Why Strong Cyber Incident Response Requires Better Communication | ARTÉMIA
Cyber Incident Communications 9 min read Crisis Communications

Why Strong Cyber Incident Response Requires Better Communication

Planning ahead gives organizations a framework for deciding what to say, when to say it, who is saying it and who needs to hear it while the facts are still developing.

In 2025, 4,080 data breaches impacted more than 370 million people in the U.S. In the first six months of 2026, 1,800 incidents have compromised the data of 471 million victims. Cyberattacks have grown increasingly sophisticated in recent years, and now that artificial intelligence is involved, they have become a matter of "when," not "if."

Yet, a startling number of businesses are not prepared for that scenario. In fact, approximately 66% of SMBs say they have no formal incident response plan, nor have they considered that they may be at risk. While enterprises are more likely to have a plan in place, nearly three-quarters say they lack "full readiness."

4,080
U.S. data breaches in 2025
More than 370 million people were impacted.
471M
Victims affected in the first half of 2026
Across 1,800 reported incidents.
66%
of SMBs report no formal incident response plan
Many have not considered that they may be at risk.

Communications planning often receives even less attention. In the first hours after an incident, a company may know that systems are unavailable but not why. It may have evidence of unauthorized access without knowing how far the intrusion went or whether data was taken.

While security teams work to establish what happened, employees, customers, partners and reporters may already be asking for answers.

In the moment, communicating about a cyberattack can feel like a catch-22. Moving too quickly can turn a preliminary finding into a public fact that later has to be corrected. Waiting too long leads people inside and outside the company to start filling the gaps themselves.

Planning ahead makes that uncertainty much easier to navigate, because it gives an organization a clear framework for deciding what to say, when to say it, who is saying it and who needs to hear it.

How ready is your team to communicate during a cyber incident?
ARTÉMIA's Cyber Incident Communications Readiness Assessment helps identify gaps in decision-making, stakeholder communications and response planning.

Test Your Readiness

Early assessments are often incomplete

The initial picture of a cyber incident can change substantially as investigators work through the evidence. An outage may later be linked to ransomware, or an intrusion may prove to extend beyond the systems first identified. Confirming unauthorized access also does not necessarily mean investigators can establish that data was viewed or taken.

Forensic work can take days or longer to resolve questions that matter immediately outside the security team. An outage may already be affecting customers and employees while contractual or regulatory notification deadlines are running. Reporters, researchers or the attackers themselves may also be putting information into the public domain before the investigation is finished.

That makes waiting for "all the facts" impractical in many incidents. Communications decisions have to be based on what is sufficiently supported at the time, with a clear distinction between confirmed findings and questions that remain open.

Early statements can create problems later

Some of the hardest communications issues begin with language that felt reassuring when it was approved.

Too definitive
Match the evidence
"No customer data was accessed." This treats a preliminary assessment as a final finding.
"We have not identified evidence of unauthorized access to customer data at this stage." The wording reflects what investigators can support at that point.
"The incident has been contained." This can imply the threat has been fully eliminated.
"We have taken steps to contain the incident and are continuing to investigate." It separates the action taken from the status of the investigation.
"Our systems are secure." This can communicate more certainty than the investigation allows.
"We are continuing to assess and secure affected systems." It describes the current response without closing off later findings.

Those statements may ultimately prove accurate. The problem is how much certainty they communicate before the investigation can support it. If later findings point in a different direction, the company has to explain why its story changed.

Early communication does not need to be vague, but it does need to match the evidence. A business can confirm when suspicious activity was identified without claiming to know when the intrusion began. It can explain that systems were taken offline as a precaution without declaring the threat eliminated.

The same principle applies to data exposure. Saying investigators have found no evidence of something so far is not the same as saying it did not happen.

An early statement should still make sense if tomorrow's forensic work expands the known scope of the incident. If it only works as long as the current assessment proves final, the wording is probably too definitive.

Legal counsel should be closely involved in a cyber incident, especially when the response may involve breach notification requirements, law enforcement, securities disclosures or personal information.

That said, legal questions do not always align with what people need to know operationally.

A formal breach notice may not address the questions people need answered in the moment. Customers may be dealing with an unavailable service or wondering whether their own systems are affected, while employees may need immediate direction on devices, credentials or access. A legally sufficient notice can still leave those questions unanswered.

On the other hand, naming categories of potentially affected information before they have been verified can create unnecessary alarm, while too much detail about attack methods may interfere with the investigation. Attribution deserves particular caution when the technical evidence remains inconclusive.

Communications teams should be part of these discussions as they happen, not brought in once the legal and technical decisions have already been made. Their role goes beyond turning decisions into cleaner language. It includes understanding how the available facts are likely to be interpreted and where the wording may create problems as the investigation develops.

Once the incident is visible, silence has consequences

Holding off on a public statement may be reasonable while a company is still trying to understand what happened; however, that becomes harder once evidence of the incident is visible outside the company.

At that point, the organization no longer controls the flow of information. Service disruptions, online posts, researcher activity or attacker claims can all shape what people believe happened before the investigation is complete.

The worry shifts from whether the details will become public, to whether the facts will make it into the public record.

A holding statement does not need to resolve questions the investigation cannot yet answer. It may simply acknowledge that an incident is under investigation, explain any known operational impact and tell stakeholders where future updates will appear.

The cadence of those updates depends on the incident, which is why having a robust crisis communications plan is essential. There is little value in issuing a statement every time a technical detail changes, but long gaps can create their own problems once the organization has told people to expect further information.

The facts need to stay aligned across the organization

Cyber incidents move quickly, and the facts can change just as fast. A customer-facing team may still be working from an earlier assessment while security has already uncovered new information. Internal updates, regulatory disclosures and website statements can easily fall out of sync.

Not every audience needs the same level of detail, but they should all be working from the same set of confirmed facts. Maintaining a clear internal record of what is known, what is still being investigated and what has been approved for external use helps prevent conflicting information from spreading.

A shared incident record should distinguish among:
ConfirmedWhat investigators can support now
Under investigationQuestions that remain open
Approved for useWhat teams can communicate externally

The people answering questions from customers, partners and other stakeholders need that context too. They should know what information is current, what they are authorized to share and which questions need to be escalated. Otherwise, an outdated answer can quickly become part of the public record.

Data exposure language needs to be precise

Terms such as "accessed," "viewed," "acquired," "exfiltrated" and "affected" are often used as though they mean the same thing, but they can describe very different findings.

Accessed Viewed Acquired Exfiltrated Affected

Investigators may confirm that an attacker had access to a system without being able to establish whether particular files were opened, copied or removed. In other cases, they may know which records were exposed to the attacker before they can determine whether any data actually left the environment.

Using those terms too broadly can make preliminary findings sound more conclusive than they are. That becomes a bigger problem as the investigation develops, because later findings may appear to contradict an earlier statement that was simply more definitive than the evidence allowed.

Material changes in scope should be addressed directly rather than quietly folded into an updated page, particularly if additional systems, records or affected individuals are identified.

Cyber incident planning needs to address decisions, not just statements

Many crisis plans include contact lists, draft holding statements and preapproved language. Those materials can save time, but they do not answer some of the decisions that tend to slow a response down.

Organizations still need to know who can authorize a public statement, how much evidence is enough before discussing potential data exposure and how disagreements among legal, security and communications teams will be resolved. Customer contracts may also create notification obligations that are easy to miss if nobody has worked through them in advance.

The communications process has to keep moving as the facts change
01 Evidence changes New forensic findings alter what is known.
02 Decision required Legal, security and communications assess the implications.
03 Approval The authorized decision-maker clears the response.
04 Stakeholder update Messages reflect the latest confirmed facts.

During an incident, those teams will not always want the same thing at the same time. Security may want more technical validation before anything is said, while legal and communications are weighing different risks around disclosure, timing and outside scrutiny.

That tension is normal. The problem is encountering it for the first time while the incident is already unfolding.

Cyber tabletop exercises are most useful when they test those decisions rather than simply walk through a response plan. An exercise that introduces incomplete information, outside inquiries and a major change in the forensic findings after the first statement has gone out will reveal far more than checking whether everyone knows where the template is stored.

Leadership visibility depends on the incident

Not every cyber event requires the CEO to become the public face of the response. For a limited technical incident, that can elevate the situation unnecessarily. A major disruption affecting customers or critical operations may call for visible leadership much sooner.

When an executive does communicate, technical detail is usually better left to the people closest to the investigation. Leadership can speak to how the organization is responding, acknowledge the impact on affected stakeholders and explain the decisions being made as a result.

The tone can make or break your efforts. Attempts to minimize disruption that people can plainly see, or language that focuses more on praising the response than addressing the consequences, can weaken an otherwise accurate statement.

Cyber communications readiness starts before the incident

The communications problems exposed by a cyber incident often trace back to gaps that existed well before the incident itself. A company may discover that nobody is quite sure who can approve a statement or how new forensic findings are supposed to reach communications. Notification obligations may also be buried in contracts or account records rather than somewhere the response team can readily use them.

By the time an incident is underway, there is little room to build that process from scratch. A cyber incident communications plan should establish how information moves from investigators to the people handling stakeholder communications, who has decision-making authority and how disagreements are escalated.

It should also reflect the reality that regulatory deadlines, contractual obligations and stakeholder needs will not always line up neatly.

The first hours of an incident will almost always involve incomplete information. The communications process needs to work under those conditions without getting ahead of the evidence.

ARTÉMIA works with organizations to prepare for and respond to high-consequence incidents, including cyber events. We support crisis communications planning, cyber incident response communications, stakeholder messaging and executive counsel.

Learn More

Stay In The Know

Get the latest expert insights and analysis delivered to your inbox.