When uncertainty becomes a threat – preparing crisis teams for misinformation

When uncertainty becomes a threat - preparing crisis teams for misinformation

In a crisis, the challenge is not always a lack of information. It is knowing what information you can trust, what remains uncertain and when you need to act anyway.

I recently read an article in International Security Journal about the impact misinformation had on organisations during Kenya’s 2024 protests.

Security managers were dealing with reports of road closures before roads had actually been blocked, old footage being shared as though it were current and warnings being passed around through employees’ family WhatsApp groups. In some cases, organisations postponed executive travel, asked employees to work remotely or suspended non-essential operations based on reports that later proved inaccurate. 

One line in particular stood out: “uncertainty itself had become a threat.” 

It struck me because this is something we don’t always replicate particularly well when we’re planning or exercising for a crisis. We know that the early stages of an incident can be confusing and that decisions are often made without having the full picture, but there is still a tendency to think about crisis management in terms of responding to something that we know has happened. 

The reality can be much messier. Information may be coming from security teams, employees, news reports, social media, local contacts and senior leaders’ own networks and those sources may be telling you different things. A message from someone an executive knows and trusts can carry considerable weight, even if nobody else in the room has been able to verify it. A video circulating online can quickly start influencing decisions before anyone has established when or where it was filmed. 

We also naturally give more weight to some sources than others. If an employee hears something from a family member who lives close to an incident, or a senior leader receives a message from a contact they have known for years, it can feel credible. The difficulty is that our trust in the person sharing the information doesn’t necessarily tell us anything about the accuracy of the original information. 

It would be easy to conclude that everything needs to be verified before anyone acts, but in a crisis that often isn’t realistic. If there is a credible threat to employees, an executive or a site, waiting for absolute certainty could be the wrong decision. 

Crisis teams therefore need to know how much confidence they can place in the information in front of them. What has been confirmed? What is still an assumption? What haven’t we been able to establish yet? They then have to decide what they are prepared to do on that basis. 

There are consequences on either side. Acting too quickly on inaccurate information could mean cancelling executive travel, closing a site, disrupting operations, or unnecessarily alarming employees, and clients. Waiting for information to be fully verified could be far more serious if the threat turns out to be genuine. Crisis teams have always had to make these judgements, but the amount of information now circulating and the speed at which it reaches people across a business makes them harder. 

This is worth thinking about before an incident happens. Which sources would the organisation normally rely on? Who would be responsible for checking a report and information that could materially change the response? How much time do you have to decide? How would the crisis team know whether something had been confirmed or was still being treated as an assumption?  

That last point is particularly important. During a fast-moving incident, an unverified report can be repeated several times, picked up by different people and gradually become accepted as fact. By the time it reaches the crisis team, the uncertainty around the original information may have disappeared. 

The organisation doesn’t need a lengthy verification process that slows everything down. Sometimes the right decision will still be to act on information that hasn’t been confirmed. The people making that decision should, however, know that’s what they’re doing. 

It also made me think about crisis exercises. When participants are given information during an exercise, there is an understandable tendency to accept it as fact. It has come from the exercise team, so why wouldn’t they? In a real incident, this will need to be addressed where someone  is filtering the information reaching the crisis team to make sure it is accurate. So why isn’t this also exercised? 

There is an argument for introducing more uncertainty deliberately. Two credible reports that contradict one another. A senior executive who receives information from a trusted contact that doesn’t match the official picture. An employee sharing footage that appears to show an incident at one of your locations, but which hasn’t yet been verified. 

What the team does with that information could tell you a lot. Do they challenge it? Does the source affect how much weight they give it? Does somebody take responsibility for checking it? When a decision is made, does everyone understand which parts of the situation have been confirmed and which haven’t? 

Crisis exercises should reflect some of the difficulties people are likely to face when something really happens. Increasingly, one of those difficulties will be deciding what information they can trust and what they are prepared to do when they can’t be completely sure. Importantly, crisis management teams must have a clear understanding on how much time they will have to decide, and what resources are available to help them in those decisions.  

The International Security Journal article argues that information resilience should form part of crisis-management structures. That feels like a sensible place to start. Organisations can’t expect to have all the facts during a crisis, but they can prepare their people to make better decisions when they don’t. 

Author – Gavin Wilson, Director of Physical Security and Risk

References

https://internationalsecurityjournal.com/misinformation-security-africa/Â