Written by Dr Shalen Sehgal | Crises Control
Incident management software is a platform that enables an organisation to activate, coordinate and document its response to a declared incident, from the first alert through to post-incident review and regulatory reporting. In oil and gas operations, where the gap between a controlled response and an escalating emergency can close quickly, the platform’s value is measured almost entirely in what happens in the first thirty minutes.
Consider the sequence that follows a significant hydrocarbon release at an onshore processing facility. Control room operators detect an abnormal pressure reading. A field technician confirms a gas release from a connecting unit. The Fire and Gas detection system activates across the processing area. The shift HSE Manager is in a meeting in the administration block. Engineering has not been notified. Leadership has no picture of what is happening.
This article uses a five, fifteen and thirty-minute structure to examine what a well-prepared organisation should be doing during the opening phase of a serious oil and gas incident. That structure is an operational framework, not a regulatory timetable. Exact actions, priorities and timing will depend on the nature and scale of the incident, the facility type, the jurisdiction and the organisation’s emergency response plan. The purpose of the framework is practical: to give HSE Managers, Emergency Response Managers and Operations Directors a structure for assessing whether their organisation can move from detection to coordinated command at the speed the incident demands.
Where response processes typically fail during this period is covered in detail in Oil and Gas Emergency Response: Why the First 10 Minutes Determine Everything. This article has a different focus: the sequence of actions that should be happening at each stage, and what a well-structured response actually looks like when it is working.
The First Five Minutes: Declaration, Authority and Initial Notification
The first decision in any major oil and gas incident is the one most commonly delayed: formal declaration.
Before an incident is declared, there is no unified command. There is no authorised activation of the emergency response team. Individual functions may become aware that something serious is happening, but each responds from its own limited picture, without a shared situation report and without a named authority coordinating the whole.
Declaration delays in the opening phase are common, and they are rarely the result of negligence. Information in the first moments is incomplete. A supervisor facing an escalating situation at a single point in the facility may attempt local management before escalating. There may be genuine uncertainty about whether what is being observed reaches the threshold that requires a formal major incident response. In multi-shift, multi-contractor environments, there may also be ambiguity about who carries the authority to make that call.
A well-designed emergency response plan removes that ambiguity before the incident occurs. It defines trigger criteria: the specific conditions that require or authorise formal declaration, such as a confirmed ignition, a release exceeding a defined concentration threshold, or a fatality or life-threatening injury. It also assigns declaration authority to a specific role on each shift, so that a field supervisor or control room operator does not need to reach multiple management layers before the response can begin.
By the end of the first five minutes, the minimum that should be in place is this: the incident formally declared, the incident commander informed and active, and at minimum the HSE Manager and Emergency Response Manager notified. These are not aspirational targets. They are the preconditions for everything that follows. When any of those conditions remain unmet as the first minutes pass, the response is at risk of falling behind the pace of the incident.
Sequential or Simultaneous: Why the Difference Matters From Minute One
In many organisations, initial notification still relies primarily on a sequential process. One person contacts the next, who contacts the next, working through a list. The structural problem with this model under actual incident conditions is not simply speed. It is that the person managing the notification process is also, in most cases, someone whose attention is needed on the incident itself. They are making calls during the minutes when they should be building a picture of what is happening and what needs to happen next.
The operational difference between sequential and simultaneous notification is significant. When all relevant functions receive their initial alert at the same moment, parallel workstreams can begin immediately. When they receive it in sequence, the response is already partially sequential before a single team has taken action.
Interested in our Incident Management Software?
Flexible Incident Management Software to keep you connected and in control.
Minutes Five to Fifteen: Activating Multiple Teams at the Same Time
A serious oil and gas incident does not affect one team. From the moment of declaration, HSE, operations, engineering, security, senior leadership and, depending on the nature and location of the incident, external emergency services all have roles that need to start in parallel.
The operational challenge in the five-to-fifteen minute period is that those roles require different actions from different functions, running simultaneously. The HSE Manager needs to activate the emergency response team and begin accounting for personnel, including shift workers, contractors and anyone in or near the affected area. Operations must assess the affected unit, evaluate isolation requirements and determine whether a controlled shutdown or depressurisation is necessary. Engineering must consider the structural and process integrity implications. Security must manage site access, control the perimeter and prepare for the arrival of external emergency services. Leadership needs enough situational information to make early decisions, including whether the incident may require regulatory notification.
The IPIECA/IOGP “Incident Management System for the Oil and Gas Industry” guidance (2023), industry guidance rather than a regulatory requirement, makes a clear point about this phase: effective response depends on moving from an initial reactive mode to structured command and control rapidly. The guidance also establishes the principle of prudently over-responding in the early phase. When the full scope of the incident is not yet known, the correct posture is to activate more resource than may ultimately prove necessary, not less.
In organisations where activation depends entirely on manual processes, these parallel workstreams routinely begin sequentially. One person works through a contact list, one call at a time. By the time the sixth call is completed, the first five recipients have been waiting: no shared operational picture, no confirmed task assignments, and no knowledge of what others have been asked to do. The response is already fragmented before the coordination phase has begun.
Minutes Fifteen to Thirty: Command Structure, Task Ownership and Operational Visibility
If the first fifteen minutes are about activating the right people, the next fifteen are about giving the incident commander a coherent operational picture and ensuring that every active team has a clear, confirmed task.
This is the phase where inadequately structured responses begin to visibly fragment. Teams activated without a shared baseline operate on different assumptions. The incident commander receives updates through radio calls, phone conversations and face-to-face contact from multiple directions at once, with no mechanism to consolidate what is arriving. Tasks assigned verbally in the opening minutes carry no formal record and no confirmed owner. Responsibilities that looked clear in the emergency response plan look less clear in practice when two functions are each waiting for the other to move first.
Achieving a coordinated command position in this phase requires more than capable people and a well-written plan. It requires a consolidated, real-time picture of who has been reached, what has been activated and what tasks remain outstanding. This is where an Operational Visibility Platform can support the response, giving the incident commander a live view of who has been reached, which tasks have been assigned, what remains outstanding and where escalation may be required.
By the thirty-minute mark, a well-prepared response should have established the following. A named incident commander with a consolidated view of what has been activated, what has been acknowledged and what remains outstanding. Confirmed notification across all relevant functions, with a record of who was reached and when. Task assignments with named owners and current status. A preliminary assessment of whether the incident is escalating, stable or contained, to inform the escalation decision. And a judgement on whether external emergency services are already engaged or need to be requested.
When Should Escalation Happen?
Escalation is one of the most inconsistently applied elements of the first thirty minutes. The decision to escalate to senior leadership, to activate the wider emergency response organisation, or to notify the regulator is frequently left to individual judgement in the moment rather than defined in the emergency response plan as a condition.
Good practice defines escalation as a condition, not a decision made under operational pressure. If the incident has not been contained within a defined period, or if specified conditions are met, such as a second explosion, a confirmed fatality, a required production isolation or an environmental release beyond a defined threshold, escalation activates according to the plan. The incident commander does not need to first conclude that escalation is warranted. The plan has already made that determination. What the incident commander needs is a clear, real-time picture of whether those conditions have been met.
Under COMAH 2015, upper tier operators in the UK are required to prepare a written on-site emergency plan covering the full range of potential major accidents, including low-probability, high-consequence events. The operator must test the plan through exercises and revise it in light of findings. The regulations separately require local authorities to prepare external emergency plans; under those arrangements, Category 1 responders as defined in the Civil Contingencies Act 2004 have a cooperation duty in testing the external plans. The core principle that cuts across both requirements is the same: a plan must be demonstrably capable of being executed under the conditions it is designed for, not merely documented.
The equivalent US requirement, OSHA 29 CFR 1910.119, mandates an emergency action plan for covered processes conforming to 29 CFR 1910.38. Across both regulatory frameworks, the practical standard is the same: operators must be able to demonstrate that their emergency arrangements are capable of being implemented under the conditions they are designed for. An emergency response plan that has not been tested is one whose reliability in a real incident is unknown.
What History Tells Us About the Consequences of a Failed Opening Phase
The value of studying major oil and gas incidents is not to present their details as benchmarks for modern response times. It is to understand what the opening phase of a serious response looks like when command and communication arrangements fail at the moment they are needed.
The Piper Alpha platform disaster of 6 July 1988 is one of the most thoroughly documented major incidents in the history of the offshore oil and gas industry. The subsequent public inquiry, chaired by Lord Cullen, found that no evacuation orders were given during the disaster, that no platform-wide emergency communications were issued, and that the Offshore Installation Manager did not assume control of the response. The inquiry’s findings on the state of the emergency response arrangements were set out in detail across its final report.
One of the most instructive findings from the Cullen Inquiry concerned the adjacent platforms Tartan and Claymore, which continued pumping oil and gas to Piper Alpha because their crews did not feel empowered to initiate a production shutdown without explicit instruction from a central authority. The absence of a functioning command structure had consequences that extended well beyond the incident site itself.
The five, fifteen and thirty-minute framework in this article is not derived from the Piper Alpha investigation, and no claim is made that it reflects the specific timeline of that disaster. The Cullen findings are relevant for a different and more direct reason: they document, with precision and in a thoroughly evidenced public record, what happens in the opening phase of a major oil and gas emergency when command authority is undefined and communication arrangements do not function. That structural lesson applies directly to the question of whether any organisation’s emergency response plan will produce a working command structure when the next serious incident occurs.
How Incident Management Software Supports Execution in the First 30 Minutes
The coordination challenges described in this article do not arise simply from a lack of tools. They arise from the structure of the response itself: notification that depends on manual calls, task assignment that relies on verbal instruction and status tracking that requires someone to chase updates from multiple teams while simultaneously managing the incident. The more complex the site and the more dispersed the workforce, the more severe those delays become.
When an incident is declared on the Crises Control platform, a pre-configured incident response workflow activates immediately. Multi-channel alerts go out simultaneously through SMS, voice call, push notification, email and the Crises Control app to all designated team members at once. The incident commander does not need to manage the notification process. Acknowledgements are tracked from the moment the alert is sent. Any contact who has not responded within a defined interval triggers automatic escalation to the next contact or tier, without manual intervention. Task assignments are distributed to each function and tracked through a live incident dashboard that gives the incident commander a consolidated operational picture without depending on manual status calls.
For oil and gas operators managing large sites, complex contractor populations, remote assets or multi-site operations, the compounding effect of manual coordination in the opening phase of a major incident is more severe than under normal operational conditions. The platform does not replace a well-designed emergency response plan, nor the judgement of the professionals executing it. What it removes is the coordination overhead that causes the opening thirty minutes to fragment at precisely the moment when structure matters most.
The audit trail and post-incident reporting that the platform builds throughout the response, covering every alert sent, every acknowledgement recorded and every task assigned and completed, provides a detailed record for post-incident review, regulatory reporting and continuous improvement.
What Should Your Organisation Be Able To Do In 30 Minutes?
The question worth asking before the next drill or audit is not whether the emergency response plan is documented. It is whether the plan can move the organisation from incident detection to coordinated command within the time a serious incident demands.
At the five-minute mark: Has the incident been formally declared? Has the incident commander been notified and confirmed active? Have the HSE Manager and Emergency Response Manager received their initial alert?
At the fifteen-minute mark: Have all relevant functions been notified? Are teams working in parallel, or is the response still largely sequential? Does each function understand what it is responsible for?
At the thirty-minute mark: Does the incident commander have a consolidated view of what has been activated, what has been acknowledged and what remains outstanding? Are escalation criteria being assessed against a real-time operational picture? Can leadership determine whether the situation is escalating, stable or contained?
The most reliable way to answer these questions is through realistic drills that test what actually happens under pressure. If command is still unclear, responsibilities remain unassigned or the incident commander is making individual telephone calls to establish what each team is doing, the drill has identified a coordination gap that should be addressed before a real incident exposes it.
The first thirty minutes are not about completing the response. They are about establishing the command, communication and operational visibility needed to manage everything that follows.
If you are reviewing your organisation’s incident management capability, request a personalised demo of Crises Control to see how our Incident Management Software helps oil and gas teams coordinate activation, communication, tasks and operational visibility from the first alert through to post-incident review.
FAQs
1. What is incident management software in the context of oil and gas operations?
Incident management software is a platform that enables an organisation to activate, coordinate and document its response to a declared incident. In oil and gas, it is applied across major process safety events, hydrocarbon releases, equipment failures, security incidents and environmental emergencies. It provides the activation, communication, task management and audit trail functions that a fragmented manual response cannot reliably deliver when an incident is moving quickly.
2. What should happen in the first five minutes of a serious oil and gas incident?
Within the first five minutes, the priority is formal declaration by a named authority, notification of the incident commander, and initial alert to the core emergency response team including the HSE Manager and Emergency Response Manager. The exact sequence is defined in the organisation’s emergency response plan. The critical operational point is that declaration should happen quickly, based on pre-defined trigger criteria, so that coordinated activation can begin before the incident develops further.
3. What does COMAH 2015 require from UK operators in terms of emergency response plans?
Under COMAH 2015, upper tier operators must prepare a written on-site emergency plan covering the full range of potential major accidents. The operator is required to test that plan through exercises and revise it in light of findings. Separately, local authorities must prepare external emergency plans; Category 1 responders under the Civil Contingencies Act 2004 have a cooperation duty in testing those external plans. Across both requirements, the regulatory standard is the same: plans must be demonstrably executable, not merely documented.
4. Is the 5/15/30-minute structure in this article a regulatory requirement?
No. The five, fifteen and thirty-minute structure used in this article is an operational and editorial framework, not a regulatory timetable. COMAH 2015, OSHA 29 CFR 1910.119 and equivalent regulations require that operators have emergency response plans that are tested and capable of being executed. They do not prescribe the specific minutes within which individual actions must occur. The framework is designed to help HSE Managers and Emergency Response Managers assess whether their current plan can move from detection to coordinated command at the speed an incident demands.
5. What does the Piper Alpha disaster reveal about emergency response planning in oil and gas?
The Cullen Inquiry into the Piper Alpha disaster (1990) documented in precise detail the consequences of an emergency response arrangement that failed at the moment it was needed: no evacuation orders issued, no platform-wide communications, no command assumed. The structural lessons are clear: command authority must be pre-assigned and communication arrangements must be tested under realistic conditions. Both apply directly to how oil and gas operators design and exercise their emergency response plans today. For further context on the dynamics of the opening phase, see also Oil and Gas Emergency Response: Why the First 10 Minutes Determine Everything.