Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Crisis-Proofing Your New Jersey Business: Building a Crisis Response Plan Before You Need One

Author: Sean M. Pena

Date: September 24, 2026

Key Contacts

Back
Executives reviewing a crisis response plan around a conference table

For New Jersey businesses, crisis preparedness should be viewed as a legal and operational function, not simply an emergency-management exercise. A well-designed crisis response plan can help preserve evidence, protect confidential communications, meet reporting obligations, limit unnecessary exposure, and prevent an already difficult situation from becoming a larger legal problem.

Key Takeaways

  • Build the crisis team before a crisis occurs. Identify the people responsible for legal, operational, communications, HR, IT, and executive decisions.
  • Establish clear escalation procedures. Employees should know which incidents require immediate attention and who to notify.
  • Preserve evidence and protect communications. Early steps involving document preservation, investigations, and notifying legal counsel can have significant consequences later.
  • Understand reporting and insurance obligations. Regulatory deadlines, contractual requirements, and insurance notice provisions may apply quickly.
  • Stress-test the plan. Hypothetical exercises can identify gaps in decision-making and communication before an actual crisis exposes them.

A serious crisis rarely arrives at a convenient time. A workplace accident, data breach, government investigation, executive misconduct allegation, cyberattack, or sudden regulatory issue can require an organization to make consequential decisions within hours, often before all the facts are known. The organizations that navigate these events most effectively are not necessarily those that avoid crises altogether. They are the ones that have already decided who will respond, who has authority to act, and how information will move when circumstances are changing quickly.

Start With a Designated Crisis Response Team

The first step is identifying the people who will take charge when a potentially significant event occurs. Depending on the organization, the team may include members of senior management, in-house counsel, outside counsel, human resources, information technology, communications, risk management, and security.

Not every crisis requires every team member. The objective is to establish a core group that can quickly assess the situation and bring in the appropriate personnel. The organization should also identify who has authority to make key decisions. During a crisis, uncertainty about who can authorize an investigation, engage outside vendors, notify regulators, communicate with employees, or issue a public statement can create costly delays. A written protocol should address these questions before the pressure is on.

Establish Legal Counsel’s Role Early

One of the most important decisions is determining when counsel should become involved. In some situations, the organization should contact counsel immediately. In others, management may initially address an operational issue without legal involvement. The organization’s plan should establish clear criteria for escalating an incident to counsel.

Counsel can help the organization evaluate legal obligations while the facts are still developing. Depending on the circumstances, that may include assessing regulatory reporting requirements, employment issues, contractual obligations, insurance coverage, evidence preservation, potential litigation, and communications with government agencies or third parties.

When an internal investigation may be necessary, involving counsel at the appropriate stage can also help the organization structure the investigation and determine how to handle communications and investigative materials. Attorney-client privilege and work-product protection are important considerations, but they should not be treated as automatic shields for everything generated during a crisis. How an investigation is structured and who is directing the work can matter.

Create a Clear Escalation Protocol

Employees cannot be expected to make sophisticated legal judgments in the middle of an emergency. They should, however, know when to escalate an incident.

Events That Require Immediate Escalation

A crisis protocol should identify events that require immediate escalation, such as:

  • A serious workplace injury or fatality;
  • A suspected data breach or significant cybersecurity incident;
  • Allegations of executive or employee misconduct;
  • A subpoena, search warrant, or regulatory inquiry;
  • Threatened or filed litigation;
  • A significant environmental incident;
  • A product defect or safety issue;
  • A material contractual dispute;
  • Theft, fraud, or other suspected financial misconduct; and
  • A significant incident likely to attract media or public attention.

The protocol should also establish practical reporting channels. Employees should know whom to contact, what information to provide, and what not to do, such as deleting files, conducting an informal investigation, making public statements, or communicating with regulators without authorization.

Protect Evidence Before It Disappears

One of the most common mistakes organizations make during a crisis is focusing on what happened without first considering what evidence must be preserved.

Electronic evidence can disappear quickly. Emails may be deleted, surveillance footage may be overwritten, text messages may be lost, and employees may continue using devices that contain potentially relevant information. A crisis response plan should therefore include procedures for issuing litigation holds or other preservation instructions when appropriate.

Preservation should be proportionate to the circumstances, but the organization should err on the side of identifying potentially relevant information early. IT personnel and outside vendors may need specific instructions regarding backups, cloud systems, messaging platforms, access logs, security footage, and employee devices. The legal team should also consider whether to suspend normal document-retention practices for particular information.

Control Communications

During a crisis, an organization can create significant problems by communicating too much, too little, or inconsistently. Accordingly, the crisis response plan should designate who is authorized to communicate with employees, customers, regulators, the media, insurers, business partners, and other outside parties. Employees should understand that an instinct to “explain what happened” can create problems if information is incomplete or inaccurate.

Internal communications require the same attention. Organizations should discourage speculation and remind employees to preserve relevant information. At the same time, employees need enough information to continue operating safely and appropriately. A communications plan should also account for social media. An employee’s personal post can attract attention to an incident even when the organization has not made a public statement. Having a process for monitoring and responding to public communications can help the organization avoid reacting impulsively.

Know the Regulatory and Reporting Landscape

Crisis response is often complicated by overlapping legal obligations. Depending on the nature of an incident, a New Jersey business may have obligations under federal law, New Jersey law, industry-specific regulations, contractual provisions, or insurance policies.

For example, a cybersecurity incident may trigger notification obligations involving affected individuals, regulators, law enforcement, contractual counterparties, or other stakeholders. Under New Jersey’s data breach notification law, a business that experiences a breach of personal information must report it to the Division of State Police before notifying affected customers. A workplace incident may require consideration of federal or state workplace-safety requirements. An environmental event may implicate state and federal reporting requirements.

The response team should maintain a current list of the regulatory agencies, contractual contacts, insurers, and other parties that may need to be notified. The organization should not assume that the same notification timeline applies to every type of incident.

Coordinate With Insurance

Insurance carriers can play an important role in a crisis, especially when the organization may face significant defense costs, property damage, business interruption, cyber losses, or third-party claims. Organizations should know what insurance policies they maintain and understand the basic notice requirements under those policies. Depending on the circumstances, coverage may involve commercial general liability, directors and officers liability, employment practices liability, cyber insurance, property coverage, or other specialized policies.

The crisis plan should also identify who is responsible for notifying the appropriate carrier or broker and should account for policy requirements concerning consent to defense counsel, settlements, remediation expenses, and other costs.

Conduct a Tabletop Exercise

A crisis plan sitting in a binder, or buried in a shared drive, is unlikely to be effective when an actual emergency occurs. Organizations should periodically test their plans. The exercise does not need to replicate every possible crisis. A hypothetical scenario can expose gaps in decision-making authority, communication channels, vendor relationships, data preservation, insurance procedures, and regulatory response.

Sample Scenario: A Friday Afternoon Ransomware Attack

Management might be given a scenario involving a ransomware attack that occurs late on a Friday afternoon. The exercise can then test basic questions:

  • Who is contacted first?
  • Who has authority to shut down systems?
  • When is outside counsel engaged?
  • Who contacts the insurer?
  • Who communicates with employees?
  • What information must be preserved?
  • What happens if the incident becomes public?

The objective is not to produce a perfect response. It is to identify weaknesses while there is still time to fix them.

Review the Plan After Every Significant Incident

Crisis preparedness should be an ongoing process. Laws and regulations change, employees change roles, vendors change, technology changes, and organizations restructure. A plan that worked two years ago may no longer reflect how the business operates.

After a significant incident, the organization should conduct a post-event review. What worked? Where did decisions stall? Were the right people involved? Did employees understand their responsibilities? Were there unexpected legal or contractual obligations? The organization should incorporate those lessons into the plan rather than discuss them and forget them.

Frequently Asked Questions

What is a crisis response plan?

A crisis response plan is a written framework that establishes who will respond to a significant incident, who has authority to make key decisions, and how information will be communicated, preserved, and reported. For New Jersey businesses, it functions as both a legal and an operational tool.

Who should be on a crisis response team?

Depending on the organization, the team may include senior management, in-house counsel, outside counsel, human resources, information technology, communications, risk management, and security. The goal is a core group that can quickly assess a situation and bring in the right people.

When should a business involve legal counsel in a crisis?

Some incidents, such as a data breach, a subpoena, or allegations of executive misconduct, may call for contacting counsel immediately. The crisis response plan should set clear criteria for when to escalate an incident to counsel, so the decision is not made under pressure.

Does attorney-client privilege protect everything created during a crisis?

No. Attorney-client privilege and work-product protection are important, but they are not automatic shields. How an internal investigation is structured and who directs the work can affect whether materials are protected.

What is a tabletop exercise?

A tabletop exercise is a hypothetical crisis scenario that management works through to test the organization’s plan. It can reveal gaps in decision-making authority, communication channels, evidence preservation, insurance procedures, and regulatory response before a real incident does.

How often should a crisis response plan be updated?

Review a plan regularly and after every significant incident. Changes in laws, personnel, vendors, technology, and corporate structure can make an older plan outdated.

How Scarinci Hollenbeck Can Help

A crisis response plan should be tailored to the organization’s operations, risk profile, regulatory environment, and corporate structure. At Scarinci Hollenbeck, our attorneys work with businesses and their leadership teams to develop crisis-response protocols, establish escalation procedures, address investigations and evidence preservation, review relevant contractual and insurance considerations, and assist with tabletop exercises. Having experienced legal counsel involved before a crisis occurs can give an organization a framework for making informed decisions when time is limited, and the consequences of a misstep can be significant. For guidance on building or stress-testing your organization’s crisis response plan, contact Sean M. Pena.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
Crisis-Proofing Your New Jersey Business: Building a Crisis Response Plan Before You Need One post image

Crisis-Proofing Your New Jersey Business: Building a Crisis Response Plan Before You Need One

For New Jersey businesses, crisis preparedness should be viewed as a legal and operational function, not simply an emergency-management exercise. A well-designed crisis response plan can help preserve evidence, protect confidential communications, meet reporting obligations, limit unnecessary exposure, and prevent an already difficult situation from becoming a larger legal problem. Key Takeaways A serious crisis […]

Author: Sean M. Pena

Link to post with title - "Crisis-Proofing Your New Jersey Business: Building a Crisis Response Plan Before You Need One"
Monmouth County's Next Development Wave: What Developers and Investors Need to Know post image

Monmouth County's Next Development Wave: What Developers and Investors Need to Know

Monmouth County is entering a significant new phase of development. For those looking to acquire property or undertake a new project, understanding the market opportunity is only the beginning. The more important question is whether a particular property can actually be developed as contemplated and what approvals, agreements, and other conditions will be required to […]

Author: Donald M. Pepe

Link to post with title - "Monmouth County's Next Development Wave: What Developers and Investors Need to Know"
Are Your Conversations with AI Shielded from Discovery? Courts Are Split post image

Are Your Conversations with AI Shielded from Discovery? Courts Are Split

Whether a client’s prompts to a generative AI tool and the documents it produces are protected from disclosure depends on the case type, who claims protection, and whether counsel was involved. In United States v. Heppner, a New York federal judge ruled that a criminal defendant’s communications with an AI platform were protected by neither […]

Author: Chris Seelinger

Link to post with title - "Are Your Conversations with AI Shielded from Discovery? Courts Are Split"
Guardianships in New Jersey: When a Loved One Can No Longer Manage Personal or Financial Affairs post image

Guardianships in New Jersey: When a Loved One Can No Longer Manage Personal or Financial Affairs

When a family member can no longer make important decisions for themself, the question is often not whether the family will step in, but whether they have the legal authority to do so. A spouse may manage household finances, or an adult child may arrange medical care and pay bills. Still, informal assistance does not […]

Author: Marc J. Comer

Link to post with title - "Guardianships in New Jersey: When a Loved One Can No Longer Manage Personal or Financial Affairs"
New Jersey’s Revised UHAC Regulations: What Residential Developers Need to Know About Affordable Housing Commitments post image

New Jersey’s Revised UHAC Regulations: What Residential Developers Need to Know About Affordable Housing Commitments

New Jersey residential developers with affordable housing obligations should carefully review their existing approvals, development agreements, and proposed deed restrictions in light of the State’s revised UHAC regulations (Uniform Housing Affordability Controls). The regulations, which took effect on November 6, 2025, significantly change the administration and physical requirements for affordable housing units. For developers with […]

Author: Wendy Rubinstein Quiroga

Link to post with title - "New Jersey’s Revised UHAC Regulations: What Residential Developers Need to Know About Affordable Housing Commitments"
“No Comment” Culture: Why Silence Is Often the Riskiest Legal Strategy post image

“No Comment” Culture: Why Silence Is Often the Riskiest Legal Strategy

A “no comment” response is sometimes the right call when a legal problem arises. As a blanket policy, however, it lets allegations go unanswered, deadlines pass, evidence disappear, and manageable disputes grow into expensive litigation. The businesses that fare best are usually the ones that say little publicly while acting decisively behind the scenes. When […]

Author: Sean M. Pena

Link to post with title - "“No Comment” Culture: Why Silence Is Often the Riskiest Legal Strategy"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
“If you would like to submit a file, please email it directly to info@sh-law.com.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!