Admincontrol Insights

Customer Profile: When the Factory Is on Fire: How Boards Navigate Crisis

Written by Admincontrol | 24 August 2026

We were lucky enough to have a great conversation with Asta Ellingsen Stenhagen, board professional and corporate lawyer, on crisis preparedness, decision-making under pressure, and why facts should always lead the way.

Asta has sat on both sides of a crisis. As a former General Counsel at one of the Nordic region’s largest tech and system delivery companies, she was the designated crisis manager for the most severe, Level 1 incidents, the kind that could rattle an entire sector. Today, as a board professional, corporate lawyer, and advisor, she brings that operational fluency into the boardroom. We spoke with her about what good crisis governance actually looks like, where boards go wrong, and how tools like Admincontrol play a quietly critical role when everything else is on fire.

About Asta Ellingsen Stenghagen

Asta is a corporate lawyer, board professional, and crisis management specialist. Her career spans senior in-house roles (including General Counsel of a major Nordic technology group) and active board directorships. She specialises in corporate law, contract law, and high-stakes governance, with direct experience managing cyber-attacks, financial distress scenarios, and reputational crises at the highest level.

From the Frontlines to the Boardroom

Asta’s entry into crisis management was less a deliberate career choice than an organic consequence of the roles she took on. As General Counsel of a large Nordic technology company, risk management, security and crisis coordination came with the territory.

“When you’re General Counsel at the largest tech and system delivery company in the Nordics, there were crises on a regular basis,” she says. “We had several layers of management for critical situations: incident management as the daily and lowest level, then different tiers of crisis management. I would normally be briefed on Level 2 and 3 situations, but I was the crisis manager for Level 1.”

At that level, the crises were often cyber-related: attacks on customer infrastructure, intrusions into company systems, and threats to critical national infrastructure. High stakes, limited time, no room for ambiguity.

The shift to board-level crisis work required a different mindset. “Crisis management in the board is slightly different from when you are an employee in an operating company,” she explains. “The crisis is run on a daily basis by management. The board is consulted and makes decisions based on the type or scenario of the crisis.”

She has since navigated board-level crises ranging from COVID-19 business continuity to financial distress and geopolitical disruption, each demanding a different kind of governance response.

In Conversation: Crisis, Governance, and Getting It Right

You talk about having a “plan as a fallback.” What does that actually mean in practice when a crisis hits?

For me, it’s always about facts first. Facts about the situation, facts about the people and the capacity to resolve it, facts about how similar situations have been handled before. If liquidity is at risk, for example, you need to know exactly how long the company`s runway is.. So, facts are always the key thing.

I think that’s where many people feel the first stress, because it can be difficult to get the facts. And then the second step is to hear out the experts.

In a crisis, the board itself is rarely the expert. That expertise sits with people inside the company, or sometimes you need to bring in external specialists. So, the process is: get the facts on the table, then hear what the experts propose.

When everyone in the room focuses on facts first, you get at least a sense of control.

What’s the biggest mistake you’ve seen boards make when a crisis hits?

Jumping to conclusions is a typical mistake made under stress and uncertainty.

When you don’t have the facts, and you haven’t listened to the experts, you make hasty decisions. In most situations (even serious ones) there is at least 30 minutes or an hour to check and hear out. If there is ever a moment where you have only 30 seconds to decide, the decision should always be to try buying time. So, you can make more well-founded decisions afterwards.

How do you strike the right balance between board oversight and letting management lead during a crisis?

The key is that the company has defined in advance what a crisis actually is, as opposed to an incident that the organisation can handle along the way. When you have a clear border between incident management and crisis management, it becomes much easier for both the board and management to understand their roles and responsibilities when turmoil happens.

What happens when the crisis falls outside those predefined scenarios — for example, when the CEO is the problem?

Scenario planning should already include that. When you prepare for crisis management, you think through the key risks relevant to your company: cyber risk, the loss of a key person, a reputational event. If a CEO is involved in a Me-Too situation, for instance, or gets caught up in something that damages the brand, that should already be part of your scenario thinking.

For a listed company, there are also regulatory requirements. If a CEO or CFO is placed on leave, you have notification obligations to the stock exchange. But very quickly, the reality is: the board hires and fires the CEO. If the board can’t convene within the hour, the chair normally has the authority to act. You put the CEO on temporary leave, you announce that, and then you buy time to get the full facts on the table.

What does good crisis preparedness look like at board level?

Three things. First, there is a plan and the board is aware of it. Second, the board knows the company’s key risks and the scenarios linked to them. And third (this is the one people underestimate) the board, or at minimum the chair, has participated in an exercise.

Many companies do an annual desktop exercise. It can be planned or unannounced. You can tell the board in advance, or you can simply have the CEO call the chair and say: ‘The factory is burning.’ That is a wake-up call for any board that has never thought about crisis management before.

What structures should be in place before a crisis occurs that people often overlook?

Communication. It’s often the thing that gets least attention in the planning, and it’s the thing that matters most.

In management, people have access to company systems: Teams, internal platforms, whatever. But as a board member, you don’t have access to those internal systems. What you do have is your board portal. So having Admincontrol, or agreeing in advance on a WhatsApp or Signal group, matters enormously, because in a cyber-attack, email and normal communication channels are often the first things compromised.

Admincontrol is an example of a secure communication tool that is already in place, accessible on a mobile phone, and limited to those who need to know. That’s exactly what you need in those moments.

How do you decide what to communicate, and to whom, in the middle of a crisis?

For listed companies, the rules are clear: inside information must go to the market first. Then employees, immediately after. That’s non-negotiable.

For unlisted companies, the priority is always: first, secure people’s lives and the assets of the company. Then a clear hierarchy of who needs to know, which means who has a role to play in the solution. Second-in-command managers are informed so they can step in. Employees in the relevant part of the business are told what they need to know. People who are ‘nice to know’ come much further down the list.

What do people fundamentally misunderstand about how boards function during a crisis?

That the board needs to be much more operational than it actually should be.

Here’s the ideal scenario: a company has a robust plan, trained people, and the right resources in place. The board only makes decisions at the highest level. They are not choosing which lawyer to hire, which IT firm to bring in, and which consultant to call. That’s management’s job.

It’s worth noting that Norwegian corporate law is distinct here. Under US or UK law, a CEO can also serve as chair. In Norway, that’s not permitted for listed companies. We have non-executive boards, which means the board is genuinely separated from day-to-day executive management. That structural distance is actually a feature, not a limitation. It means the board can hold the strategic line while management runs the crisis.

The biggest misunderstanding is that the board needs to be much more operational when there is a crisis. In the ideal scenario, no, they are not.

What advice would you give to a board chair about building crisis readiness?

It depends on the business. If you are running a high-risk operation with a small team, then crisis management competence needs to be inside the board itself. But even where that’s not the case, you can cover a lot of ground with three things: a short plan, a short exercise, and an agreed communication platform.

Those three pillars (plan, exercise, communication) can be built with tools you already have. For listed companies especially, I think this should be a minimum requirement.

On Admincontrol’s Role in a Crisis

When Asta talks about communication infrastructure, she’s not speaking abstractly. She points to Admincontrol specifically as an example of a tool that solves a real governance problem: board members don’t have access to internal company systems, but they need a secure, reliable channel that works even when email is compromised.

“If there is a plan stored in Admincontrol, board members know where to go and what their role is in a crisis,” she says. “As a chair, I know the CEO will call me. As a board member, I know the chair is the first point of contact. And I know I’ll receive updates through Admincontrol or the agreed group. That clarity is everything.”

She also makes a practical observation about access: in a cyber incident, the company’s own systems may be compromised. A board portal operating independently of internal infrastructure is not a luxury. It is continuity planning.

In a cyber-attack, email and normal communication channels are often the first things compromised. Admincontrol is already in place, accessible on a mobile phone, and limited to those who need to know.”

Getting Things Done

We asked Asta what drew her to crisis management as a specialty in the first place. Her answer was characteristic: matter-of-fact, and quietly revealing.

“I like to get things done,” she says. “In a crisis, moving forward is always really important. Standing and watching the house burn down — that’s not an option. You need to be able to act, and to act in a way that takes the company forward. That’s motivating in itself.”

It’s as good a philosophy for crisis management as it is for governance more broadly. Know the facts. Listen to the experts. Buy time when you need it. And then act.