Crisis Communication During Cyberattacks – Part 1 of 3: What Companies Need to Consider in the Four Phases
Cyberattacks are among the greatest risks of our time – for businesses, governments and society as a whole. The rapid development of AI is also enabling ever new and increasingly sophisticated forms of attack.
When a cyberattack occurs, companies face a threefold challenge: managing the attack itself, complying with potential legal obligations in the event of a data breach, and communicating with all relevant internal and external stakeholders – from employees and affected individuals to customers and the media.
Why Cyberattacks Are Particularly Challenging from a Communications Perspective
A product recall, an industrial accident, an allegation of compliance misconduct against a senior executive: crises like these are challenging from a communications perspective, but they often follow a familiar pattern. A cyberattack, however, challenges several fundamental assumptions of traditional crisis communication at once:
The facts emerge gradually. Forensic investigations provide preliminary findings as they progress. In the first few days, it is often impossible to determine conclusively whether data has merely been encrypted or has also been exfiltrated. Yet communication cannot wait – precisely at a time when there is the least certainty and the greatest demand for information.
There is an adversary with a communications strategy of their own. In ransomware attacks, attackers can deliberately control the pace of escalation – through countdowns, leak sites, staged data releases or direct contact with customers and the media. Losing control of the narrative is one of the key risks in this situation.
The organisation is both a victim and accountable. A cyberattack is a criminal act against the company. At the same time, questions immediately arise as to whether its security measures, response and handling of information were adequate. This dual role makes communication during a cyber crisis particularly sensitive.
Communication channels can be part of the incident. Email, intranet, telephone systems, websites or CRM systems may all become unavailable at the same time. With them, distribution lists, contact details and prepared materials may also become inaccessible. If the crisis communication plan is stored on an encrypted drive, it is useless at the very moment it is needed most. Alternative communication channels and offline access to key contact details should therefore be an integral part of crisis preparedness.
Four Types of Cyberattack – Four Communication Strategies
“Cyberattack” is not a single scenario, but an umbrella term for different types of incidents. Distinguishing between them is important for communication planning, as their visibility, time pressure and target audiences can vary significantly.
Encryption and extortion (ransomware): Service and system outages quickly become apparent – often before the cause is clear. Issuing a holding statement and setting up appropriate tools for ongoing process communication are among the key early communication measures. The extortion itself should not be the focus of communication. Instead, communication should address the cause – the cyberattack – its internal and external impact, any potential data loss and, at a later stage, plans for restoring operations.
Data exfiltration without operational disruption: From the outside, everything may initially appear to be functioning normally. The need to communicate arises from legal obligations, the company’s responsibility towards those affected and potential reputational risks. The situation becomes particularly critical if third parties break the news first – for example, via a leak site or through the attackers themselves contacting affected individuals directly.
Operational disruption and sabotage, e.g. DDoS attacks: Customers may notice the disruption before its cause has been identified. Time pressure is high, while data may or may not have been compromised. At this stage, service communication comes first: What is working, what is not, and which alternative channels can customers use to contact the company or access its services?
Attacks via service providers and the supply chain: A company may be affected even if it has not been attacked directly. Control over information may lie partly with a third party, yet the company still has a responsibility to explain the situation to its customers. Contractually defined information and notification processes therefore become an important communication factor – as do the expectations of different stakeholder groups regarding who should inform them, how and through which channels.
The Four Phases of Cyber Crisis Communication
Cyber crises do not unfold as a single event. They develop dynamically through different phases, each with its own communication requirements.
Phase 1: Suspicion – Disruption Without a Confirmed Cause
Something is not working, and no one knows for certain why. The communication challenge is to remain responsive without committing to an explanation too early. A holding statement is the appropriate tool at this stage. It describes what is currently known, confirms that the issue is being investigated and indicates when the next update can be expected.
Crucially, every holding statement has an expiry date. Referring to a “technical disruption” is appropriate as long as this reflects the organisation’s actual state of knowledge. Once a cyberattack has been confirmed internally, the wording must be adjusted accordingly. Otherwise, the technical crisis risks being compounded by a crisis of credibility.
Phase 2: Confirmation – Naming the Attack
Once the attack has been verified, the communication task shifts from bridging uncertainty to providing context and orientation. At this point, both sequencing and target audiences become important: employees, customers, affected individuals, the media and, where relevant, other stakeholders all require different information. At the same time, statutory reporting and notification deadlines may already be running.
A central task in this phase is to develop a master narrative for the attack, incorporating the three core elements of Concern, Control and Commitment. This provides the basis for informing all target audiences consistently in line with the One Voice principle. Importantly, individuals affected by a data breach must always receive dedicated communication that both meets legal requirements and helps preserve trust.
Phase 3: Investigation and Ongoing Communication
Forensic findings often emerge gradually, the picture becomes more precise, and potential data releases on the dark web may come to light. From a communications perspective, this means providing updates at a reliable cadence while clearly distinguishing between confirmed facts, open questions and next steps.
Appropriate communication tools and channels need to be established for this purpose. These may include microsites hosted independently of the organisation’s affected systems, helping to ensure that they remain accessible throughout the incident.
As the situation develops, each new stage can then be communicated clearly and transparently.
Phase 4: Recovery and Follow-Up
The technical recovery marks an important final chapter of the crisis: restoring services for customers and system access for employees, communicating any enhanced security measures and recognising the efforts of the teams involved are all important steps on the path back to normal operations.
What Companies Need to Decide Before a Cyberattack Occurs
Cyberattacks are among the types of crisis in which the communication infrastructure itself may be affected. The ability to communicate effectively during an incident must therefore be prepared and safeguarded in advance. This should be a central component of any crisis communication manual.
Preparations should include, for example, alternative channels for communication within the crisis team, offline access to key stakeholder contact details – such as employee email addresses and media contacts – and dark sites: pre-prepared websites that can be activated in an emergency and are hosted independently of the organisation’s own systems.
Frequently Asked Questions About Cyber Crisis Communication
How should companies communicate in the first hours after a cyberattack?
With a concise holding statement that covers only the confirmed facts, the current impact, the actions being taken and when the next update can be expected. Speculation and premature assurances have no place in early crisis communication.
When should a cyberattack be publicly acknowledged?
Once an attack has been confirmed internally, communications should no longer refer to the incident merely as a “technical disruption”. Whether the company should also communicate proactively to the public depends on the visibility of the incident, who is affected, applicable notification requirements and the specific circumstances.
What is a holding statement in the context of a cyberattack?
A holding statement is a brief, preliminary statement used during the early stages of a crisis. It enables the organisation to communicate while avoiding unverified claims about the cause, the attackers or the consequences.
Why is it risky to rule out a data breach too early?
Because forensic investigations often only establish at a later stage whether data has been exfiltrated and, if so, to what extent. If a company gives the all-clear too soon, it may later have to correct its statement. This can damage credibility more than clearly acknowledging uncertainty from the outset.
Tina Hunstein-Glasl
Tina Hunstein-Glasl is the founder of Tina Glasl Strategy & Communication and is one of the leading experts in crisis communication and strategic change management in the German-speaking region. For over 20 years, she has supported companies, organizations, and institutions in successfully navigating complex challenges, crises, and transformations. As a co-founder of the ORVIETO ACADEMY for Communicative Leadership, she also strengthens the communication skills and inner stability of leaders in the context of the 21st century. She studied communication, political science, and sociology at LMU Munich and is a trained coach with further qualifications in organizational development.
Whether it’s a cyber incident, a product recall, or legal disputes, communication is the decisive factor in determining how strongly a crisis affec...
- Crisis communication
- Crisis prevention
Crises are the ultimate test for every leader and communication professional. As external turbulence increases, manuals, processes, and structures ...
- Crisis prevention
- krisen-resilienz
Not every crisis turns into a scandal – but certain factors significantly increase the risk. When does a problem become a crisis, and when does a c...
- Crisis communication
- Crisis prevention