Skip to content
atlas

Communication plan

Also known as: crisis communication plan

A plan for who tells what to whom during a crisis - staff, customers, authorities and the press.

Draft - this entry has not been reviewed yet.

Formal

The part of the contingency plan that names who may speak for the organisation and sets approval steps, prepared messages, contact lists and reporting deadlines for internal and external communication during an incident.

In plain English

Like agreeing in advance who in the family calls grandma with bad news, so she does not hear it first from the neighbours.

In practice

When member data leaks from a pension fund, the plan says only the director speaks to the press, members get a prepared message in e-Boks, and Datatilsynet is notified within 72 hours.

Why it matters

Confused or late messages can do more harm to trust than the incident itself, and missing a reporting deadline set by law can bring fines.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Map every audience you may have to reach in an incident - staff, management, board, customers or citizens, suppliers, insurer, regulators, police, media and partners - and note who owns each relationship.
  2. Name a spokesperson and a deputy for each audience, and agree an approval chain for outgoing messages with a maximum turnaround time, so a statement is never stuck waiting for one person.
  3. Write pre-approved holding statements for the likeliest scenarios, such as ransomware, a data leak and a long IT outage, that say what you know, what you are doing and when the next update comes.
  4. Choose a channel for each audience and prepare out-of-band alternatives in advance, such as a paper phone tree, an SMS service or a separate messaging platform, in case email, Teams and the intranet are down or watched by the attacker.
  5. Agree that one situation log owned by the crisis team is the single source of truth, and derive every message to the press, customer service and regulators from it so the versions never conflict.
  6. Build the legal duties into the plan - notifying Datatilsynet within 72 hours and informing affected people without undue delay when a breach puts them at high risk, and telling service recipients about significant incidents under NIS2 - and name who drafts each message.
  7. Keep the plan, contact lists and statements on paper or offline, and test them in exercises at least once a year, including a round where the normal channels are unavailable.

Common pitfalls

  • Claiming early that no data was taken before the forensic work has confirmed it, and then having to correct the statement.
  • Relying on email and Teams to coordinate the response while the attacker may be reading them.
  • Letting the press office, customer service and the report to the authorities tell different versions of the same incident.
  • Forgetting that ransomware groups may contact customers and journalists directly before you have said anything.

Good guides

Technical deep dive

NIST SP 800-34 Rev. 1 lists the crisis communications plan as one of the plan types around an information system contingency plan, and ISO 22301:2019 clause 8.4.3 requires procedures for warning and communication, covering communication with interested parties, the media and, where relevant, national or regional authorities, including how communication is recorded. NIST SP 800-61 addresses the same need from the incident-response side: who may share what with law enforcement, other response teams, suppliers, customers and the media, and the rule that information sharing is decided in advance rather than improvised.

A working plan contains a stakeholder map (staff, management, board, customers, citizens or patients, suppliers, insurers, regulators, police, media, partners), named spokespersons with deputies, an approval chain with a maximum turnaround time, pre-approved holding statements for the most likely scenarios, and channel choices for each audience. It also defines a single source of truth, usually a situation log owned by the crisis team, from which all messages are derived, so that the press office, customer service and the regulator do not receive conflicting versions.

The legal deadlines drive the timing more than any communications preference. Under GDPR Article 34 the controller must inform affected data subjects without undue delay when a breach is likely to result in a high risk to them, in clear and plain language describing the nature of the breach, the likely consequences, the measures taken and a contact point. Article 34(3) allows a public communication instead when individual notice would involve disproportionate effort. NIS2 Article 23(1) requires entities, where appropriate, to notify recipients of their services of significant incidents likely to affect them, and Article 23(2) to tell recipients potentially affected by a significant cyber threat what measures they can take. These external messages and the regulatory reports must be consistent, because regulators and journalists compare them.

Cyber incidents add constraints that ordinary crisis communication does not face. Email, Teams and the intranet may be compromised or monitored by the attacker, so the plan needs out-of-band channels such as phone trees on paper, SMS services or a separate messaging platform prepared in advance. Statements should avoid premature claims such as "no data was taken" before forensics confirms it, since corrections damage trust more than an honest "we are investigating". Ransomware groups also contact customers and journalists directly, which the plan should anticipate.

Relationships

Sources & further reading

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.