8min read

Crisis Communication During Cyberattacks – Part 2 of 3: Crisis Communication Plan: From the Master Story to Ongoing Updates

A cyber crisis is not a single event, but a situation that unfolds over weeks. The crucial question, therefore, is not only what is said on the first day. What matters is whether the organization’s position still holds up on day fifteen. This is precisely where communication in this type of crisis often fails: not with the initial statement, but with what follows.

The Master Story: A Position That Must Hold Up Despite Uncertain Facts

The master story is the written set of core messages from which all other communication materials are derived, both internally and externally. It ensures a consistent one-voice approach. The following elements have proven effective:

  • 1. Current facts: What has been confirmed, what is being investigated, and what remains unclear? Making this distinction prevents preliminary assumptions from resurfacing later as inaccurate statements.

  • 2. Position and responsibility: How does the organization assess the incident, and what responsibility does it assume for investigating it and addressing its consequences? This part can be formulated early on and generally remains relatively stable.

  • 3. Actions and commitments: Who is investigating what, what are the next steps, and how will further information be communicated? In the early stages, this section compensates for missing facts by providing clear and credible commitments.

  • 4. Personal statement: Those affected should always (!) be able to expect the organization to address them personally, express regret or, where necessary and appropriate, offer an apology.

The master story should not include speculation about the cause of the incident or who may be responsible, superlatives about the organization’s own level of security, premature assurances regarding the data situation, or details of a potential extortion attempt.

The master story should be coordinated between the crisis management team, communications, legal, data protection, and the forensic experts responsible for investigating the incident. In practice, the time-critical bottleneck is often not drafting the master story, but getting it approved.

Keeping the Master Story Up to Date: A Living Document

The second, often underestimated step is keeping the master story up to date. Forensic findings emerge gradually, and each new piece of information can change the communication landscape. Without a structured updating process, conflicting versions can emerge, creating a second, self-inflicted crisis.

  • Version control with date and time. Each version is clearly identifiable, ensuring that everyone communicating on behalf of the organization knows which version is current.

  • Consistency checks against previous statements. Before each new version is released, it is checked against previous publications and commitments for potential contradictions. Any discrepancies are explained proactively rather than corrected without comment.

  • Separate stable from variable elements. The organization’s position and sense of responsibility remain largely consistent, while the factual picture evolves. Mixing the two can make every update appear as though the organization’s position itself has changed.

  • A reliable update schedule. Updates are provided at announced intervals. Even if there is no change in the situation, communicating this can be valuable if an update has been promised and that commitment is honored.

Dark Site or Status Page: A Central Source for Reliable Updates

A dedicated crisis microsite, dark site, or status page is one of the most effective communication tools during a cyber incident. It brings the latest information together in one place and reduces the risk of conflicting messages being communicated through different channels.

It can provide chronological updates with dates and times, the status of key services, alternative contact options, and selected public questions and answers. For the media, it serves as an authoritative primary source that can be cited; for customers, as a reliable point of reference; and for internal teams, as a central resource for clarifying important questions related to day-to-day operations.

Two factors determine whether such a page is effective. First, it must remain accessible independently of the affected infrastructure. Second, it must be kept up to date. A status page containing outdated information signals a lack of progress rather than an organization’s ability to manage the situation.

The Communication Toolkit: Seven Key Elements and When to Use Them

The specific communication materials are derived from the master story. What matters is less whether every piece of wording has been finalized in advance than knowing when each material is needed, who approves it, and through which channel it will be distributed. Since the master story is developed on the basis of the first verified findings, it is preceded in the early phase by a holding statement. This bridges the first critical hours.

  • Initial employee communication: Provides operational information (including contingency operations), security and behavioral guidance, and agreed messaging for handling external inquiries.

  • Customer communication: Sets out what is currently known, the specific impact on customers, and alternative ways to contact the organization. Practical service information takes priority over detailed explanations.

  • Press statement: Can be reactive or proactive. If there is a visible disruption to operations, early communication is often necessary; in the event of a data breach, the decision to communicate proactively requires careful consideration.

  • Internal Q&A / agreed messaging: Ensures a consistent one-voice approach across hotlines, sales teams, reception staff, managers, and communications.

  • Public FAQ: Addresses selected questions from customers and the media in sufficient detail for publication without disclosing sensitive security information.

  • Notification to affected individuals (particularly in the event of a data breach): Shaped by legal requirements, but also an important opportunity to build trust; it should be clear and easy to understand, with specific guidance on actions to take and security precautions.

Requirements for the Q&A Document

The internal Q&A is the workhorse of a one-voice policy. Hotline staff, sales teams, reception staff, managers, and the communications department must all provide the same answer to the same question – over a period of weeks and as the facts continue to evolve.

  • Non-answers should be included. For questions about the attack vector, the perpetrators, defensive measures, or extortion demands, the agreed response may simply be that the organization will not provide information on the matter.

  • The Q&A follows the versioning of the master story. In line with the one-voice policy, both documents must always be up to date and based on the same current level of knowledge.

  • Expert and general-audience versions. Technical details – for example, regarding backup and security systems – are often the subject of follow-up questions. Depending on who is asking, answers may need to be more detailed and technical or more accessible to a general audience. For example, we distinguish between inquiries from specialist IT security publications and those from general or regional media.

  • Preparation is valuable. It is advisable to prepare key questions relating to IT and cyber security in advance as part of the crisis communication manual. In the event of an incident, these can then be updated much more quickly.

In addition, a public Q&A can be useful. It should address only approved questions from customers, affected individuals, and the media. This format also offers benefits for SEO and generative search systems, as it makes specific questions and clear answers easier to find. These selected Q&As can, for example, be published on the crisis microsite.

Cybersecurity Mailings: Keeping Security in Mind

Following a cyberattack, recipients need to be informed while at the same time being encouraged to exercise greater caution. This is precisely why mailings must be designed in a way that does not facilitate follow-up attacks.

  • Information requirements. The information that must be included in a mailing should be coordinated with the legal and data protection teams. Crisis communications determines which additional content can help maintain trust and protect the organization’s reputation.

  • Balancing empathy with legal review. It is possible to express regret about the impact of the incident and take responsibility for investigating it without prejudging a cause or liability that has not yet been established.

  • Use links and attachments sparingly. Avoid them wherever possible in the initial communication. If, for example, you refer recipients to the security recommendations of the German Federal Office for Information Security (BSI), do so without including a link. The reason is simple: clicking malicious links or opening attachments is a common way for attackers to gain access to systems.

  • Do not ask recipients to change login credentials via a link provided in the mailing. If password changes are necessary, explain how to access the service through the usual, familiar route rather than providing a new login link.

  • Announce further communications in advance. If recipients know that another message will follow, they can verify it more easily.

  • State verification rules explicitly. For example: The company will never contact you unexpectedly to ask for passwords, login credentials, or bank account information.

What a Cyber Crisis Communication Plan Should Include

As complex and dynamic as cyberattacks are, organizations can prepare for them effectively – through clear structures, pre-drafted communication materials, and regular exercises.

  • Approval process. Define a core team comprising communications, legal/data protection, and forensic experts to draft the holding statement and master story. These are then submitted to the crisis management team for final approval.

  • Backup infrastructure. Maintain distribution lists outside the organization’s own systems, external email addresses, alternative telephone channels, an independently hosted status page (dark site/microsite), and documents that are accessible offline.

  • Pre-drafted content. Prepare Q&As, mailing templates, and holding statements in advance. Well-prepared text modules make it possible to respond more quickly and effectively when a crisis occurs.

  • Crisis exercises. Crisis management teams as well as communications teams can practise their response to cyberattacks through realistic exercises and crisis simulations, helping them prepare as effectively as possible for a real incident.

Frequently Asked Questions About Crisis Communication During Cyberattacks

What should a cyber crisis communication plan include?
At a minimum, it should include approval processes, backup communication channels, contact lists stored outside the organization’s own infrastructure, pre-drafted communication materials, a system for developing and updating the master story, internal Q&As (particularly on IT and cyber security), an independently accessible website (dark site), and a clear process for verifying communications.

What is a master story in cyber crisis communication?
A master story is an agreed, written set of core messages from which all internal and external communication is derived. In a cyber crisis, it should cover confirmed facts, outstanding questions, the organization’s position and responsibilities, actions and commitments, as well as a personal statement addressing those affected.

Does a company need a dark site for cyberattacks?
Not every company needs a separate website, but having a central source of up-to-date information that remains accessible independently of the organization’s own infrastructure is highly advisable during a cyber incident. The key requirement is that it continues to function even if the organization’s own systems are unavailable.

How often should a company provide updates during a cyberattack?
There is no fixed standard. Instead, updates should follow an announced schedule that the organization can realistically maintain. Wherever possible, the timing of the next update should be clearly communicated. Even an update without new forensic findings can help reduce uncertainty.

A robust master story should not be developed only once a cyberattack is underway. It should be prepared in advance and consistently updated throughout the crisis.

Contact us – we will work with you to develop a crisis communication plan including a cyber scenario, master story, and a ready-to-use communication toolkit.

author

Tina Hunstein-Glasl

Tina Hunstein-Glasl is the founder of Tina Glasl Strategy & Communication and is one of the leading experts in crisis communication and strategic change management in the German-speaking region. For over 20 years, she has supported companies, organizations, and institutions in successfully navigating complex challenges, crises, and transformations. As a co-founder of the ORVIETO ACADEMY for Communicative Leadership, she also strengthens the communication skills and inner stability of leaders in the context of the 21st century. She studied communication, political science, and sociology at LMU Munich and is a trained coach with further qualifications in organizational development.

You may also be interested in