Analysis
Incident communication: what to say in the first 24 hours
How security leaders communicate in the first day of an incident — internal cadence, customer and press statements, and the phrases that age badly.
TL;DR: In the first 24 hours you know less than everyone wants you to know. The discipline is separating what's verified from what's suspected, promising cadence instead of conclusions, and never saying anything you may have to retract. Trust is lost less by the incident than by the third correction to your account of it.
What are the first-day communication jobs?
Four audiences, four different needs. Responders need facts and a channel — a dedicated, access-controlled workspace with a single incident log. Executives and board need honest uncertainty: what we know, what we suspect, what we're doing, when we'll know more — in writing, on a cadence, before they hear it elsewhere. Employees need enough to not learn about it from the news, plus one instruction: don't speculate externally, route inquiries to a named owner. External parties — customers, regulators, press — need verified statements on a schedule, shaped by disclosure obligations that may already be ticking (GDPR's 72 hours, the SEC's materiality clock, state notification laws, contractual notice terms).
What does a good first statement look like?
Three sentences, honestly boring: we identified an incident affecting X; we have engaged [response steps] and relevant authorities as appropriate; we will provide an update by [time]. What it never contains: scope claims ("limited to…"), cause claims ("a sophisticated attack"), or absolutes ("no evidence that…" reads as "we haven't looked yet" to practitioners and becomes a quote in the lawsuit if wrong). Every early absolute is a loan taken against future credibility, at a terrible interest rate.
What phrases age badly?
A short blacklist, learned from other people's retractions: "no customer data was affected" (before forensics), "we take security seriously" (the industry's most hollow sentence), "sophisticated threat actor" (often disproven by the eventual root cause), "isolated incident" (until it isn't), and any specific number in the first week. The honest replacements: "our investigation is ongoing," "we will share what we confirm," "here is what we're doing now." Practitioners, journalists, and regulators all read hedged precision as competence.
How do you keep internal communication from becoming the second incident?
Three controls. One log: decisions, timestamps, who approved what — it is both your coordination tool and, later, your evidence of good faith on "without unreasonable delay" questions. Privilege discipline: route investigation communications through counsel where appropriate, and keep speculation out of writing everywhere — casual Slack theories become discovery exhibits. A single voice: one approval chain for anything external, one spokesperson, one holding statement everyone else points to. The companies that come out of incidents with reputations intact are rarely the ones with the smallest breaches — they're the ones whose account of events never had to change.
Frequently asked questions
- What should a company say publicly in the first 24 hours of a breach?
- Only what is verified: that an incident is being investigated, what the company is doing, and when it will update next. Early specifics about scope or cause are usually wrong, and walking back 'no customer data was affected' costs more trust than saying 'we don't yet know.'
- Who should approve external incident statements?
- A small pre-agreed group — typically legal, communications, the CISO, and the CEO or a designated executive. Disclosure obligations (SEC, GDPR, state laws, contracts) mean statements are legal documents; nothing goes out unreviewed.
- How often should you update stakeholders during an incident?
- On a stated cadence, even when there's nothing new. 'Next update at 4 pm' with an on-time 'still investigating' beats silence — silence gets filled by speculation.
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.