Skip to content
CISOteria
Back to Insights
SecOps

Cyber Crisis Communication: What to Say While an Incident Is Still Unfolding

August 27, 2026 7 min read CISOteria
Cyber Crisis and how to overcome it
Table of Contents

Cyber Crisis Communication Starts Before You Have All the Answers

In one of our previous discussions on post-incident recovery, we looked at the role communication plays after the immediate crisis begins to ease. Even when systems are restored, customers, employees, partners, regulators, and the board may still need explanations, evidence of corrective action, and reasons to believe the organization has regained control.

But communication does not begin when the incident ends.

Cyber crisis communication begins before the investigation is complete. While security teams are still containing the incident and establishing the facts, executives, employees, customers, and regulators may already need answers. 

At that stage, the forensic investigation may still be incomplete. The scope may change. Some information may be too sensitive to share. Different stakeholders may need different answers, and every statement the organization makes can affect what happens next. 

The organization is therefore expected to communicate at exactly the moment when certainty is lowest. 

This is where crisis communication differs from post-incident trust repair. The immediate challenge is to keep people informed while containment, investigation, recovery, and sometimes negotiations with the attacker are still underway.

Recent research identifies this as one of the characteristics that makes cyber crisis communication different from more traditional crisis communication. In many crises, communication follows the disruptive event. In a cyber incident, communication frequently happens while forensic investigation and operational response are still in progress.

A public statement can affect a ransomware negotiation. Information shared internally may reach an attacker. In a third-party breach, an organization may depend on another company’s investigation before it can answer its own customers. 

For CISOs, the challenge begins before the full picture is available: how do you communicate while the incident is still unfolding?

Communication Is Part of Cyber Incident Response

Cyber incident response is often described through technical activities such as detection, analysis, containment, eradication, and recovery.

Communication runs through the same process.

A 2025 study on cybersecurity crisis communication argues that organizations need structured communication protocols throughout the incident lifecycle rather than ad hoc messaging. Its proposed model integrates communication into notification and escalation, analysis and response, external stakeholder communication, and post-incident review. 

Poor communication can make an already difficult incident harder to manage. Different teams may work from different versions of the situation. Executives may receive information that has already changed. Customer service may answer questions before an agreed position exists. Employees may learn developments through the media. Legal, security, communications, and management may each apply a different standard when deciding what can safely be shared. 

The result is fragmentation at exactly the moment when the organization needs a common understanding of what is happening.

The same 2025 research emphasizes predefined roles, escalation paths, communication responsibilities, and structured information sharing across technical, legal, management, and public relations teams. 

Knowing who communicates is therefore only the first step. The harder decision is determining what can responsibly be said while the facts are still changing.

The Goal Is Clarity Under Uncertainty

In the early hours of a serious cyber incident, the organization may still have only a partial picture. Even so, waiting to communicate may not be practical. 

The organization should clearly separate confirmed facts from information that is still uncertain. A useful update can explain what has been confirmed so far, what the investigation is still examining, what actions are already underway, which groups appear to be affected based on current evidence, and when more information is expected. 

The 2026 study supports this approach by highlighting the value of communicating what is known, what remains under review, and what is still unclear. 

This allows the organization to provide useful information without presenting an incomplete forensic picture as a final conclusion.

Build a Cyber Crisis Communication Plan Before You Need It

The worst time to decide how cyber crisis communication works is when the incident is already unfolding.

By then, information is changing quickly. Technical teams are focused on containment. Legal teams may be assessing reporting obligations. Executives want answers. Employees and customers may already be asking questions.

A communication plan therefore needs to define the process rather than predict the exact wording of a future statement.

The 2025 research emphasizes predefined roles, escalation paths, communication channels, stakeholder engagement, and coordination between security, management, legal, and communications functions. The 2026 research goes further, arguing that communication should remain closely connected to forensic and operational work because communication decisions can directly affect negotiations, investigations, and containment. 

For CISOs, preparation means establishing how technical information reaches decision-makers, how uncertainty is communicated, how earlier statements are updated, how alternative channels are activated when normal systems fail, and how critical suppliers are expected to share information during an incident. 

The aim is to reduce improvisation when pressure is highest and keep communication connected to the live response. 

CISOteria can support this process by keeping risks, responsibilities, decisions, and follow-up actions connected in one operational view. This gives security leaders a clearer picture of what is known, who owns the next step, and which stakeholders need to be involved as the incident develops.

One Incident Does Not Mean One Message

A cyber incident rarely has a single audience. 

The 2025 research identifies audience adaptation as an important part of structured cyber crisis communication. Technical teams, executives, regulators, customers, and the media have different information needs, requiring messages to be adapted to each audience to reduce the risk of misunderstanding. 

Employees Need Direction

Internal communication becomes especially important when the incident begins affecting daily operations.

Employees may lose access to systems, remote work tools, shared files, or normal communication channels. They may also receive questions from customers, partners, or other external contacts before the organization has published a broader update.

The 2026 study describes employees as both affected participants and important parts of the wider information environment. What they understand, what they repeat, and how they respond to questions can influence the course of the incident.

Internal communication should therefore focus on practical direction. Employees need to understand which systems are safe to use, which alternative channels have been approved, where questions should be directed, and what information should remain restricted.

Executives Need Decision-Relevant Information

Executives have a different information need.

They usually do not need every forensic artifact or technical hypothesis. They need enough reliable information to understand the business consequences and make decisions while the investigation continues.

The CISO therefore has to translate a changing technical picture into decision-relevant information. That may include the operational impact, possible exposure of customer data, regulatory implications, dependencies on third parties, the status of recovery, and any communication decision that could affect the investigation or negotiations.

The Attacker May Be Listening Too

Cyber incident communication must account for the possibility that threat actors are monitoring what the organization says publicly – and potentially internally.

The 2026 research repeatedly notes that threat actors may monitor public communication and, depending on their level of access, may also be able to observe internal communication.

External communication can unintentionally reveal useful details to the attacker. A statement may expose information about disruption, recovery progress, priorities, or the organization’s negotiating position. 

Organizations should therefore consider the operational impact of a message before publishing it. 

Cyber Crisis Communication Depends on the Type of Incident

Cyber crisis communication does not follow one fixed template. The right approach depends on the type of incident and the operational risks created by disclosure. The 2026 research highlights several important differences: 

  • Ransomware: Communication may affect negotiations, reveal the scale of disruption, or expose recovery capabilities. Organizations need to keep stakeholders informed while preserving enough flexibility to adapt as the incident develops.
  • Third-party compromise: The organization may need to communicate with its own customers while depending on the compromised supplier for forensic information. Clear pre-incident agreements on information sharing, update timing, and external communication can reduce delays and confusion.
  • Nation-state espionage: Broad communication may compromise an ongoing investigation or alert an attacker who is still active. Early communication may therefore need to remain limited to a small need-to-know group, sometimes through alternative channels.

The key point is that timing, transparency, and the level of detail should reflect the operational context of the incident. In some cases, faster communication is necessary. In others, restraint protects the response. 

Message Framing Comes After Evidence

Once the organization has established what it can responsibly confirm, it still has to decide how to explain the incident. 

Research presented at ECIS 2025 examined 7,941 U.S. data breach disclosures and found that organizations rarely rely on a single response strategy. The researchers identified 18 distinct combinations, including approaches such as compensation, apology, justification, excuses, and presenting the organization as a victim of the attack. 

These choices shape how the organization explains responsibility and responds to those affected. 

For CISOs, however, the factual foundation needs to come first. The organization may want to reassure customers or explain the actions already taken, but the message should remain within the boundaries of what the investigation can support. 

Conclusion: Communicate With the Incident as It Develops

Cyber crisis communication takes place while the facts are still developing.

Security teams may still be investigating while executives, employees, customers, partners, and regulators already need information. The organization therefore needs a communication process that can evolve with the incident.

That means keeping messages aligned with the current evidence, adapting information to the needs of different audiences, and considering how disclosure could affect the operational response.

This is what separates crisis communication from post-incident trust repair. Post-incident communication addresses what happens after the immediate crisis. Crisis communication helps the organization navigate the period when the outcome is still uncertain.

A mature incident response plan should therefore define how communication works before the first urgent request for an answer arrives.

For Further Reading

This blog post is based on insights and analysis from:

  • Covarrubias, Jersain Zadamig Llamas. “Effective communication as a pillar of cybersecurity: Managing incidents and crises in the digital era.” Journal of Risk Analysis and Crisis Response 15.2 (2025): 34-34.
    https://doi.org/10.54560/jracr.v15i2.564 
  • Jechle, Deinera, Sebastian Schuetz, and Heiko Gewald. “Decoding Data Breach Response Strategies: Insights from Situational Crisis Communication Theory using Topic Modeling.” ECIS. 2025. 

https://www.researchgate.net/publication/393568155_Decoding_Data_Breach_Response_Strategies_Insights_from_Situational_Crisis_Communication_Theory_using_Topic_Modelling 

  • Jong, Wouter, Kelly Mikelatou, and Marcel Vielvoije. “When Crisis Communication Meets Forensics: Managing Narratives in Ransomware, Third-Party, and Nation-State Attacks.” Computers & Security (2026): 105082. 

https://doi.org/10.1016/j.cose.2026.105082 

Frequently Asked Questions

Want to learn more?

Subscribe for the latest insights on cyber program management and security leadership.

See Plans