# Why communications must live inside security
When a breach is detected, internal teams often understand the technical picture within hours but the public hears about it days later. That delay is where most lasting damage happens. By the time a formal statement appears, the narrative is usually set by third parties—ransomware leak sites, monitoring services, or social posts—and rarely matches the company's preferred explanation.
Regulation has removed the luxury of waiting for every fact. Under UK and EU GDPR a personal data breach that puts people at risk must be reported to the regulator within 72 hours. NIS2 asks for an early warning within 24 hours for in-scope organisations. In the U.S., listed companies decide materiality and file a Form 8-K within four business days. Those filings are public and shape coverage, customer perception, and searchable records.
Because these clocks are short, the natural reaction is to hand off messaging to legal and produce a liability-focused statement. That often reads like a cover-up: vague adjectives, exaggerated claims of sophistication, and minimal actionable information. Every later correction becomes a fresh news cycle and a reason to doubt the company.
# Practical components to build now
- Map who declares an incident material and on what evidence. Legal will own the word, but security must provide the evidence.
- Define which incident types go only to regulators, which require customer notices, and which need public statements (example: credential-stuffing affecting accounts vs. HR data exposed by ransomware).
- Specify out-of-hours approvers and deputies.
- Define triggers for going public before a full technical picture is ready (for example, imminent third-party disclosure).
- Maintain the technical timeline for forensic purposes: access vectors, lateral movement, compromised accounts, indicators of compromise.
- Use the plain-language timeline as the spine for customer notices and regulator filings so revised numbers don't create repeated news cycles.
Pre-approved spokespeople and holding statements
- Name a spokesperson and a deputy in advance. Provide them with holding statements that are legally reviewed and signed off.
- Make templates factual: blanks for systems, data types, mitigations and next steps. Avoid stock phrases like "sophisticated" or generic assurances.
- Rehearse bridge calls and statement approvals with the same frequency and seriousness as technical tabletop exercises.
# How this changes incident response behavior
Communications planning reframes early incident calls. Instead of arguing disclosure in the middle of a tense overnight call, teams follow predefined rules. That reduces delays, avoids liability-first statements, and makes regulator filings and public notices consistent with evidence. When a statement is limited to what the evidence supports, each update is less likely to trigger new suspicion.
# Short checklist to start this week
- Draft a disclosure decision tree with security, legal, and communications.
- Create the plain-language timeline template and practice filling it during a tabletop exercise.
- Identify and clear spokespeople and three holding-statement templates.
- Run a simulated out-of-hours approval to test the deputy chain.