Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryCrisis Management Plan (CMP)
Contents & downloads
- GOV-POL-002
- QHSE-PLN-001
- QHSE-PRO-001
- TEC-PRO-001
Nomenclature
| Term | Definition |
|---|---|
| ASD | Australian Signals Directorate. |
| BCP | Business Continuity Plan (QHSE-PLN-001). |
| BCS | Becloudsmart — Westlink’s external managed cloud services provider (MCSP) for Microsoft 365 administration, identity and access control. |
| CMP | Crisis Management Plan (this document). |
| CMT | Crisis Management Team — the enterprise-level command group convened on declaration of a crisis. |
| CRE | CRE Insurance Broking — Westlink’s insurance broker and first contact for insurable events. |
| DISP | Defence Industry Security Program. |
| ICT | Information and communications technology. |
| MAO | Maximum Acceptable Outage — the longest a critical function can be unavailable before the organisation suffers unacceptable harm. Held in the BCP. |
| MCSP | Managed Cloud Services Provider. |
| NDB | Notifiable Data Breach (Privacy Act 1988 (Cth) Part IIIC). |
| OAIC | Office of the Australian Information Commissioner. |
| RPO | Recovery Point Objective — the maximum tolerable data loss measured in time. Held in the BCP. |
| RTO | Recovery Time Objective — the target time within which a function must be restored after a disruption. Held in the BCP. |
| SaaS | Software as a Service — cloud-delivered software applications. |
| SPP | Security Policies and Plans — Westlink’s DISP security governance document (DEF-POL-001). |
| VoIP | Voice over Internet Protocol — internet telephony. Westlink uses the 3CX platform. |
Purpose
This plan establishes how Westlink detects, declares, directs and de-escalates a crisis, safeguarding its people, information, operations, customers and reputation. It provides enterprise-level command and communications; operational recovery then follows the Business Continuity Plan (QHSE-PLN-001).
The plan is aligned with ISO 22301:2019 (Business Continuity Management Systems) and integrates Westlink’s DISP Entry level obligations through the Security Policies and Plans (SPP). It supports Westlink’s JOSCAR-AU 2026 crisis-management commitment.
Scope
This plan applies to all Westlink personnel (employees and contractors), projects and critical functions, at any hour. Westlink is a remote-capable organisation operating from its Perth head office with a regional presence in Brisbane (QLD) and a Singapore-based staff member; the Crisis Management Team can convene and direct the response from any location.
The crisis types in scope are cyber and information security; premises loss or emergency; supply-chain disruption; workforce unavailability and health and safety; serious incident or fatality; and reputational, media or legal escalation.
Relationship to the Business Continuity Plan
The Business Continuity Plan (QHSE-PLN-001) holds the recovery tolerances (MAO, RTO and RPO), continuity measures and recovery playbooks. This Crisis Management Plan governs crisis activation, command decisions, stakeholder communications and regulatory and contractual notifications, and is used in conjunction with the BCP. On declaration, the Crisis Management Team directs the enterprise response and communications while the BCP playbooks execute operational continuity and recovery.
Definitions
A crisis is an event that threatens Westlink’s people, critical services, legal or contractual obligations or reputation, and that requires enterprise coordination. Continuity is the ability to maintain or restore critical functions within their defined recovery tolerances, as set out in the BCP. Acronyms and specialist terms are defined in the Nomenclature table in the front matter.
Standards and Obligations
This plan is read with the ISO 22301:2019 business-continuity framework and Westlink’s DISP Entry level obligations implemented through the SPP. Where a cyber incident involves a ransomware or cyber-extortion payment, a report to the Australian Signals Directorate is mandatory within 72 hours under the Cyber Security Act 2024 (Cth) Part 3; that obligation is owned by the Cyber Security Procedure (TEC-PRO-001), which this plan cross-references rather than duplicates.
Objectives and Targets
The objectives of this plan are to:
-
Protect the safety of personnel, and the security of Westlink information, assets and reputation, throughout a crisis;
-
Provide clear authority to declare, direct and stand down a crisis, with a defined command structure and escalation;
-
Meet Westlink’s regulatory, contractual, DISP and customer notification obligations during a crisis; and
-
Coordinate with the Business Continuity Plan for operational recovery, and improve the plan after each event.
Governance and Activation
The default crisis lead is the Chief Executive Officer (CEO). If the CEO is unavailable, the fallback order is FTM, then Operations Manager, then QLD Regional Manager, then Chartering Manager. Stand-down requires the agreement of both the FTM and the CEO, and confirmation that recovery is within the BCP tolerances and backlogs are under control. When in doubt, a crisis is declared early and scaled back.
A crisis is declared, for example, when any of the following occurs:
-
A life-safety or site emergency exceeds local response capability;
-
A cyber incident involves material data compromise, an outage beyond four hours, or a likely regulatory or contractual notification;
-
A major supply-chain disruption affects delivery, liabilities or Defence-relevant work; or
-
A reputational, media or legal escalation creates enterprise-level exposure.
Roles and Responsibilities
On declaration, the FTM assigns a severity band, which determines the response posture and communications cadence.
| Band | Impact |
|---|---|
| P1 | Critical |
| P2 | Major |
| P3 | Moderate |
| P4 | Minor |
The Crisis Management Team (CMT) is the enterprise command group and shares its core membership with the Business Continuity Steering Committee. Legal, public-relations, Becloudsmart and CRE Insurance specialists are co-opted as required.
| Role | Incumbent |
|---|---|
| Chief Executive Officer (CEO) | John A. Di Giovanni |
| Finance and Technology Manager (FTM) | Craig Foreman |
| Operations Manager (OM) | Rob Carbon |
| QLD Regional Manager (QRM) | Brian Harrington |
| Chartering Manager (CM) | Manu Kohli |
The crisis lead (CEO by default) declares the level, sets objectives, approves communications, and coordinates regulatory and insurer notifications with the FTM. Operations (OM, QRM and CM) coordinate customers and suppliers, routing and HSEQ controls. ICT containment is run by the FTM with Becloudsmart; insurance is run by the FTM with CRE. Responsibilities for the key crisis activities are allocated below (R = responsible, A = accountable, C = consulted, I = informed).
| Activity | CEO | FTM | OM | QRM | CM | BCS | CRE |
|---|---|---|---|---|---|---|---|
| Declare incident level | A | R | C | C | C | C | I |
| Cyber containment | I | A | I | I | I | R | I |
| Customer communications | A | I | R | R | C | — | — |
| Supplier rerouting | A | I | R | C | R | — | — |
| Insurance notification | A | R | C | C | C | I | R |
Activities and Schedule
The crisis response is organised as scenario playbooks. Each playbook emphasises crisis-level command and policy integration; the operational recovery steps are governed by the Business Continuity Plan (QHSE-PLN-001). The immediate first-response checklist for a P1 or P2 event is at Appendix A.
Cyber attack or data breach
Within the first two hours the crisis lead declares the level and opens the incident log; Becloudsmart disables affected accounts, revokes tokens, resets credentials, isolates endpoints and tightens conditional access; evidence is preserved; and impacts are assessed against the BCP tolerances. Personnel shift to clean devices and work from home, using SaaS retention and versioning under heightened monitoring.
Notifications are made as required: a Notifiable Data Breach assessment and, where the threshold is met, notification to the OAIC and affected individuals; a report to the Australian Signals Directorate within 72 hours where a ransomware or cyber-extortion payment is made or proposed (mandatory under the Cyber Security Act 2024 (Cth) Part 3); a ReportCyber report to the ASD as soon as practicable; DISP reporting through the SPP; contractually required customer notices; and notification to CRE Insurance. These notifications are executed under the Cyber Security Procedure (TEC-PRO-001) and the Privacy Policy.
Premises loss or emergency
Life-safety is addressed first; personnel are accounted for and local evacuation procedures completed. The default posture is company-wide work-from-home; inbound numbers are rerouted to mobiles through the 3CX platform; SaaS health is verified; and facilities restoration is managed.
Supply-chain disruption
Port and road alerts and supplier communications are monitored, and the risk register is updated where Defence work is affected. Pre-qualified alternates are activated and laycan or routing adjusted. Force-majeure and variation clauses are applied under Westlink’s terms and the Contract, Legal and Insurance Review process.
Workforce unavailability and health and safety
Wellbeing and fatigue controls are enforced and remote-first continuity maintained. Alternates are kept ready with SaaS and MFA access, with handover through Teams. Where a safety or regulatory reporting obligation arises it is escalated under the Hazard and Incident Reporting and Investigation Procedure (QHSE-PRO-001).
Serious incident or fatality
Medical and emergency services are engaged and the scene secured; regulator notifications are made as applicable; evidence is preserved; and internal and external communications are coordinated. The event is investigated and lessons captured under the Hazard and Incident Reporting and Investigation Procedure (QHSE-PRO-001).
Reputational, media or legal escalation
A single-voice principle applies: external statements are approved by the CEO, using pre-approved holding lines, and coordinated with the insurer and legal counsel where litigation or claims are likely.
Resources
The standing resources that support crisis command are maintained between events:
-
Governance and policy — cyber controls under the Cyber Security Procedure (TEC-PRO-001); personal data handled under the Privacy Policy; DISP Entry level controls under the SPP; and wellbeing and fatigue controls under the Work Health and Safety Policy (GOV-POL-002);
-
Technology and communications — Teams and Microsoft 365 for command and coordination; pre-configured VoIP rerouting and overflow to mobiles on the 3CX platform; and Becloudsmart managed cloud services and identity administration; and
-
People and process — the Business Continuity Plan (QHSE-PLN-001) for recovery tolerances and playbooks; CRE Insurance Broking as the insurance broker; and pre-approved holding statements and incident and decision log templates.
Key personnel and vendor contacts are maintained in the contact directory at Appendix B.
Monitoring and Reporting
Communication during a crisis is timely, accurate, least-privilege and customer-first, with a single source of truth and a one-voice principle for external messaging. Primary channels are Teams and Microsoft 365 email, VoIP and mobile, with SMS as a fallback and a website notice where external communication is required. Stakeholder notification triggers and service levels are set out below.
| Stakeholder | Trigger | Owner | Channel | Service level |
|---|---|---|---|---|
| All workers | P1 / P2 declared | FTM | Teams + email | 60 min |
| Key customers | Service impact ≥ 4 h | OM / QRM | Phone / email | As needed |
| Carriers / agents | Reroute or alternates | OM / CM | Phone / email | As needed |
| CRE Insurance | Insurable event | FTM | Phone / email | Immediate |
| DISP / Defence | DISP-relevant event | Per SPP | Per SPP | Per SPP |
Regulatory and contractual notifications during a crisis are: an OAIC Notifiable Data Breach assessment, with notification within 30 days where the threshold is met; a ReportCyber report to the ASD as soon as practicable; the mandatory 72-hour ASD ransomware-payment report under the Cyber Security Act 2024 (Cth) Part 3 where applicable; DISP and Defence reporting under the SPP; and customer notices and insurer notification per contract and the Contract, Legal and Insurance Review process. Evidence and records are preserved with chain of custody, and personal data is restricted to need-to-know under the Privacy Policy.
Review
The plan is exercised and maintained on the following cycle, and is reviewed at least annually and after any activation or material organisational change.
-
Quarterly — a Crisis Management Team tabletop against a rotating scenario (cyber, premises loss, supply chain, workforce);
-
Half-yearly — technical drills of VoIP reroute failover, clean-device SaaS access and alternate communications;
-
Annually — a full exercise of company-wide remote-work continuity and crisis communications, including continuity when the crisis lead is unavailable; and
-
After every activation — an after-action review that captures lessons, updates this plan and the Business Continuity Plan, and refreshes Defence security awareness and insider-threat training.
References
This plan is read in conjunction with ISO 22301:2019 (business continuity management systems), the Cyber Security Act 2024 (Cth) Part 3, the Privacy Act 1988 (Cth) Part IIIC (Notifiable Data Breach scheme), the Defence Industry Security Program (DISP) Entry level requirements, and the internal documents listed in the Related Documents table in the front matter — in particular the Business Continuity Plan (QHSE-PLN-001), the Cyber Security Procedure (TEC-PRO-001), the Hazard and Incident Reporting and Investigation Procedure (QHSE-PRO-001) and the Work Health and Safety Policy (GOV-POL-002).
Compliance coverage — cited by 1 requirement across 1 framework
JOSCAR-AU 2026(1)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q2.6.12 | Q2.6.12 | Full | Crisis Management Plan — enterprise crisis command, scenario playbooks, communications and regulatory notifications, and exercising regime. |
Declared compliance references (1)
JOSCAR-Q2.6.12
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 08/06/2026 | WLK-GBL-QHSE-PLN-003 | Crisis Management Plan (CMP) | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | Initial issue in new WMS. Rebuilt from legacy WLK-GBL-QHSE-PLN-003 and renumbered to QHSE-PLN-002. Wired to JOSCAR-AU 2026 Q2.6.12. |