The single most useful thing to understand about breach communications is that almost none of the work can be done during a breach. Decisions that take a week when unhurried have to be made in an hour, by people who are exhausted, working from incomplete information, and under legal pressure. A plan written in advance is what makes that survivable.
This page covers communications planning only. It is not legal advice, and it does not set out regulatory obligations, which vary by jurisdiction and by the kind of data involved. Notification requirements in particular are a question for qualified counsel, not for a communications team.
Why the plan has to exist beforehand
During an incident there is a period — sometimes hours, sometimes much longer — when the organisation knows something has happened but does not yet know its extent. That gap is where most communications damage occurs. Silence is read as concealment; speculation that later proves wrong is worse than silence.
A prepared plan does not tell you what happened. It tells you who decides, who speaks, what can be said before the facts are settled, and how to say "we don't know yet" in a way that is credible rather than evasive.
Who needs to be in the room before anything happens
Communications cannot own this alone. A workable plan is agreed in advance between security or incident response, legal counsel, the executive who will ultimately decide, and whoever will speak publicly. Customer support belongs there too, because support is where affected customers will actually arrive first, usually before any public statement exists.
The point of agreeing this early is to establish decision rights. In an incident, the expensive delays are almost never about wording. They are about nobody being certain who is allowed to approve it.
What to draft in advance
Holding statements for a few plausible scenarios, written while calm and reviewed by counsel. They will not fit the real incident exactly, and that is fine — editing a reviewed draft under pressure is a different task from writing from nothing.
Alongside those: a contact list that does not depend on company systems that may themselves be unavailable, an agreed internal channel for coordination, and a decision on who is authorised to speak to press at all. That last one prevents the common failure where three people give three slightly different accounts within an hour.
Sequencing: who hears first
Affected customers should not learn about an incident from a news story. In practice that means customer notification and public statement are planned together, with the notification going first wherever the facts and any legal obligations allow it.
Employees need to know as well, and early. They will be asked by customers, partners and family, and an organisation whose own staff are guessing has effectively lost control of its account of events.
What credible early statements do and do not contain
They confirm what is known, state plainly what is not yet known, describe what is being done, and say when the next update will come. Committing to a next update matters more than it appears: it converts silence from an absence into a schedule.
They avoid estimating scope before it is established, avoid assigning blame, and avoid characterising the incident with words like "sophisticated" that read as deflection unless independently supported. Anything stated early that has to be retracted later costs more trust than the original incident often did.
After it ends
The communications work continues after the incident closes. What was learned, what changed as a result, and what customers can expect differently are all reasonable things to say publicly, and saying them is often what restores standing. Organisations that go quiet the moment the immediate pressure lifts tend to leave the story unfinished in the minds of the people who were affected.
A minimum viable plan
- Agreed decision rights: who approves external statements, and who deputises.
- A named, trained spokesperson, and a rule that nobody else speaks.
- Counsel-reviewed holding statements for a handful of scenarios.
- Contact routes that do not depend on potentially compromised systems.
- A sequencing decision: customers and employees before press, wherever possible.
- A commitment to scheduled updates rather than open-ended silence.
None of this reduces the likelihood of an incident. It reduces the chance that the response to one becomes the more damaging event.
See our cybersecurity PR practice for how incident preparedness sits alongside ongoing visibility work.

