Data breaches, regulatory enforcement actions, market disruptions, and executive scandals can destroy financial brands overnight. The companies that survive crises are the ones that prepared before they happened. We build crisis communication frameworks so your team knows exactly what to do when it matters most.
You have no crisis playbook and the clock is already ticking
Most financial services companies have no documented crisis communication plan. When a breach occurs, a regulator acts, or a journalist calls, the response gets improvised – emails drafted by committee, legal and PR fighting over language, hours passing while customers and media demand answers. In financial services, a delayed or confused response doesn't just damage reputation, it can trigger regulatory penalties and customer withdrawals.
Your crisis team doesn't know who does what
When a crisis hits, who makes the call on public statements? Who talks to regulators? Who handles customer communication? Who briefs the board? In most financial companies these roles aren't defined until the crisis is already underway, which produces conflicting messages and dangerous delays. The first hour sets the trajectory for everything that follows, and most teams spend that hour figuring out roles instead of executing them.
Regulatory notification requirements add pressure other industries don't face
Financial services companies carry specific regulatory obligations during a crisis – breach notification windows, SEC disclosure rules, banking regulator communications, and state-level notification laws that vary by jurisdiction. Missing one of these deadlines doesn't just create a PR problem, it creates legal exposure. A crisis plan that only covers messaging and skips the notification calendar is incomplete.
Social media turns internal problems into public crises in minutes
A customer complaint on X, a leaked internal document, or a screenshot of a system outage can go viral before your communications team is even notified. Financial services companies are high-visibility targets for online criticism because money is emotional and outages get screenshotted immediately. Without active social monitoring and a rapid response protocol, small incidents escalate into full-blown reputational events within hours.
We build crisis communication frameworks tailored to the specific risks financial services companies face. This starts with a vulnerability assessment – mapping the scenarios most likely to hit your business (data breaches, system outages, regulatory actions, executive departures, market events, fraud, compliance failures) and rating your current readiness for each one honestly, not optimistically.
For each high-probability scenario we build a crisis playbook with specific response protocols: pre-approved message templates, stakeholder communication sequences, a regulatory notification checklist mapped to real deadlines, media response guidelines, and a social monitoring and escalation procedure. The playbook is written so your team can execute under pressure without improvising language or waiting on legal sign-off mid-crisis.
We define the crisis team itself – who's on it, what each person owns, how the team gets activated, and who has decision authority at each severity level. In financial services this typically spans communications, legal, compliance, executive leadership, and customer support, with a clear escalation path so a level-1 incident doesn't sit on someone's desk waiting for a level-3 sign-off chain.
A playbook nobody has practiced is barely better than no playbook, so training is where the framework actually gets stress-tested. We run tabletop exercises – simulated crisis scenarios where your team executes the response in real time, under artificial time pressure and with a real linked internal [growth strategy](/services/strategy/) so crisis response ties back to how you're already communicating with customers day to day. These sessions expose the gaps a document review never catches.
Winston Francois takes an operator approach here, not a documentation exercise. We build frameworks that are practical and executable, not 200-page binders nobody opens. The target is a team that can respond to any scenario within 60 minutes with a coordinated, compliant, and credible message – and knows it, because they've done it in a drill before they've done it for real.
In financial services crisis communications, speed and transparency beat perfection every time. A company that says 'we detected an issue, here's what we know, here's what we're doing, we'll update you in 2 hours' within 30 minutes outperforms a company that spends 6 hours crafting the perfect statement. Silence in a crisis is never read as diligence – it's read as hiding something.
Our 90-day crisis readiness sprint opens with a 30-day assessment. We evaluate your current preparedness, map the most likely and highest-impact scenarios, review your regulatory notification obligations, and interview the people who'd actually be in the room – legal, compliance, communications, customer support, and executive leadership – about what they think their role would be in a real crisis. The gaps between what they think and what's actually documented are usually the most useful finding of this phase.
Days 30-60 are framework development. We build the crisis playbooks, draft pre-approved message templates, define the crisis team structure, and produce the regulatory notification checklists. This runs in close collaboration with your legal and compliance teams so every template and procedure clears your actual approval chain before it's finalized, not after.
Days 60-90 are training and testing. We run 2-3 tabletop exercises simulating different scenarios and test whether your team can actually execute the playbooks under pressure, not just read them. After each exercise we debrief, log the gaps, and update the framework. The goal isn't a finished document – it's a team that has rehearsed enough to move fast and stay coordinated when the real thing happens, which for most companies is a matter of when, not if.
The first 30 days are assessment. We interview leadership, legal, compliance, communications, and customer support, review any existing crisis documentation, audit your social monitoring setup, and map your regulatory notification obligations against your actual products and jurisdictions. The vulnerability assessment lands by day 30.
Days 30-60 are document production. Our team drafts the crisis playbooks, message templates, and team charter, with legal and compliance review built into the process – every template moves through your approval chain before it's considered final, so there's no scramble mid-crisis over language that hasn't been cleared.
Days 60-90 are tabletop exercises and refinement. Each exercise runs 2-3 hours and simulates a realistic scenario with time pressure, media inquiries, and regulatory requirements layered in as it unfolds. We facilitate, debrief the team afterward, and update the playbooks based on what the simulation actually revealed rather than what we assumed going in.
Crisis readiness engagements run 3-4 months for the initial framework, with optional annual refreshes covering updated scenarios, new tabletop exercises, and template updates. We also offer rapid-response retainers for companies that want our team on call when an incident is actually happening, separate from the readiness build itself. Related work on [brand strategy](/services/creative/) often surfaces in this phase too, since the crisis voice has to match the brand voice customers already know.
If your financial services company needs crisis communications leadership, we should talk.
Let us take a custom approach to your growth goals by assembling and leading the best-in-class marketing team to support your next stage.
The initial crisis readiness sprint typically runs $25K-$45K over 3-4 months, covering assessment, playbook development, and tabletop exercises. Annual refresh retainers run $8K-$15K. Rapid-response retainers, which put our team on call during actual incidents, run $3K-$5K per month. Weigh that against the cost of a mismanaged crisis – customer attrition, regulatory fines, and brand damage that can take years to undo.
At minimum, annually. You should also update after any real crisis to capture lessons learned, after major business changes like new products or leadership, and after regulatory changes that shift your notification requirements. We recommend an annual tabletop exercise specifically to catch gaps that organizational changes create between refreshes.
At minimum: data breaches and cybersecurity incidents, system outages affecting customer access, regulatory enforcement actions, executive misconduct or departure, internal or external fraud, market events affecting customers, and negative media coverage. We prioritize based on your specific business – a consumer neobank faces a different risk profile than a B2B payments processor, and the playbook should reflect that instead of treating every scenario as equally likely.
We build practical, executable frameworks, not shelf-ware. Our playbooks come with pre-approved templates, clear decision trees, and specific timing requirements so a team can act without waiting on a meeting. We bring an operator's view of coordination too – crisis response is as much about getting legal, compliance, customer support, and leadership moving in sync as it is about the actual messaging. Our tabletop exercises are built to be realistic enough to genuinely stress-test that coordination, not just walk through a script.
Yes, through our rapid-response retainer. When a crisis hits, our team activates within the hour to support your response – drafting statements, coordinating messaging across channels, managing media inquiries, and making sure regulatory notifications go out on time. This runs separately from the readiness program, which is what builds the framework your team executes when we're not directly involved.
A tabletop exercise is a facilitated simulation where your crisis team practices responding to a realistic scenario in real time. We introduce developments as the exercise unfolds – a media call, a customer complaint spike, a regulatory inquiry – mimicking how a real incident actually escalates. Your team practices executing the playbook and making decisions under time pressure across functions, and each session, typically 2-3 hours, ends with a structured debrief that feeds directly back into the [measurement](/services/measurement/) of how ready the team actually is versus how ready the document says they are.
Tuesday, June 16, 2026
Frank Growth – Episode 224 – The Bootstrapper’s Revenge with Alex Roy
Tuesday, July 21, 2026
Frank Growth – Episode 229 – Longevity Medicine’s Dirty Secret with Jim Donnelly
Tuesday, July 14, 2026
Frank Growth – Episode 228 – Your Bookkeeper Is Failing You with John Zdanowski
Tuesday, August 11, 2026
Frank Growth – Episode 232 – His AI Employee Works While He Sleeps with Andrew Mok
Ready to unlock your growth?
Book Free Call