The First 72 Hours of a Corporate Crisis: A Legal Framework for Australian Businesses

Insights | Investigations & Disputes

Corporate crises rarely arrive in an orderly form.

A whistleblower complaint may allege fraud. A cyber incident may expose confidential information. A regulator may issue a compulsory notice. Allegations concerning a senior executive may surface publicly before an internal investigation has even begun.

In each case, the pressure is immediate: establish the facts, contain the problem, protect the organisation, and decide what to say. The decisions made in the first hours can shape litigation, regulatory exposure, privilege, insurance, disclosure, and reputation long after the immediate event has passed.

The objective in the first 72 hours is not to solve the entire problem. It is to establish control, preserve options, and create the conditions for sound decision-making.

What Businesses Should Do First

The response should begin with six priorities:

  • Establish control: Appoint a clear decision-maker and crisis response team.
  • Preserve evidence: Suspend routine destruction and secure relevant records, devices, and systems.
  • Involve legal advisers early: Identify immediate obligations and structure the investigation carefully.
  • Assess notification requirements: Consider regulators, ASX, privacy, safety, insurers, lenders, and contractual counterparties.
  • Control communications: Distinguish known facts from allegations and speculation.
  • Define the investigation: Determine scope, independence, reporting lines, and how findings will be documented.

The 72-hour framework is not a legal grace period. Some obligations may require action considerably sooner.

The First 24 Hours: Stabilise, Preserve, and Identify Obligations

A corporate crisis can simultaneously engage legal liability, governance, operations, insurance, employment, contracts, financial markets, and reputation. The response therefore needs central coordination from the outset.

The organisation should establish who leads the response, who instructs advisers, who reports to the board, who communicates with regulators, and who controls external communications. A large response team is not necessarily an effective one. Clear authority and reporting lines matter more.

Evidence preservation should occur before the organisation attempts to reconstruct the full story. Relevant material may include emails, messaging applications, financial records, system logs, mobile devices, CCTV, access records, and physical documents. Routine deletion or destruction processes may need to be suspended.

In cyber incidents, containment requires particular care. Australian Signals Directorate guidance warns that powering down affected systems can destroy information valuable to forensic investigations. Containment and preservation should therefore be managed together.

Legal Professional Privilege Should Be Considered at the Outset

Legal professional privilege does not arise simply because a lawyer is copied into an email or an investigation is labelled "privileged".

The High Court has adopted a dominant-purpose test. In broad terms, the relevant communication or document must have been created for the dominant purpose of obtaining or providing legal advice, or for use in actual or anticipated litigation where the applicable requirements are met.

An internal investigation may serve several purposes at once: establishing facts, making employment decisions, improving systems, satisfying a regulator, and obtaining legal advice. If privilege matters, the investigation should be structured deliberately from the beginning — including who is the client, who instructs counsel, how experts are engaged, and how reports are commissioned.

The legal position should be preserved from the outset, not assembled retrospectively.

Do Disclosure or Notification Obligations Arise Immediately?

Potential notification obligations should be mapped early, because different regimes operate on different triggers and timelines.

For ASX-listed entities, Listing Rule 3.1 may require immediate disclosure of market-sensitive information, subject to the exceptions in Listing Rule 3.1A. ASX guidance explains that "immediately" means promptly and without delay.

For suspected eligible data breaches, an entity subject to the Privacy Act must take all reasonable steps to complete its assessment within 30 calendar days of becoming aware of grounds for the suspicion. The OAIC treats 30 days as a maximum and expects assessments to be completed sooner where possible.

Other incidents may require notification to workplace safety authorities, insurers, lenders, contractual counterparties, law enforcement, or sector-specific regulators.

The practical point is simple: a crisis cannot automatically remain internal merely because the investigation is incomplete.

Whistleblower Matters Require Additional Discipline

Where the crisis begins with a protected whistleblower disclosure, confidentiality and anti-detriment obligations can materially affect the investigation.

ASIC states that company officers must not disclose a whistleblower's identity, or information likely to identify them, unless authorised by law, and must not cause or threaten detriment because of a protected disclosure.

The complaint should not be circulated more widely than necessary. Investigators should also avoid approaching witnesses in a manner that unnecessarily identifies the whistleblower.

At the same time, people against whom allegations are made must be treated fairly. A properly designed investigation manages confidentiality, procedural fairness, evidence preservation, and the need to determine what actually occurred.

Hours 24 to 48: Build the Investigation Architecture

Once immediate risks are stabilised, the organisation should define the investigation. The starting point is a clear question: what is the organisation trying to determine?

The scope should identify the initial issues and establish a process for expanding the investigation if further matters emerge.

The organisation should also decide whether the investigation can be conducted internally or whether independence requires external lawyers, forensic specialists, or investigators. External independence may be particularly important where allegations concern senior management, directors, or the personnel who would ordinarily investigate the issue.

The investigation plan should address document collection, witness sequencing, electronic material, interview records, confidentiality, privilege, and the form of the final report. Decisions about reporting should be made early, because they can affect privilege, disclosure, and procedural fairness.

Communications should remain controlled. Internal messages should distinguish facts from allegations, avoid blame or premature conclusions, and reach only those who need the information.

Externally, public statements should not outrun the facts. Descriptions such as "isolated", "contained", or "no wrongdoing occurred" can create real difficulty if later evidence proves otherwise.

Hours 48 to 72: Move From Reaction to Strategy

By the second and third day, the organisation should be shifting from immediate containment to a structured forward strategy. There should be growing clarity around the investigation, evidence, regulatory obligations, communications, insurance, operational consequences, and board oversight.

The board should receive enough information to discharge its oversight responsibilities without becoming the operational investigation team. Useful questions include:

  • What is known, and what remains uncertain?
  • What evidence supports the current assessment?
  • What notifications or disclosures may be required?
  • Who is directing the investigation?
  • What could materially change the organisation's position over the next 24 hours?

Scenario planning should also begin. The organisation should consider what happens if allegations are substantiated, further misconduct is discovered, a regulator intervenes, information becomes public, or litigation follows.

Insurance and contracts should not be overlooked. Policies may impose notification requirements or require insurer consent before costs are incurred. Contracts and financing documents may contain notice requirements, audit rights, cybersecurity obligations, indemnities, termination rights, or default provisions.

What Should Businesses Avoid?

Common early mistakes can materially worsen the position. Businesses should avoid:

  • Destroying or altering relevant material.
  • Conducting uncontrolled witness interviews.
  • Circulating sensitive allegations more widely than necessary.
  • Making definitive public statements before facts are established.
  • Assuming every lawyer-involved communication is privileged.
  • Delaying consideration of disclosure obligations.
  • Allowing multiple people to communicate independently with regulators.

The objective is not perfect information. It is disciplined decision-making under imperfect information.

Preparation Begins Before the Crisis

The most effective crisis responses usually begin before an incident occurs.

Organisations should already know who leads the response, which advisers and insurers to contact, where critical information is held, how board escalation occurs, and who has authority to communicate externally.

Cyber response plans should be tested. Whistleblower procedures should work in practice. Delegations and escalation thresholds should be understood. A response plan that exists only in a policy folder is of limited value.

The First 72 Hours Can Shape What Follows

Corporate crises are defined as much by uncertainty as by urgency.

The strongest response does not come from the organisation with every answer on day one. It comes from the organisation that quickly establishes the right process for obtaining those answers — while preserving its legal position and keeping control of the broader business consequences.

In the first 72 hours, the goal is controlled action: preserve the evidence, understand the obligations, establish the facts, and make each decision with a clear appreciation of what may follow.

How We Can Help

We advise corporations, boards, executives, and individuals on complex disputes, regulatory and internal investigations, corporate governance, and reputational risk.

We assist clients from the earliest stages of a crisis, establishing investigation frameworks, preserving privilege and evidence, managing regulatory engagement, advising boards, and coordinating litigation and broader crisis-response strategy.

Speak with Our Investigations & Disputes TeamSend an Enquiry

This publication is current as at 24 September 2026, which we believe may be of interest to our clients and friends of the firm, and is for general information only. It does not constitute legal, financial, investment or tax advice.