SmartSuite for the Crisis Management Lead
The Crisis Management Lead, or Incident Commander, directs the response to disruptive events: activating playbooks, coordinating teams and communications, maintaining situational awareness and overseeing recovery. After the event they run the post-incident review and own the corrective actions.
What you own
- Maintain the crisis management plan and playbooks
- Declare and activate the crisis response
- Direct the crisis team and coordinate cross-functional action
- Own stakeholder and regulatory communications during the event
- Maintain the incident log and situational awareness
- Run post-incident reviews and own corrective actions
- Exercise the crisis team on a schedule
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
How they use SmartSuite
Response Activation
Triggers coordinated recovery workflows when a crisis is declared.
Real-Time Coordination
Uses centralized dashboards to track tasks, updates, and communications.
Post-Incident Reviews
Captures lessons learned, corrective actions, and improvement recommendations.
How they use SmartSuite
Suites that serve this role
Products this role uses most
How SmartSuite supports this role
Operational resilience. Triggers coordinated response workflows when a crisis is declared and tracks tasks, updates and communications on one dashboard.
Issues and actions. Captures lessons learned, corrective actions and improvement recommendations from post-incident reviews and tracks them to closure.
Reporting. Logs the incident timeline and produces after-action reports for leadership and regulators.
Industry reference
ISO 22361:2022 is the crisis management standard, sitting alongside ISO 22301:2019 for continuity; FEMA's National Incident Management System and its Incident Command System provide the command structure most US organisations adopt. The BCI Good Practice Guidelines cover exercising the crisis team.
Disclosure rules set the clock during a live event: SEC registrants must disclose material cyber incidents within four business days of determining materiality; banks must notify regulators of computer-security incidents within 36 hours; NIS2 requires an early warning within 24 hours; hospitals operate under CMS emergency plans; GDPR requires breach notification within 72 hours.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.








