Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Toss your standard crisis communications plan for cyberattacks. Five questions to ensure your company’s preparedness

By Ted Birkhahn
c-suite-freepik-security.jpg
October 28, 2021

The unrelenting pace of cyberattacks shows no signs of abating. Google and Microsoft have pledged billions of dollars to mitigate cyberattacks. The Biden Administration has made cybersecurity a core strategic imperative for America’s national security. State actors continue to unleash debilitating cyberattacks against companies of all sizes. The risk is omnipresent and will continue to intensify.

 The level of public-private sector cooperation is unprecedented – and that’s a good thing. But here’s the rub: the sophistication, evolution, and lethality of these attacks will progress. Cyberattacks are one of the most significant threats that can destroy a company’s reputation, undermine customer loyalty, threaten investor commitment, and plunge overall value.   

 Boards understand an unavoidable reality: it’s not if, but when your company will face a cyberattack. Another thing they must realize is that cyberattacks are distinct from other types of corporate crises – especially in how, when, and why an organization communicates with its stakeholders during and in the aftermath of an attack. Here are five questions boards should ask the C-suite before a cyberattack occurs.

 

  1. How well do our Chief Security Officer and Chief Communications Officer work together? Cyberattacks affect every aspect of a business; therefore, it stands to reason that a multidisciplinary team should comprise the Cyber Incident Response Team (CIRT). It’s critical that a senior communications executive is included with legal, technology and security leaders, to ensure effective coordination. This will help to build a bridge between IT, legal, the C-suite, and outside partners, and ensure that the communications team has insights into accurate information as the breach unfolds. 

 

  1. How will we respond publicly without inciting threat actors? A ransomware attack typically involves ransom negotiations and stolen data. This begs the question of whether your company has a communications governance plan that adheres to compliance, security, and messaging protocols. Any message — whether through a company spokesperson, social media post, or external announcement — must strike the right balance of addressing stakeholders’ key concerns without further provoking the threat actors. When and how the company communicates influences ransom demands, the length and severity of the attack, and the release of stolen information.

 

  1. Do we have a plan in place that adheres to regulatory protocols? Put simply, if your Chief Communications Officer is spearheading the communications charge, they should be as knowledgeable in cybersecurity reporting requirements as your Chief Compliance Officer to respond to a host of international and domestic compliance protocols. 

For instance, UK General Data Protection Regulation requires organizations that are hit by personal data breaches that could “result in a high risk to the rights and freedoms of individuals” to notify the Information Commissioner’s Office within 72 hours. For financial institutions (FI), if customer information is misused or breached, FIs need to inform regulators, under the Gramm-Leach-Bliley Act, in a specified timeframe. Similarly, at the state level, FIs based in New York that experience a cyberattack must follow compliance protocols outlined in the New York Department of Financial Services (NYDFS) Cybersecurity Regulation.

 

  1. If our primary modes of communication are compromised, what’s our plan? If one or more communications channels are rendered useless or dangerous because of a cyberattack, it’s critical to have backup communications channels established to disseminate information quickly and effectively. Your communications team must know how to use them and your stakeholders must be reachable via these channels. Your company should consider cloud-based platforms that facilitate one- and two-way communications, and can be turned live at a moment’s notice. 

 

  1. Should we prioritize speed or accuracy? A slow response during a cyberattack can profoundly damage a company's reputation. Yet, although speed is important, inaccurate information will cause more damage. If the crisis communications infrastructure is already in place, combined with the appropriate legal, compliance, operations, and IT entities, your chances of communicating accurately and impactfully increase significantly.  

 

Cyberattacks represent one of the most severe threats that can tank a company’s value and erode its reputation. The good news is, cyberattacks are front and center on most companies' radar of potential vulnerabilities. But many are still ill-prepared, especially in understanding the significant differences between standard crisis scenarios and cyberattack incidents. While the above questions are not a panacea for warding off attacks, they should help to put your company in a much stronger position to mobilize resources and respond effectively. 

KEYWORDS: compliance tools crisis communications cyber security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Ted Birkhahn is President of HPL Cyber, a brand, marketing and communications firm that specializes in helping cybersecurity companies grow.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • hacker-freepik

    Thinking like a hacker: Protect your company from cyberattacks

    See More
  • The Long and Winding Road to Cyber Recovery

    Five steps to secure your business – From the C-suite to the assembly line

    See More
  • 10 Questions for Your Security Consultant

    See More

Related Products

See More Products
  • 1119490936.jpg

    Solving Cyber Risk: Protecting Your Company and Society

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Physical Layer Security in Wireless Communications

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing