Commentary October 08 2026

Basil Jarrett | When your crisis plan isn’t ready for AI

Updated 6 hours ago 4 min read

Loading article...

  • Jarrett Jarrett. Photo - File
  • Jarrett Jarrett. Photo - File
  • One of the biggest mistakes organisations still make is treating cybersecurity incidents as primarily technical matters. One of the biggest mistakes organisations still make is treating cybersecurity incidents as primarily technical matters. Photo - pexels.com
  • Crisis communication cannot be treated as something the communications department “handles” after the emergency occurs. Crisis communication cannot be treated as something the communications department “handles” after the emergency occurs. Photo - pexels.com

Most organisations like to believe that they have a crisis communication plan. Some even do. There is usually a binder somewhere, perhaps on a shelf in corporate affairs or human resources, containing contact lists, approval protocols, template statements, and a reassuringly complicated flowchart showing who calls whom when something goes off the rails.

The problem is that many of those plans were built for yesterday’s crises. Fire. Industrial action. Executive misconduct. Maybe the CEO got caught doing something exceptionally stupid at the staff Christmas party. Either way, there would be a meeting, somebody would call the communications team, a holding statement would be drafted, lawyers would remove every useful word from it, and several hours later, management would approve what little remained.

But that model is increasingly becoming obsolete because the next crisis facing your organisation may begin with somebody stealing your customers’ data at 2:13 in the morning, cloning your CEO’s voice by 2:20, producing a convincing video of him admitting responsibility by 2:27, and having the whole thing circulating on WhatsApp before your communications director has found his glasses.

Just last week, the Ministry of Science and Technology revealed that over five million attempts were made to breach Jamaica’s digital systems in the first three months of 2026, reiterating its call for stronger cybersecurity measures across the country.

Welcome to crisis communication in the age of artificial intelligence, where an organisation can lose control of its reputation before senior management even knows there is a problem.

THE OLD CLOCK NO LONGER WORKS

The fundamental difference between the old crisis environment and the new one is speed. Artificial intelligence and cyber have changed one of the most important variables in crisis management: Time.

Traditional crisis plans often assume that organisations will have some opportunity to gather information, convene senior leadership, consult lawyers, prepare messages, and then communicate. But cyber incidents do not always allow that luxury. Sometimes the first public sign of a breach is not a carefully worded company statement, but rather the hacker announcing it. And sometimes, the first “statement” attributed to the organisation may itself not even be real. That means the modern crisis communication plan must be designed around the uncomfortable possibility that your communications channels may themselves be part of the crisis.

If the company email is compromised, how do you reach employees? If the website is down, where does the public go for verified information? If the CEO’s WhatsApp account has been hacked, who confirms which instructions are genuine? And if a video surfaces showing a senior executive apparently admitting wrongdoing, who determines whether it is authentic? These are no longer hypothetical questions.

CYBER IS NOT AN IT PROBLEM

One of the biggest mistakes organisations still make is treating cybersecurity incidents as primarily technical matters. The IT team handles the breach, the communications team handles the media, legal handles the regulators, and management waits for somebody to tell them what happened.

That separation may look neat on an organisational chart, but real crises are considerably messier. A ransomware attack may simultaneously become an operational crisis, a legal crisis, a financial crisis, a customer-service crisis, and a reputational crisis all at once. This is why effective crisis communication cannot be bolted onto cyber response after the technical people have finished their work. Rather, it has to be built into the response from the beginning.

In every serious crisis, one of the most important questions is surprisingly simple: Who has the authority to speak? That question becomes even more important during AI and cyber incidents because facts are often incomplete. The communications team may know that something has happened but not exactly what. The technical team may understand the breach but be uncomfortable explaining it publicly. The lawyers typically want absolute certainty before anybody says anything, and senior management may be afraid that speaking too early creates legal exposure. So everybody waits.

But silence creates a vacuum, and the Internet abhors a vacuum. Somebody will fill it. A disgruntled employee. A hacker. A fake account. A badly informed WhatsApp voice note or a budding TikTok blogger striving to go viral. The organisation that communicates first does not automatically win, but the organisation that establishes itself early as the most credible source of verified information has a fighting chance.

THE FIRST STATEMENT DOESN’T NEED ALL THE ANSWERS

Organisations often delay communication because they believe they must fully understand the incident before saying anything. But a credible first response may simply acknowledge awareness of the incident and establish that response protocols have been activated. It may also state that technical specialists and the relevant authorities are already in the picture and explain what customers or employees should do right now.

That kind of disciplined communication establishes the organisation as the primary source of verified information, and in a crisis, that position matters greatly. People will forgive uncertainty, but they are much less forgiving of silence, contradiction, or the impression that management has lost control.

Artificial intelligence adds another layer of difficulty to the problem because the crisis itself may be entirely fictional and fabricated. Imagine a convincing video appearing online showing your CEO announcing that the company is insolvent or the minister of finance apparently announcing an emergency bank closure. By the time somebody says, “This is fake news”, the recording has already been forwarded through 247 WhatsApp groups, liked, shared, and reposted on TikTok and doing the rounds on morning radio.

Organisations, therefore, need established verification mechanisms, official channels, and known spokespersons. They also need pre-agreed methods for authenticating urgent instructions and procedures for identifying and escalating. You do not want to be inventing those procedures while a fake recording is now 200,000 views strong.

A PLAN YOU HAVE NEVER TESTED IS NOT A PLAN

But writing the plan is the easy part. Testing it is where the real work begins. Take the website offline. Compromise the CEO’s email. Pretend customer data has appeared on the dark web. Then tell the team that three journalists are at the gates. You may be surprised how quickly that impressive 60-page crisis plan begins sweating at the seams.

Crisis communication cannot be treated as something the communications department “handles” after the emergency occurs. It requires preparation, clear authority, scenario planning, training, and critically, executive involvement. And perhaps most importantly, it needs somebody to look at the organisation from the outside and ask the uncomfortable questions management may not think to ask itself.

Major Basil Jarrett is the director of communications at the Major Organised Crime and Anti-Corruption Agency (MOCA) and crisis communications consultant. Follow him on Twitter, Instagram, Threads @IamBasilJarrett and linkedin.com/in/basiljarrett. Send feedback to columns@gleanerjm.com.