Internationalsecurityjournal iconInternationalsecurityjournalSep 9, 2026 ~6 min source read

Make crisis communications a core security competency

When a breach becomes public, the lag between internal understanding and external explanation does more reputational damage than the intrusion itself. Treat communications with the same planning, rehearsals, and decision rules as containment.

Making crisis communications a core security competency

Share this story

Send the public story page.

Useful takeaways from this story.

Decide disclosure decisions before an incident: build a disclosure decision tree that assigns responsibility, thresholds, and approval paths.

Keep two timelines: a technical forensic timeline and a plain-language, date-stamped timeline that becomes the basis for external statements.

Regulatory clocks (GDPR 72-hour, NIS2 24-hour early warning, Form 8-K four business days) force fast public statements—preparation reduces legal-driven vagueness.

# Why communications must live inside security

When a breach is detected, internal teams often understand the technical picture within hours but the public hears about it days later. That delay is where most lasting damage happens. By the time a formal statement appears, the narrative is usually set by third parties—ransomware leak sites, monitoring services, or social posts—and rarely matches the company's preferred explanation.

Regulation has removed the luxury of waiting for every fact. Under UK and EU GDPR a personal data breach that puts people at risk must be reported to the regulator within 72 hours. NIS2 asks for an early warning within 24 hours for in-scope organisations. In the U.S., listed companies decide materiality and file a Form 8-K within four business days. Those filings are public and shape coverage, customer perception, and searchable records.

Because these clocks are short, the natural reaction is to hand off messaging to legal and produce a liability-focused statement. That often reads like a cover-up: vague adjectives, exaggerated claims of sophistication, and minimal actionable information. Every later correction becomes a fresh news cycle and a reason to doubt the company.

# Practical components to build now

  • Map who declares an incident material and on what evidence. Legal will own the word, but security must provide the evidence.
  • Define which incident types go only to regulators, which require customer notices, and which need public statements (example: credential-stuffing affecting accounts vs. HR data exposed by ransomware).
  • Specify out-of-hours approvers and deputies.
  • Define triggers for going public before a full technical picture is ready (for example, imminent third-party disclosure).
  • Maintain the technical timeline for forensic purposes: access vectors, lateral movement, compromised accounts, indicators of compromise.
  • Use the plain-language timeline as the spine for customer notices and regulator filings so revised numbers don't create repeated news cycles.

Pre-approved spokespeople and holding statements

  • Name a spokesperson and a deputy in advance. Provide them with holding statements that are legally reviewed and signed off.
  • Make templates factual: blanks for systems, data types, mitigations and next steps. Avoid stock phrases like "sophisticated" or generic assurances.
  • Rehearse bridge calls and statement approvals with the same frequency and seriousness as technical tabletop exercises.

# How this changes incident response behavior

Communications planning reframes early incident calls. Instead of arguing disclosure in the middle of a tense overnight call, teams follow predefined rules. That reduces delays, avoids liability-first statements, and makes regulator filings and public notices consistent with evidence. When a statement is limited to what the evidence supports, each update is less likely to trigger new suspicion.

# Short checklist to start this week

  • Draft a disclosure decision tree with security, legal, and communications.
  • Create the plain-language timeline template and practice filling it during a tabletop exercise.
  • Identify and clear spokespeople and three holding-statement templates.
  • Run a simulated out-of-hours approval to test the deputy chain.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app