Building a Law Firm Crisis Communication Plan
A ransomware notice, a partner's arrest, a leaked settlement number, a server outage on the morning of a filing deadline: firms without a plan improvise their way into a second, self-inflicted crisis. Here is how to build one before you need it.
Most firms find out they need a crisis communication plan at the exact moment they don't have one. A managing partner is on a plane when a reporter emails asking for comment on a client's arrest. A paralegal notices unusual login activity at 11pm and nobody knows who to call first. A senior associate is named in a bar complaint that hits the local legal press before the firm has said a single word internally. In every one of these situations, the actual legal or ethical problem is usually survivable. What turns it into lasting damage is the twelve to forty-eight hours right after, when nobody agreed in advance on who speaks, what gets said, and in what order.
A crisis communication plan is not a PR document and it is not the same thing as your incident response policy, even though the two overlap. It is specifically about who talks to whom, when, and with what information, from the moment something goes wrong until the firm has stabilized. Litigation firms think about this reflexively when a client is in the news. Far fewer firms think about it when the firm itself is the subject, and that gap is where the real damage tends to happen, because everyone defaults to instinct instead of a plan, and instinct under pressure is inconsistent by nature.
This is a working guide to actually building one, not a generic template you fill in once and forget. It covers what counts as a crisis worth planning for, who needs to be on the notification chain, what to say and not say in the first hour, how to handle clients, staff, media, and regulators separately, and how to make sure the plan you write actually gets used when the day comes instead of sitting in a binder nobody has opened since the associate retreat where it was introduced.
What actually counts as a crisis, and what doesn't
Not every bad day is a crisis, and treating routine problems like five-alarm fires trains your team to ignore the plan when a real one hits. A single missed deadline on one matter is a serious problem for that client and that attorney, but it is not, on its own, a firm-wide crisis requiring a coordinated response. The threshold for activating a crisis plan is usually some combination of scale, reputational exposure outside the firm, and the potential for the story to be told by someone other than the firm first. A data breach touching client records, a partner facing criminal charges, a malpractice claim that has already reached a reporter, a natural disaster that shuts the office, a sudden death or incapacity of a name partner, a ransomware lock on the firm's systems, or a public accusation of misconduct against anyone at the firm all clear that bar.
The mistake most firms make is defining this list too narrowly, usually around data breaches alone because that is the category with the most regulatory attention. A firm that only has a breach response plan gets caught flat when the crisis is instead a viral video of a client complaint, a lateral hire's prior firm suing over a stolen book of business, or a court publicly sanctioning an attorney for conduct in a filing. The plan needs to be broad enough to cover any event where the firm's reputation, client trust, or ability to operate is at real risk, and specific enough that everyone on the notification chain knows within minutes whether what just happened qualifies.
- Does this event touch client data, client funds, or client confidentiality?
- Could this reach a reporter, regulator, or the public before the firm has spoken?
- Does it involve a partner, named attorney, or firm-wide system rather than one isolated matter?
- Would a client reasonably expect to hear from the firm directly about this?
Build the notification tree before the phone rings
The single most common failure in a real crisis is not that nobody knew what to say. It is that nobody knew who to call first, so five different people made five different calls, and by the time leadership actually understood the scope of the problem, three different versions of it were already circulating. A notification tree solves this by naming, in advance, exactly who gets told first, in what order, and who is authorized to escalate beyond that first circle. It should name actual people by name and by backup, not by title alone, because titles are useless at 6am when the managing partner is unreachable and someone still has to make a call.
The tree typically starts with whoever first discovers the issue calling one designated crisis lead, who then activates a short response team, usually the managing partner or equivalent, general counsel or outside ethics counsel if the firm has one on retainer, the firm's IT or security lead if systems are involved, and whoever owns client relationships for any matters directly affected. Everyone else, including the rest of the staff, waits to hear from that group rather than hearing about it secondhand or from a client who called in first. Write down phone numbers, not just email addresses, because the crises that matter most tend to happen outside business hours when email goes unread for hours.
The first sixty minutes decide the next sixty days
There is a strong pull, in the first hour of a real crisis, to say something reassuring immediately because silence feels like it is making things worse. Resist it. The first hour should be spent confirming facts, not communicating them. Firms that put out a statement before they actually know what happened almost always have to walk something back within a day, and a correction reads far worse to clients and the press than an initial silence followed by an accurate statement. The instinct to fill the silence is exactly the instinct that gets firms into a second, self-inflicted crisis stacked on top of the first one.
What the first hour is actually for is establishing scope. How many clients or matters are affected, is this contained or ongoing, does it trigger a bar reporting obligation, does the firm's malpractice or cyber insurer need to be notified immediately given policy terms that often require prompt notice, and does outside counsel need to be looped in before anyone puts anything in writing. Only once those questions have real answers does it make sense to draft any external message. A short holding statement acknowledging that the firm is aware of a situation and is actively addressing it is almost always the right move if any external inquiry comes in during this window, rather than either full silence or a detailed account you haven't verified yet.
What you tell clients, and how fast
Clients affected by a crisis, whether it is a breach touching their file, a delay caused by an office closure, or a conflict issue surfaced by a partner's departure, deserve to hear it from the firm directly and before they hear it anywhere else. The order matters as much as the content. A client who reads about their law firm's data breach in a news article before getting a call from the firm loses trust immediately, even if the substance of what happened was survivable. Direct, proactive outreach, even brief, beats a polished statement that arrives late every time.
What you actually tell a client depends heavily on what kind of crisis it is, but the structure holds steady across types. Say what happened in plain terms, say specifically what it means for their matter, and say what happens next and by when. Clients handle bad news far better when it comes with a concrete next step than when it comes wrapped in reassurance with no specifics attached. For matters where clients need ongoing visibility during a drawn-out response, a channel where they can check status themselves without waiting on a callback takes real pressure off the phone lines during the exact period when your team has the least capacity to answer them. Casely's client portal gives clients a real-time, filtered view of their own matter and its documents, with privilege filtering applied automatically so nothing sensitive gets exposed by accident, which matters even more than usual when a firm is fielding a high volume of anxious client contact at once.
| Feature | Silent until certain | Proactive holding statement |
|---|---|---|
| Timing | Client hears it from press or a third party first | Client hears from the firm within hours, even before all facts are confirmed |
| Trust impact | Feels like concealment even if unintentional | Feels like the firm is on top of it |
| Follow-up burden | Firm spends weeks rebuilding trust after the fact | Firm spends the same weeks, but starting from a position of credibility |
Keeping staff aligned so nobody freelances a statement
A crisis rarely stays contained to the people directly managing it, because staff talk to each other, and staff talk to clients too, often with good intentions and no idea what they are and are not supposed to say. The fastest way to lose control of a firm's message is to leave the rest of the team to guess at the facts and fill in gaps with speculation, which then gets repeated to clients, opposing counsel, or a reporter as if it were confirmed. A short, factual internal briefing, even one paragraph, sent to all staff before rumors start filling that vacuum does more to protect the firm's message than any external statement will.
The internal briefing should tell staff three things clearly: what the firm can confirm right now, who is authorized to speak externally about it, and what to say if a client or reporter asks them directly, which should always be a version of "I'm not the right person to speak to that, let me connect you with someone who can." Staff should never be left improvising an answer under the assumption that saying something is better than saying nothing. During a drawn-out crisis, it also helps enormously that critical case deadlines don't quietly slip while everyone's attention is on the crisis itself. A deadline diary that surfaces whichever date across every matter is coming up soonest, attached directly to the matter rather than living in one person's calendar, means the crisis response doesn't accidentally create a second, entirely preventable one on an unrelated file nobody was watching that week.
Data breaches need their own separate playbook
A cybersecurity incident deserves its own branch of the plan because the timeline and obligations are different from almost every other crisis type. Most jurisdictions and bar rules impose specific notification windows once a breach involving client data is confirmed, and those windows start running from confirmation, not from full understanding of scope. That means the sequence has to be forensics first, involving outside security counsel or a breach response firm immediately rather than trying to investigate internally, scope second, and notification third, calibrated to what the law actually requires in each affected client's jurisdiction rather than a single generic notice sent everywhere.
The instinct to delay client notification until every technical detail is nailed down usually backfires here specifically, because regulatory clocks are running regardless of how confident the firm feels about its investigation. It is entirely appropriate to send an initial notice that says a security incident occurred, that an investigation is underway with a named outside firm, and that a follow-up with specifics will come by a stated date, rather than waiting weeks for a complete picture before saying anything at all. On the technical side, firms that store documents with per-firm encryption keys rather than shared infrastructure are working from a materially stronger starting position when a breach does occur, since a compromise of one client's environment does not automatically expose every other firm sharing the same underlying key.
Handling media and public-facing inquiries
Most firms will never field a press inquiry in a given year, which is exactly why the ones that do tend to handle it badly. The core rule is simple and almost always ignored under pressure: exactly one person speaks for the firm externally, everyone else routes inquiries to that person, and nothing goes out that hasn't been reviewed by whoever is serving as the firm's crisis lead or outside counsel for the matter. A reporter calling multiple attorneys at the same firm and getting three slightly different answers is a worse outcome than a single, careful, delayed response from one designated spokesperson.
When a statement is warranted, shorter is almost always better than comprehensive. State what can be confirmed, state that the firm takes the matter seriously, state what is being done, and stop. Long statements packed with caveats and legal qualifiers read as evasive even when every word in them is true, and they give a reporter far more material to quote selectively. It also helps to have the statement reviewed by someone outside the immediate crisis team before it goes out, because people close to a stressful situation consistently misjudge how a sentence will read to someone with no context at all.
- 01Confirm the facts internally before saying anything externally
- 02Designate exactly one spokesperson for all external contact
- 03Draft a short factual statement, reviewed by someone outside the crisis team
- 04Notify directly affected clients before any public statement goes out
- 05Follow up with a fuller account once the full scope is actually known
Your bar and regulatory reporting obligations
Separate from the communication decisions above, most crisis events trigger a distinct question the plan needs to answer explicitly: does this require notifying the state bar, a malpractice insurer, or another regulator, and within what window. This is easy to lose track of in the middle of managing clients and staff, precisely because it is a compliance task rather than a communication one, and it tends to fall through the cracks when everyone's attention is on the more visible parts of the response. Build this into the plan as its own checklist item assigned to a specific person, usually general counsel or the managing partner, so it does not depend on someone remembering it in the moment.
Malpractice and cyber insurance policies in particular often carry strict notice provisions, sometimes requiring notification within days of an incident becoming known, and failing to meet that window can jeopardize coverage entirely regardless of the merits of the underlying claim. The same applies to conflicts that surface mid-crisis, for instance when a departing partner's new firm turns out to represent an adverse party on an active matter. Running that check requires searching the firm's complete contact and matter history, not just currently open files, and across every role a person or entity has played across the firm's history, not only as a named client, since the conflict is just as real if the person only ever appeared as a witness or a related entity on an older matter.
Document everything as it happens, not after
Every crisis eventually produces a question, sometimes from a regulator, sometimes from an insurer, sometimes from opposing counsel in a related malpractice claim, about exactly what the firm knew and when, and what it did in response. Firms that document their response in real time answer that question cleanly. Firms that try to reconstruct a timeline weeks later from memory and scattered emails answer it badly, even when they actually did everything right at the time, because the paper trail simply isn't there to show it.
Keep a running, timestamped log of every material decision and action taken during the response, who made the call, what was communicated, and to whom. This does not need to be elaborate. A shared document updated in real time by the crisis lead is enough, as long as it actually gets updated as things happen rather than backfilled afterward from memory. The same discipline that keeps a normal case file defensible applies here: a firm that already keeps a comment on every document recording what changed and why has a team that is used to this habit, and that habit transfers naturally to the higher-stakes documentation a crisis actually demands, rather than requiring the team to build a new discipline from nothing under pressure.
Testing the plan before you need it for real
A crisis communication plan that has never been rehearsed fails in exactly the ways you'd expect: the notification tree has stale phone numbers, nobody remembers who the designated spokesperson actually is, and the first real activation of the plan doubles as its first real test, at the worst possible moment to discover the gaps. A short tabletop exercise once or twice a year, walking the leadership team through a realistic scenario and having them actually name who they'd call and what they'd say, surfaces those gaps cheaply and without any real stakes attached.
Pick a scenario close to what your firm would actually face given its practice areas and client base, a breach for a firm handling sensitive personal data, a media inquiry for a firm doing high-profile litigation, an office closure for a firm in a region prone to severe weather, and walk through the first hour, the first day, and the first week out loud as a group. It routinely surfaces that the plan named someone who left the firm two years ago, or that nobody actually knows the malpractice carrier's notification deadline, or that the "media policy" everyone assumed existed was never actually written down. Finding that out in a conference room costs nothing. Finding it out during an actual crisis costs the firm its credibility at the exact moment it needs it most.
Getting your plan in place at your firm
None of this requires a consultant or an elaborate binder nobody will read. It requires naming actual people, writing down actual phone numbers, deciding in advance who speaks and who doesn't, and running through it once so the plan isn't being read for the first time during the actual crisis. Most firms that skip this step aren't being careless, they're simply busy, and a crisis plan feels like a project for a slower month that never actually arrives. The firms that have one usually built it right after a near miss, a close call that made the gap obvious without the full cost of a real failure attached to it. It is worth building yours before that happens rather than after.
The infrastructure underneath a good crisis response matters just as much as the plan itself. A firm that already has clean, current contact records across its full matter history, deadlines that surface automatically instead of living in someone's head, and a client-facing channel that doesn't depend on phone lines being staffed around the clock is simply better positioned to execute a plan under pressure than a firm reconstructing all of that from spreadsheets and inboxes in the middle of the event. That is worth thinking through separately from the plan itself, since the systems a firm runs on day to day are exactly the systems it will be leaning on hardest during the week it can least afford them to fail.
If client-facing communication is the part of your plan that feels least tested, that is usually the right place to start. Take a look at how a client portal actually works in practice, since the same real-time visibility that reduces routine "where are we" calls on a normal week is exactly what keeps client communication from collapsing into chaos during the week that isn't normal at all.
WRITTEN BY
Saumyajit M.Founder, Casely
Founder of Casely. Builds the practice management software the firm runs on, and writes about the operational side of running a legal practice.
More about the team