Back to Blog
Pooja·September 22, 2026·12 min read·

Crisis Detection: How to Catch a Brand Crisis Before It Spikes

A flat mention volume line with a small early sentiment dip visible well before the sharp spike that would mark a crisis going viral

Most crisis playbooks start at the moment a story is already breaking: acknowledge within fifteen minutes, statement within twenty, full briefing within ninety. That timeline only helps once someone has actually noticed something is wrong. The harder, less-discussed problem is earlier than that: building a detection system precise enough to catch a real crisis forming while it is still a handful of pointed comments, without drowning your team in false alarms every time volume ticks up for an unrelated reason. This guide covers the detection layer specifically, how to set a real baseline, the four trigger types worth alerting on, how to tune thresholds so the system stays trusted, and what a working detection setup actually looks like day to day.

Key takeaways
  • A crisis usually announces itself in sentiment before it does in volume. A sharp shift in tone among a small number of early mentions frequently precedes the spike that makes a story impossible to miss, and that gap is where detection earns its value.
  • Roughly 68% of reputational crises escalate within 24 hours of the first social signal, which means the detection window between that first signal and full escalation is short enough that a manually checked dashboard usually misses it.
  • Four trigger types cover most real crises: volume, sentiment, authority, and cross-platform spread. A system built around only one of these, usually volume, misses the crises that start quiet and credible instead of loud and viral.
  • A detection system nobody trusts gets ignored, which is worse than having none at all. Tuning thresholds down false-positive rates deliberately, starting narrow and expanding slowly, keeps a real alert from getting lost in noise.
  • Detection is a baseline problem before it is a technology problem. You cannot recognize an anomaly without first knowing, in specific numbers, what normal looks like for your brand.

Why detection is a separate problem from response

Our guide on handling a brand crisis covers the response sequence once something is confirmed: the 15-20-60-90 timeline, keeping channels aligned, and the recovery phase afterward. That entire sequence assumes someone has already noticed the crisis. This guide sits one step earlier, on the specific mechanics of noticing it at all, with enough lead time that the response plan has room to work instead of getting triggered by the time a story has already gone fully viral.

The two problems require genuinely different skills. Response is about speed and message discipline once a situation is confirmed. Detection is a statistics problem: knowing what normal looks like for your brand well enough to recognize the exact moment something stops being normal, without flagging every routine fluctuation as an emergency. A team can have a flawless 15-20-60-90 response plan and still lose the two-hour narrative window entirely, simply because nobody noticed the early signal until the volume spike made it undeniable.

Build a real baseline before you set a single alert

An anomaly only means something relative to a known normal, and most teams skip straight to setting alert thresholds without ever writing down what their baseline actually is. Before configuring a single trigger, pull at least four to six weeks of your own mention history and record three numbers: your average daily mention volume, your typical sentiment distribution, and your usual response time to routine mentions.

Most brands settle into a sentiment distribution somewhere around 60 to 70% neutral, 20 to 25% positive, and 5 to 15% negative on a routine day, though the exact split varies enough by category that your own history matters more than any general benchmark. Write these numbers down somewhere your whole team can reference them, beyond a dashboard nobody checks between crises. The baseline turns "mentions are up today" from a vague feeling into "mentions are running three times above our six-week average," the specific kind of statement a threshold can actually act on.

If you want a quick starting check on how your brand currently shows up before building a full baseline, our free AI visibility audit is a useful first step. Revisit the baseline quarterly. A brand that just launched a major campaign or shipped a widely covered product update has a different normal than it did the quarter before, and a threshold tuned to stale numbers either fires constantly or misses real shifts entirely.

The four trigger types worth alerting on

Four labeled trigger types, volume spike, sentiment shift, authority mention, and cross-platform spread, each with a simple icon and a one-line threshold example

Most detection setups default to a single trigger: alert when mention volume spikes. That catches the crises that go loud fast, and misses the ones that start as a small number of highly credible complaints. Four trigger types, run together, cover a much wider range of real crisis shapes.

Trigger What it catches Starting threshold
VolumeA story spreading fast across many peopleMentions exceed 3x your baseline within a 2-hour window
SentimentA tone shift before volume catches up5 or more negative mentions on the same topic within 4 hours
AuthorityA single credible voice, even at low volumeAny mention from a verified journalist or a high-follower account
Cross-platformThe same complaint independently surfacing in multiple placesSame complaint appears on 2 or more platforms within 6 hours

The authority trigger deserves special attention because it is the one most teams skip, and it catches a genuinely different shape of risk. A single mention from a verified journalist or an account with a large, engaged following can outweigh a hundred mentions from unverified accounts, since that one voice has the reach to turn a quiet complaint into a story on its own. Treat an authority-trigger alert with the same urgency as a volume spike, even when the raw mention count looks unremarkable. Reputation management workflows built around this trigger route a single high-authority mention straight to the person who can respond, rather than letting it sit in a general queue.

A confirmation checklist showing an alert being read and verified against actual mentions before a response decision gets made

The cross-platform trigger catches a pattern that a single-platform dashboard structurally cannot see: the same specific complaint appearing independently on Reddit, a review site, and a support forum within a few hours of each other. That kind of independent, cross-platform repetition is a stronger signal than the same volume of mentions concentrated on one platform, since it suggests the underlying issue is real and widespread rather than a single thread that happened to get attention.

Tune your thresholds so the system stays trusted

A detection system that cries wolf gets ignored, and an ignored alert is functionally identical to no alert at all. The practical fix is to start narrow and expand deliberately rather than casting a wide net from day one. Begin with tight, specific queries, your exact brand name, product names, and close misspellings, and track your false-positive rate for two full weeks before adding anything broader like industry terms or unbranded category language.

Aim for a false-positive rate under 20% before expanding coverage. If more than one in five alerts turns out to be nothing worth acting on, tighten the trigger before widening the net further, since every irrelevant alert erodes trust in the ones that matter. This mirrors the same tuning discipline covered in our guide on choosing keywords to monitor, applied specifically to the higher-stakes, higher-urgency context of crisis alerting rather than general listening.

A threshold set too loose trains your team to ignore the dashboard. A threshold set too tight misses the crisis. The right threshold is the one that fires rarely enough that when it does, someone actually looks.

Review your trigger performance monthly, alongside your keyword list. Note which alerts turned out to matter and which were noise, and adjust the specific thresholds accordingly. A volume trigger set at 3x baseline might need to move to 4x for a brand with naturally spiky mention patterns around product launches, while a brand with unusually stable, low-variance mention volume might safely tighten to 2x without adding noise.

Where early signals actually show up first

Detection coverage is not evenly valuable across every platform. Fast-moving platforms like X tend to show volume spikes first, but by the time a story is trending there, the early window has usually already closed. Reddit and forum monitoring catches a meaningful share of genuinely early signals specifically because detailed, unhurried community discussion tends to surface a product complaint or safety concern well before it becomes a viral post anywhere else. A thread with a dozen replies working through a specific issue in detail is often the earliest real signal available, hours or sometimes days before the same story breaks on a faster platform.

Review platforms and support forums carry a similar early-signal advantage for product and service issues specifically, since people posting there are usually describing a concrete, personal experience rather than reacting to something they saw someone else post. A cluster of similar complaints appearing across review sites in a short window is exactly the kind of cross-platform pattern the trigger table above is built to catch, and it typically precedes broader social coverage by a meaningful margin.

From detection to the first response decision

A detection system only creates value if an alert reaches someone who can act on it within minutes, not hours. Route each trigger type to a named owner in advance, the same discipline covered in our guide on building a listening workflow, so nobody has to figure out who should be looking at an authority-trigger alert while the clock is already running. An authority or cross-platform trigger should route to whoever owns crisis response directly, not into a general queue that gets checked once a day.

Once an alert fires, the first decision is not whether to respond publicly yet, it is whether the signal is real. Pull the actual mentions behind the alert and read them before doing anything else. A volume spike caused by a genuine product issue looks very different on close reading than one caused by an unrelated meme or a coincidental spike in an unrelated conversation that happens to use similar language. This confirmation step, kept to a few minutes, separates a detection system that supports good decisions from one that triggers a panicked response to a false alarm. PR teams running this as a standing part of their coverage review, rather than a separate system only glanced at occasionally, catch this distinction fastest.

Frequently asked questions

What is the difference between crisis detection and crisis monitoring?

Monitoring is the ongoing collection of mentions across channels, the raw data feed. Detection is the specific layer on top of that feed that decides which changes in the data are significant enough to alert someone about, based on a defined baseline and specific trigger thresholds. A team can monitor extensively and still have poor detection if nobody has set up the baselines and triggers that turn raw mention data into a timely, trustworthy alert.

How do you know what mention volume is normal for your brand?

Pull at least four to six weeks of your own mention history and calculate your average daily volume, along with how much that volume typically varies day to day. There is no universal number that applies across brands, since normal volume depends heavily on brand size, category, and how frequently you run campaigns or ship updates. Any useful threshold should be built against your own recent history, not a general industry benchmark.

Why does sentiment often shift before volume spikes in a real crisis?

A real issue typically starts with a small number of people directly affected posting about it in detail, often in a community like Reddit or a support forum where people work through a problem at length rather than reacting quickly. That early conversation can carry a sharp, clearly negative tone well before enough people are talking about it to register as a volume spike on a broader dashboard. By the time volume catches up, the sentiment shift has usually already been visible for hours to anyone specifically watching for it.

How many false positives should a crisis detection system tolerate?

Aim for under 20% during the tuning period before expanding your alert coverage further. A higher rate than that tends to train the team responsible for reviewing alerts to start ignoring them, which defeats the purpose of having the system at all. Start with narrow, specific triggers, measure the false-positive rate over a couple of weeks, and only widen coverage once that rate is under control.

Does a small brand need all four trigger types, or is volume enough?

A small brand benefits from all four, arguably more than a large one, since a small brand has fewer routine mentions overall, which means a sentiment shift or an authority mention stands out more clearly against a quieter baseline. Volume-only detection specifically misses the crisis shape that starts as a small number of credible, negative mentions rather than a viral spike, and a smaller brand is more likely to face exactly that shape of risk, where a single unhappy customer with a real audience says something that never generates the volume a volume-only trigger is looking for.

Catching a crisis before it spikes is a baseline problem wearing a technology costume. Know your normal in specific numbers, watch for the four trigger types rather than volume alone, tune deliberately so the system stays trusted, and route each alert to a named person who can confirm it fast. Get the detection layer right, and the response plan your team already has finally gets the lead time it was built to use.

Catch the shift before the spike

Mentient monitors Reddit, news, reviews, and the web in real time with sentiment scored automatically, so a shift in tone shows up in your dashboard while it's still a handful of mentions, not after the story has already spread.

Start free trial

About the author

Pooja

Pooja runs the engineering and data science behind Mentient. Her whole career has been about turning messy, large-scale data into something you can act on. She owns the AI models that read sentiment and pull the mentions worth your time out of the noise. Accuracy matters to her. So does speed, and she refuses to trade one for the other.

Track your brand in AI & the web

Monitor mentions, sentiment, and AI visibility across Reddit, the web, ChatGPT, Gemini, and Perplexity.

Start free trial →