Senior leader coordinating a crisis response team in a modern control room, symbolising strategic decision-making and resilience

Crisis Management and ISO 22361: A Strategic Advantage for Every Organisation

Crisis Management and ISO 22361: A Strategic Advantage for Every Organisation

Crisis management is no longer a niche concern — it’s a strategic capability that every organisation must cultivate. ISO 22361 provides a structured framework for doing just that. Whether you’re navigating reputational risk, cyber threats, or operational disruption, this international standard helps leaders respond with clarity and control.

🔍 What is ISO 22361?

ISO 22361:2022 is the global standard for crisis management. It offers guidance on building a crisis management capability, covering leadership, decision-making, communication, and coordination. Unlike ISO 22301, which focuses on continuity planning, ISO 22361 supports organisations in managing crises as they unfold.

💡 Why Crisis Management Matters

  • Unpredictable threats: From data breaches to supply chain failures, crises can emerge from anywhere.
  • Leadership under pressure: ISO 22361 helps leaders make confident, timely decisions when it matters most.
  • Stakeholder expectations: Customers, regulators, and communities expect transparency and control during a crisis.
  • Reputation and recovery: A well-managed crisis can protect — or even enhance — your brand.

🧩 ISO 22361 vs ISO 22301: A Resilience Duo

ISO 22301 keeps operations running, and is a standard that you can be certified against. ISO 22361 is a guidance standard, helping to refine and drive your response. Together, they form a comprehensive resilience strategy:

ISO 22301ISO 22361
Focuses on continuity of operationsFocuses on strategic crisis response
Emphasises recovery and preparednessEmphasises leadership and decision-making
Often led by operational teamsOften led by senior leadership

🛠️ Getting Started with Crisis Management

  1. Review your current resilience frameworks — identify gaps in crisis leadership and communication.
  2. Engage senior stakeholders — crisis management must be owned at the top.
  3. Use ISO 22361 as a guide — tailor its principles to your organisation’s structure and culture.
  4. Train and test — run scenario-based exercises to build confidence and capability.

Understanding the fundamentals of crisis management is critical to ensure effective coordination throughout the response to an incident.

🚀 RiskReady’s Approach

At RiskReady, we help organisations understand crisis management so that they can embed effective practices into their resilience frameworks. Our ISO 22361 crisis management e-learning modules — are designed to be practical, accessible, and grounded in real-world challenges.

Share The Post

Helen Molyneux, founder of RiskReady and Cambridge Risk Solutions

Helen Molyneux is the founder of Cambridge Risk Solutions, a specialist resilience consultancy with nearly two decades of experience in business continuity, crisis management and information security. She holds Lead Auditor certifications for ISO 22301 and ISO 27001, and has worked across both public and private sectors helping organisations prepare for, respond to, and recover from disruption. RiskReady is her e-learning platform, built to make that same practical expertise accessible to individuals and teams at every level.

Find out more about Cambridge Risk Solutions →

Leave a Comment

Your email address will not be published. Required fields are marked *