Table of Contents
When a cyber security incident occurs, the technical response is only part of the challenge. Organisations—particularly in technology-driven sectors requiring specialized b2b tech PR—also need to communicate effectively with employees, customers, regulators, partners and, potentially, the media.
That communication cannot be worked out as the incident unfolds. Information may be incomplete, systems may be unavailable and decisions will need to be made quickly.
Developing a proactive crisis communications plan provides the structure needed to communicate clearly without getting ahead of the facts or compounding operational risk.
Communications planning needs to happen before an attack
Cyber security incident planning often focuses heavily on technology, but communications should be built into the same response framework.
The plan should establish who makes communication decisions, who approves statements and who speaks publicly. It should also identify the audiences that may need information and the channels available to reach them.
This matters because normal communication systems may be affected by the attack. Contact lists, draft statements and key procedures should be accessible even if internal networks or email are unavailable.
Preparation creates room for considered decisions when time is limited.
Establish clear roles and approval processes
A ransomware attack can quickly involve senior leadership, cyber security specialists, legal advisers, insurers, regulators and communications teams.
Each has a different responsibility. Without clear decision-making authority, conflicting priorities can slow the response or produce inconsistent messages.
A comprehensive issues management framework should identify who gathers verified information, who decides what can be disclosed, who approves external communications and who acts as spokesperson.
These roles should be tested before they are needed. A plan that exists only on paper provides little reassurance when an incident becomes real.
Communicate what you know, not what you assume
The early stages of a cyber incident are uncertain. The extent of the attack may not be known, and it may also be unclear what information has been accessed, stolen or published.
This makes accuracy essential.
There can be pressure to provide definitive answers quickly, particularly when customers or journalists are asking questions. But speculating about answers before you know them creates a greater problem if those answers later prove incorrect.
A good communications plan should distinguish between confirmed facts, matters still being investigated and actions already being taken. Remember that updates can follow as the picture becomes clearer, but once you put incorrect information into the world it is impossible to take it back.
Most importantly, organisations should understand that while being responsive is an essential part of a communications plan in a crisis, it does not mean pretending to have every answer.
Plan for different audiences
A single statement will rarely meet everyone’s needs.
Employees may need instructions about accessing systems or responding to enquiries. Customers may want to know whether their information is affected and what action they should take. Regulators and government bodies may require formal notification. Journalists will want clear facts and access to an authorised spokesperson.
Planning these audiences in advance helps an organisation communicate in the right order and with the right level of detail.
It also reduces the risk of people learning important information through media coverage or social media before hearing directly from the organisation.
Prepare for media attention
A significant ransomware attack can become a public story quickly, particularly when services are disrupted or sensitive information is involved.
Media preparation should therefore form part of the incident response plan. This includes ensuring executives undergo thorough media training, identifying official spokespeople, preparing holding statements, and establishing a clear process for handling intense journalist enquiries.
The goal is not to control every interpretation of the incident. It is to ensure accurate information is available and the organisation has a clear, consistent voice.
Pure Public Relations’ guaranteed media coverage model is built around securing media coverage, but cyber incident communication requires a different priority first: communicating responsibly when scrutiny is high.
Keep communicating after systems are restored
Technical recovery does not automatically end the communications response.
Stakeholders may still have questions, investigations may reveal new information, regulatory requirements may continue, and previous statements may need updating.
A post-incident review should examine communications alongside the technical response. Were approvals fast enough? Did the right audiences receive information? Were spokespeople prepared? Did communication channels remain available?
Those lessons should then be incorporated into the cyber incident response plan.
The strongest communications plan is not the one written after an attack. It is the one prepared, tested and understood before the organisation needs it.

