Integrating Strategic Communications into Cyber Incident Response | ARTÉMIA
Cyber Incident Communications 8 min read Crisis Communications

Integrating Strategic Communications into Cyber Incident Response

The communications decisions that can be settled before a cyber incident should not be consuming time once the response is underway.

A cyber incident may be underway for days or weeks before an organization realizes something is wrong. Once it is detected, the pressure can build quickly. Investigators are trying to determine what happened and how far it spread while the rest of the organization begins making decisions that cannot always wait for a complete forensic picture.

If the response depends on first figuring out who can approve a statement, where notification obligations are documented or how communications will get current information from investigators, valuable time is being spent on questions that should have been settled beforehand.

How ready is your team to communicate during a cyber incident?
ARTÉMIA's Cyber Incident Communications Readiness Assessment helps identify gaps in decision-making, stakeholder communications and response planning.

Test Your Readiness

Decide who has authority before an incident

Approval chains that work perfectly well during normal business hours can break down quickly during a cyber incident.

The usual decision-maker may be unavailable. Legal counsel and communications staff may be working from different locations. New forensic findings can arrive after language has already been drafted or approved.

A cyber incident communications plan should spell out who has authority to approve external communications and who steps in when that person cannot be reached. Communications also needs a defined route for receiving current information from the people handling the technical response.

Without that connection, a statement can be outdated before it is published.

These are basic governance decisions, but they consume valuable time when nobody has settled them in advance.

Know which stakeholders carry specific obligations

Some of the most important communications requirements may sit outside the crisis plan entirely.

A major customer, for example, may have a contract requiring notification within a specific window. That obligation can easily be missed if the relevant terms are buried in account files or known only to the person who manages the relationship.

Pre-incident stakeholder mapping can surface those requirements and connect them to the people responsible for the relationship. It also helps the response team distinguish between stakeholders who require formal notification and those who may need direct communication because of the operational impact of the incident.

This becomes especially important for companies with complex enterprise or partner relationships. The response team should not have to spend the first hours of an incident searching through contracts to determine who needs to hear from them.

Plan for communications when normal systems are disrupted

Cyber incidents can affect the same systems an organization normally relies on to communicate.

If email, the corporate website or internal tools become unavailable or cannot be trusted, the response team needs another way to reach employees and publish authoritative information. That alternative should already be established and accessible to the people expected to use it.

Backup channels also have to be maintained. Old contact information or an emergency publishing process nobody can access will create another problem at exactly the wrong time.

This part of cyber communications planning is easy to overlook because it feels operational rather than editorial. During an incident, however, even a well-drafted statement has little value if the organization has no reliable way to distribute it.

Understand how cyber insurance fits into the response

Cyber insurance can introduce another dependency that deserves attention before an incident.

Some policies provide coverage for crisis communications, public relations or related response services. Coverage may depend on insurer approval or use of an approved provider, however. An organization that expects its existing communications adviser to step in immediately should know in advance whether that arrangement is compatible with the policy.

The response plan should also reflect how communications support is activated. If insurer authorization is required before outside work begins, the people managing the incident need to know who handles that process.

This is particularly important when a company already has established legal, technical and communications partners. Insurance requirements can add another set of relationships to an already complicated response, and any mismatch is better discovered before the company needs those resources.

Check the activation process before an incident. If insurer approval or an approved provider is required, the response team should know who handles that authorization before outside communications support is needed.
Decisions to settle before an incident
Authority Who can approve external communications? Define the primary decision-maker and the backup when that person cannot be reached.
Stakeholders Who has notification requirements? Surface contractual deadlines and identify the people responsible for each relationship.
Channels How will the organization communicate if normal systems fail? Maintain backup routes for employees, customers and authoritative public updates.
Insurance How is communications support activated? Know whether insurer approval or an approved provider is required before work begins.

Templates only help when the process around them works

Preapproved holding statements and draft employee messages can save time, particularly in the early stages of an incident. Their usefulness depends on what surrounds them.

The actual event will still determine whether a public statement is appropriate, which stakeholders need direct outreach and how the language should change as forensic findings develop. A template provides a starting point. The response process determines whether the resulting communication is accurate and reaches the right people.

That process should cover where the facts come from, who approves the message and how updated information gets incorporated once the first communication has gone out.

Otherwise, organizations can end up with a folder full of polished templates and no clear way to use them.

Tabletop exercises should expose weak points

A communications plan can look perfectly workable until one of its assumptions fails.

Cyber tabletop exercises give organizations a chance to find those assumptions before a real incident does. Make the usual approver unavailable or take corporate email off the table. Introduce a customer notification deadline after the response is already underway. Change a key forensic finding after the first statement has been drafted.

Tabletop stress test Test the assumptions the communications process depends on
Scenario 01 The usual approver is unavailable Can the team keep moving without creating a new approval process in the moment?
Scenario 02 Corporate email is unavailable Can employees and response partners still receive reliable information?
Scenario 03 A customer deadline appears Can the team identify the obligation, owner and required communication quickly?
Scenario 04 A forensic finding changes Can approved language be updated before outdated information reaches stakeholders?
The exercise is useful when it reveals how the team adapts after an assumption fails, not simply whether participants can locate the crisis plan.

What happens next depends on more than whether participants know where the crisis plan is stored. Exercises also give the people who will have to make decisions together a chance to work through the friction in advance.

During a real incident, different functions will bring different concerns about evidence, disclosure and timing. The organization needs a workable way to resolve those disagreements without bringing the response to a standstill.

Reduce the decisions that can be made in advance

A cyber incident will create plenty of questions the organization genuinely cannot answer immediately. Approval authority, customer notification terms and backup communications channels should already be settled.

With a clear cyber incident communications plan, teams are given a working structure before the facts start moving. That leaves more attention for the decisions that actually depend on what happened.

For companies reviewing cyber preparedness, communications should be examined alongside the technical response rather than treated as something to work out once an incident occurs.

ARTÉMIA Communications works with organizations to strengthen crisis communications readiness, including cyber incident communications planning, stakeholder mapping and scenario planning.

Learn More

Stay In The Know

Get the latest expert insights and analysis delivered to your inbox.