. The crisis table must know how to reorder this list of priorities according to the scenario.
After the crisis: turning the case into value
When the acute phase closes, you are left with two things: a damage table and a list of lessons. The damage table is turned into litigation and collection proceedings against contract breaches, into recourse against faulty suppliers or service providers, and, where necessary, into internal investigation and criminal complaint steps. The list of lessons, in turn, flows into updating the protocol: which notification was late, which authority was unclear, which record was missing. The company that comes out of a crisis should not be the same as the one that went into it.
The Köksal approach
In crisis matters, our Crisis Management focus area coordinates legal, communication and management actions from a single centre. For our ongoing-advisory clients, a crisis protocol is a standard part of preventive advisory: the initial call list, the evidence-freezing instruction, the notification inventory, and approved communication templates are prepared in advance. For scenarios that require an internal investigation, you can take a look at our step-by-step investigation guide.
Conclusion
Crisis management in companies leaves no room for improvisation. A pre-written protocol, an up-to-date set of communication templates, and an evidence-security instruction more than pay for themselves in the first crisis that occurs. The capacity for crisis management is built not on the day of the crisis but today.


