Risk & Preventive Advisory · Alt Service

In the first 48 hours of a crisis, let protocol speak.

The command structure for the first 48 hours of a sudden legal, operational, or reputational crisis: incident map, emergency measures, evidence preservation, and notification inventory.

Sub-service Dossier
Overview

Why are the first hours decisive?

In crises, the most lasting damage arises from wrong decisions made in the first hours: a deleted record, a hastily issued statement, a missed notification deadline. The first 48 hours are the window in which evidence, liability, and communication must all be managed at once. This is the service counterpart of the roadmap we detail in our crisis guide.

01

Response structure

An incident map is drawn up: what happened, who knows, which systems and contracts were affected. Emergency legal measures are prioritised; an evidence preservation instruction is issued and records are secured through e-discovery infrastructure. The notification inventory (insurance, authority, contractual) is arranged by deadline order; the spokesperson and approval chain are clarified.

02

Priorities by scenario

In a data breach, the 72-hour regime and our cyber response line; in a search and seizure, record-keeping discipline and on-site response; in a product crisis, recalls and supply contracts; in a media crisis, access blocking and rebuttal tools come to the fore. The crisis desk must be able to recognise the scenario and reorder the priority list within minutes.

How We Work

The first call sets the clock

The engagement follows a fixed rhythm. Intake call: within the first hour, the incident map is sketched and the privileged workstream is set up so that analysis stays protected. Execution: the 48-hour checklist runs — evidence preservation instructions, the notification inventory in deadline order (the 72-hour data-breach regime under the KVKK and GDPR Article 33 among the tightest), and the approval chain for every outgoing statement. Handoff: by day three, the file passes to the specialist tracks — communication coordination, authority liaison, defence or recovery — under one coordinating strategy. Post-incident: a lessons memo updates the protocol.

03

Where does each deadline come from?

The time pressure comes from scattered sources that have to end up on one list: on the KVKK (No. 6698) side, the 72-hour breach notification that follows from the Board’s settled practice; the same window in Article 33 GDPR; where you serve customers caught by NIS2, the 24-hour early warning, 72-hour notification and one-month final report ladder that reaches you through your contracts; the notice conditions in the insurance policies, counted in days; and, in a search-and-seizure scenario, the procedural rights that have to be exercised on the spot or not at all. The picture differs from company to company, so when the crisis protocol is built we draw up that company’s own inventory of deadlines and put a named owner against every item on it. For the sector framework, our NIS2 record is the place to start.

04

Who is it for, and what do you get?

The first-48-hours structure is used most by manufacturing and logistics operations dealing with a product safety incident, by e-commerce and SaaS companies facing a data breach, by regulated businesses put through an unannounced inspection, and by companies on a retainer that already have the protocol in place. What the set-up project delivers is concrete: scenario cards written for the company, the deadline and notification matrix, the incident log template, the notification files and the post-incident report, and one tabletop exercise a year. Where there is a German parent the protocol is built in both languages, and the balance between what group headquarters expects to be told and the defence strategy in Türkiye — the language of the correspondence above all — is settled at the outset. The rules for dealing with the authorities themselves are covered by our authority and audit liaison service.

Why Köksal?

We are by your side for Crisis Response: The First 48 Hours

Our Crisis Management focus area operates on a 24/7 access basis: ready-made protocol templates, notification drafts and approved communication texts. For retainer clients, the crisis protocol is established in advance — on the first call, it is not a file but a plan that opens.

Köksal team multidisciplinary work
05

Other Applications of This Service

Risk & Preventive Advisory — our other specialised solutions in this area.

Risk & Preventive Advisory — back to the parent service
06

Matter Connections

The focus areas, practice areas, desks and legislation connected with this sub-service.

08

The Team Delivering This Service

With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

09

Related Publications

Fresh perspectives and guides from the Knowledge Centre.

Your first point of contact should be your legal team, because the steps taken in the first hours have irreversible consequences for evidence, liability, and notification deadlines. We coordinate the crisis from a single centre and tie the other advisers into that framework.

Yes, and this is the most effective way: the call list, evidence instructions, notification inventory, and communication templates are prepared in advance. It is kept alive with an annual tabletop exercise.

Including data breaches, search and seizure, product and supply crises, loss of a key executive, media attacks, and sudden dispute escalation; in any sudden event with a legal dimension.

Service

Crisis Response: The First 48 Hours — get the right legal support.

Let us identify the right solution together, drawing on our experience in Türkiye and the DACH region.