How to Respond to a Cybersecurity Incident: Complete Guide (2026)
Published: June 2026 • 24 min read
The nature of the modern digital ecosystem means the probability of an organization falling victim to a cyber-attack is high [citation:1]. But just because an organization has been hit by a cyber incident, that does not mean its reputation—or the emotional wellbeing of its staff—needs to suffer [citation:1]. A cybersecurity incident is not just a technical problem; it is a human and communications challenge that requires careful management [citation:1]. For foundational guidance on crisis communication, explore the EMWNews Academy.
How you communicate during and after an incident shapes how your organization is perceived [citation:10][citation:1]. This guide provides a framework for effective communications before, during, and after a cybersecurity incident [citation:9][citation:10].
1. Why Communication Is Critical
Effective communication following a cyber incident forms a critical element of the activities needed to protect your company's customers, stakeholders, and reputation [citation:9]. During an incident, organizations often prioritize their technical response and relegate communication to a secondary consideration. But how you communicate—both during and after the incident—can shape how your organization is perceived [citation:10][citation:9].
Key principles to guide your communication strategy:
- Transparency builds trust – Organizations that take responsibility and are seen to be proactively trying to address the problem are perceived positively [citation:9]. If stakeholders first hear about the incident from the media, they are more likely to react negatively [citation:9].
- Silence creates space for speculation – Even a placeholder statement is better than silence [citation:9].
- Consistency across all audiences – Core points should be consistent across staff, customers, stakeholders, and media, though each group may need tailored detail [citation:10].
2. Preparing Your Communications Strategy
Although you cannot predict the timing and nature of a cyber incident, effective preparation will help your communications team lessen its harmful impact [citation:10][citation:1]. Developing this strategic communication skill is a key focus of the Learning Paths at EMWNews.
2.1 Key Elements of a Communications Plan
- Draft pre-approved templates – Prepare adaptable templates for media requests, internal updates, and customer notifications [citation:10]. Playbooks don't fail because of technology; they fail because reality doesn't follow a script. A great playbook is concise and focused on three key components: what type of crisis, who is in the room, and who is responsible for what [citation:1].
- Define roles and responsibilities – Appoint a Communications Lead responsible for approving all messages [citation:9]. Outline who in the organization has the authority to make decisions, and communicate and practice those structures in advance [citation:1].
- Identify official spokespeople – Train them in crisis communication so they understand the incident messaging strategy [citation:10].
- Establish alternative communication channels – Your usual channels may not be available during an incident. Plan for phone lines, messaging apps, or social media platforms [citation:10].
- Understand regulatory obligations – Know what regulatory disclosures are required and build them into your plan [citation:9][citation:3].
2.2 Testing Your Plan
Don't wait until an incident to find out if the plan works. Run simulations to ensure teams understand their roles [citation:3].
- Tabletop exercises – Teams talk through the procedures they would apply during a specific security event [citation:3].
- Operational exercises – Hands-on exercises that put functional processes and procedures to the test [citation:3].
- Conduct regular reviews – Reassess and validate plans annually, and revise whenever changes occur to your infrastructure or business structure [citation:3].
3. The First Hours: Immediate Response
In the first hours after an incident, facts are often incomplete or simply wrong. Acting too fast can lead to incorrect notifications, followed by corrections, followed by yet more corrections. Verify. Check again. Then communicate.
3.1 Information Gathering
The Communications Lead needs to gather the following information from the incident response team as early as possible [citation:9]:
- What type of incident has occurred?
- Who is affected (e.g., clients, agencies, the public)?
- How widespread is the incident (local, regional, national, international)?
- Is there an immediate risk to others?
- Is the incident ongoing or contained?
Also check for [citation:9]:
- Is the incident being reported publicly or on social media?
- Have clients or users reported it to you?
- Has the attacker contacted you or made themselves known?
What you don't know can be just as important as what you do. Make a note of any gaps in information. As the situation develops, new details will emerge that may change how you respond [citation:9].
3.2 Initial Statements
Prepared generic statements can be sent quickly [citation:9]:
- "We are aware of a disruption with our systems, and we are looking into the cause." [citation:9]
- "We are aware that some of our online services are currently down, we are working at getting them back up as soon as possible." [citation:9]
Avoid framing cyber attacks as minor glitches or unexpected tech issues. If you stay silent, journalists may turn to third-party sources, which can lead to misinformation [citation:9].
4. Internal Communications
HR leaders play a crucial role in steering organizations through cybersecurity incidents, serving as the backbone of support for their people [citation:11]. Cybersecurity leaders must remember that dealing with an incident is not just a technical problem—humans need to be managed too [citation:1].
4.1 Employee Communication Checklist
Once the incident response team is active, internal staff should be informed [citation:9].
| Action | Key Message | Mode |
|---|---|---|
| Initial Notification | "We're aware of a cybersecurity incident. Steps are being taken. Updates will follow." [citation:11] | Email or internal messaging |
| Employee Action Instructions | "Please change your passwords immediately and avoid using [specific systems]." [citation:11] | Email or secure messaging |
| Confidentiality Reminder | "Please do not share information externally or speculate internally. Updates will come directly from the incident response team." [citation:11] | Email or internal memo |
| External Communications Policy | "Direct all media or external inquiries to [designated contact]. Do not comment on the situation." [citation:11] | Email or internal notice |
| Regular Status Updates | "We have isolated the issue and are continuing to monitor the situation. More updates will follow." [citation:11] | Email or company-wide announcement |
| Support Resources | "Support services are available. Please contact HR if you need assistance." [citation:11] | Email or resource links |
4.2 Managing People During a Crisis
Responders need downtime to stay fresh. Make sure they eat well, have a place to stay, and have time to go home. It's an ultra-marathon, so resilience is essential [citation:1].
5. Customer and Stakeholder Communications
When external stakeholders are affected, contact them as soon as it is appropriate to do so [citation:9]. Some people prefer to talk to a real person—be ready to provide a phone number or help line [citation:9].
5.1 What to Include in Customer Communications
- What happened – A clear description of the incident in plain language
- What is being done – Actions taken to contain the incident and restore services
- What customers should do – Specific, actionable steps to protect themselves
- How to get help – Contact information for questions and support
5.2 Communicating with Different Stakeholders
A risk and visibility matrix can help decide messaging priority [citation:9]:
- High visibility, high risk – Communicate early but cautiously. Start with a short message, then expand.
- High visibility, low risk – Use a written statement or media release. Timing may depend on the scale of the outage.
- Low visibility, high risk – Notify stakeholders as soon as the incident is discovered. Public messaging can come later.
- Low visibility, low risk – No immediate communication may be needed. Consider a post on your website or social media.
6. Crafting Effective Messages
When creating messaging, you need to cover a lot of ground while keeping things clear and easy to understand [citation:9].
6.1 Messaging Best Practices
- Strike a balance – Share clear, helpful information while protecting sensitive details that could be misused or escalate the attack [citation:9].
- Avoid retractions – Avoid saying anything you may need to retract or correct later. For example, stating that there is no known impact on personal data can be problematic if this understanding changes later [citation:10].
- Assume everything is public – Assume everything you say to stakeholders could be reported to the media [citation:9][citation:12].
- Provide reassurance – Where possible, reassure stakeholders that you are taking the right steps to respond [citation:10].
6.2 Communication Dos and Don'ts
Based on legal guidance for incident communications [citation:12]:
| Do | Don't |
|---|---|
| Communicate via telephone where possible [citation:12] | Include subjective conclusions in emails [citation:12] |
| Mark legal communications as "Privileged and Confidential" [citation:12] | Circulate forensic reports via email, particularly in draft form [citation:12] |
| Limit email content to factual/objective information [citation:12] | Use unofficial communication methods (texts, instant messaging) for incident matters [citation:12] |
| Assume any written communication might be discoverable [citation:12] | Use "reply all" or continue old email threads for new topics [citation:12] |
| Start new email threads with clear recipient lists [citation:12] | Mix legal and business advice in the same communication [citation:12] |
When in doubt, pick up the phone and obtain input from legal counsel before sending a written communication [citation:12].
7. Press Release Template
Use this template as a starting point for your cybersecurity incident press release. Adapt it to your specific situation. To refine your crisis communication skills further, explore the Certifications offered by EMWNews.
FOR IMMEDIATE RELEASE [Company Name] Responds to Cybersecurity Incident [Date] [City, State] – [Company Name] is currently responding to a cybersecurity incident that has affected [describe affected systems/services]. Upon detection, we immediately activated our incident response protocols and engaged third-party cybersecurity experts. What We Know [Brief, factual description of the incident based on confirmed information] Our Response Our teams are working to contain the issue and restore services. We have [describe actions taken]. What Customers Should Do [Specific, actionable steps for customers to protect themselves] We understand that this incident may be concerning. Our priority is to resolve the situation as quickly and securely as possible. We will provide updates as new information becomes available. For more information, please visit [URL] or contact [phone/email]. About [Company Name] [Brief description of company] Media Contact: [Name], [Title] [Email] [Phone]
8. Website Status Pages
A dedicated incident page on your website serves as a single source of truth. Place a prominent banner on your homepage that links directly to it. Include:
- Clear description of the incident and its impact
- Current status and actions being taken
- Timestamps showing when information was last updated
- A direct contact method for urgent concerns
10. The Medium to Long Term
A cyber incident can resemble an earthquake in its impact. Recovery time can vary from a few days to several months [citation:10].
- Provide regular updates – Continue providing updates on progress and anticipated timelines. After the initial phase, external factors may resurface the story, so prepare for these possibilities [citation:10].
- Communicate assessment updates – Share updates on the impact, including the extent of potential data compromise and recovery efforts [citation:10].
- Continue stakeholder engagement – Provide updates and address concerns to maintain transparency and rebuild trust [citation:10].
- Share lessons learned – Transparency builds collective resilience. The NCSC encourages organizations to share insights from incident response [citation:10].
10.1 Post-Incident Review
Each incident is a learning opportunity. Conduct a formal lessons-learned session that includes all team members who played a role [citation:3]. This helps identify gaps and improve future responses [citation:3].
11. Common Mistakes
Avoid these common mistakes when responding to a cybersecurity incident:
- Delayed communication – Silence creates space for speculation [citation:9].
- Minimizing the issue – Avoiding framing cyber attacks as minor glitches [citation:9].
- Inconsistent messaging – Mixed messages across channels breed skepticism.
- Rushed statements – Rushed statements can create confusion or alarm [citation:9].
- No follow-up – Disappearing after the initial announcement.
- Vague or technical language – Obscuring what happened erodes trust.
- Not having a communications lead – A single point of accountability for approval of all messages is essential [citation:9].
Common Mistake Tip
One of the most common mistakes is waiting too long to communicate. If stakeholders first hear about the incident from the media, they are more likely to react negatively [citation:9].
12. Frequently Asked Questions
When should I communicate about a cybersecurity incident?
Communicate as soon as you have verified information. Even a placeholder statement acknowledging the issue is better than silence [citation:9].
What should I include in an initial communication?
Include: a brief description of what is known (or that you are investigating), what actions you are taking, and when people can expect more information. Be honest about what you don't know yet [citation:9].
How should I communicate with employees?
Inform employees before the external message goes out. Provide clear talking points. Remind them not to speculate internally or share externally. Provide regular updates [citation:11][citation:9].
What should I avoid saying?
Avoid vague descriptions that obscure what happened, technical jargon, minimizing the issue, or saying anything you may need to retract later [citation:9][citation:10].
How do I manage media inquiries?
Have prepared media statements ready. A single designated spokesperson should handle media inquiries. Remember that you are not required to respond to every media query, but refusing to engage can mean losing control of the narrative [citation:9].
13. Final Summary
Key Takeaways
- A cyber incident is not just a technical problem – It is a human and communications challenge [citation:1].
- Prepare in advance – Draft templates, define roles, and test your plan regularly [citation:10][citation:3].
- Appoint a Communications Lead – One person must be responsible for approving all messages [citation:9].
- Communicate early and honestly – Even placeholder statements are better than silence [citation:9].
- Be transparent about what you know—and what you don't – Note gaps in information and update as you learn more [citation:9].
- Tailor messages to different audiences – Core points should be consistent, but different groups need different levels of detail [citation:10].
- Use multiple channels – Your usual channels may not be available [citation:10].
- Maintain communication discipline – Use telephone where possible, limit email content, and assume all written communication could be made public [citation:12].
- Manage your people – Responders need downtime and support [citation:1].
- Learn and improve – Conduct lessons-learned sessions after every significant incident [citation:3].
- Avoid common mistakes – delayed communication, minimizing the issue, inconsistent messaging, no follow-up.
- In 2026, a professional cybersecurity incident response is essential for protecting your reputation and preserving trust.
Dealing with a cybersecurity incident is difficult, but can be made harder because in addition to being a stressful, high-pressure situation, decisions have to be made with incomplete information [citation:1]. That is the leadership moment: how do you take fragments of data and start correlating the next steps [citation:1]? What survives is your process: who is doing what, and how are you going to do it [citation:1]? Applying these principles can be further supported through the Business Action Center, which offers practical tools for implementation.
Take the time to prepare a crisis communication plan, practice your response through simulations, and communicate with transparency and consistency. A well-executed response turns a difficult situation into a foundation for long-term trust and credibility.
Is your organization prepared for a cybersecurity incident? Use the template, checklist, and strategies in this guide to protect your organization's reputation. Regular practice with Daily Missions can help reinforce these crisis communication habits.