Corporate reputation management is not a crisis response. It is three disciplines: establish trust, protect it, restore it, long before anything goes wrong.
Most boards get the order backwards. They wait for a crisis, then ask legal and communications to build a practice that should already exist.
The starting point is behaviour, not messaging. A statement describes what you did. It cannot replace doing it well, and that gap is where most recoveries fail.
This is the standing discipline, not the reactive one. Managing a live reputation crisis is the narrower job, once something has broken.
Crisis communications governs what you say during that event. Corporate reputation management decides whether anyone believes you, every other day of the year.
Most corporate reputation management services only show up after the story breaks. The useful version works before that, inside the board’s own governance.

The Author – Peter Wilkinson
Why The Sequence Matters Now
What corporate reputation actually means is straightforward: it is what stakeholders believe about an organisation based on its conduct, not its statements.
Optus supplied the case study Australia keeps relearning. In September 2022 it disclosed a breach, later specified by the privacy regulator as affecting around 9.5 million people, caused by an unauthenticated, internet-facing API.
Medibank followed within weeks: health claims data for roughly 9.7 million customers, stolen and published on the dark web after the insurer refused to pay the ransom demanded.
Both companies are now defendants in the Federal Court, sued separately by the Australian Information Commissioner, Optus since August 2025 and Medibank since June 2024, over whether they took reasonable steps to protect that data.
I ask every board the same question before we discuss a single word of messaging: what have you actually verified, not what have you announced.
Two Federal Court cases running at once is not a coincidence. It is what happens when reputation is treated as a communications problem instead of a governance one.
Corporate Reputation Management: The Three-Part Framework
Corporate reputation management works on three disciplines: establish it, protect it, restore it. Most organisations only discover the second and third exist once a crisis has already broken.
Establish is the product of behaviour, governance and culture operating in alignment over years, not a single control. Optus’s own case shows what happens without it: the exposed API sat unauthenticated for close to three years before anyone found it, on the regulator’s own timeline.
This is the discipline behind reputation management done properly, it starts long before anything goes wrong, not after a story breaks.
Protect means understanding exposure before it becomes public, with a response already tested rather than improvised. A reputation audit, mapping where the exposure already sits, is the practical version of this discipline, not a slogan.
Reputation protection also means corporate reputation monitoring, continuous tracking of media, social, regulatory and stakeholder signals, so a problem surfaces while there is still time to shape it. Wilkinson Group’s approach to issues management is built on that same principle.
Restore, as Kelly Bayer Rosmarin found when she resigned as Optus CEO in November 2023 after a second crisis hit, takes considerably longer than boards expect. Trust rebuilds slower than it collapses, and no statement shortens that timeline.
Establish, protect, restore. The same three verbs, used consistently, are the only reputation vocabulary a board needs.
What A Weak Apology Costs You
Optus’s initial statement undersold the breach’s scope. Each update in the days after expanded it, ending in confirmation that passport and licence numbers were exposed.
A disclosure that gets ahead of what regulators and journalists will find anyway reads as candour. One revised piecemeal under pressure reads as containment.
Weak: “We are investigating an incident and will update customers as appropriate.” Vague, passive, commits to nothing checkable.
Strong: “We have confirmed 9.5 million records were affected as of today. The entry point is closed. We will publish a further update within 48 hours.” Specific, dated, checkable.
Match the apology to the evidence, too. One broader than the acknowledged facts invites scepticism; one narrower than what stakeholders can already see invites accusations of minimising.
Strategy Is Not The Same As A Statement
Strategy is the three-part discipline itself, decided by the board before anything happens. Tactics are what get deployed during a live incident: the notification letter, the holding statement, the spokesperson brief.
One board can have a strong strategy and still issue a weak tactic under pressure. The reverse rarely happens. Get the strategy right first, and the tactics get easier to defend.
Who Owns This, And When It Gets Built
This gets built in the ordinary governance cycle, in the annual risk review, not invented mid-crisis. Waiting for the incident to define the plan is how boards end up drafting policy live on television.
It also needs one senior owner, not a committee. A board navigating a live threat needs someone who has sat in that room before, not a team assembling a response from a template.
Peter Wilkinson has advised boards through data-breach fallout since before Australia’s mandatory notification scheme existed. He treats ownership built as ongoing counsel, the model behind Wilkinson Confidante, as the practical answer to that gap.
This is the same discipline behind reputation management strategy work with boards under sustained pressure: publish what changed, name who is accountable for it, keep saying so after the headlines move on.
No Framework Fixes A Board That Hasn’t Changed
I have never seen a strategy document repair a board that hadn’t actually changed the practice that caused the failure. Message discipline doesn’t invent facts stakeholders can verify for themselves.
Three lines are what actually hold:
- Establish trust through behaviour, governance and culture, before anything happens.
- Protect it through tested exposure mapping and continuous monitoring, once risk appears.
- Restore it through specific, verifiable change, communicated once it’s real, after damage is public.
The Reputation Boards Inherit
Reputation is inherited by whoever leads next. A board that treats it as governance hands over something durable.
A board that treats it as messaging hands over a repair job, and a shorter runway to fix it than the last one had.
The future of reputation belongs to boards that build it as infrastructure, long before they need it as insurance.
