Boards of directors serve in oversight capacities to assure their organizations are ready to handle security incidents, and a big part of this includes cyber crisis communications. I believe that a board that can help its organization prepare for worst-case scenarios is taking part in preemptively reducing the impact of those scenarios.
Effective crisis communications can create a vital lifeline to continuity of business efforts and can help minimize the impact of a cyber incident. Of course, it’s crucial that organizations have timely detection, containment, eradication, and recovery capabilities. Yet just as important is training in advance the organizational muscles needed to communicate quickly and effectively with stakeholders, customers, and the wider public during a cyber-crisis, maintaining and possibly even improving trust.
A swift and coordinated response to a crisis is imperative. Social media platforms, official statements, and regular updates shared across multiple channels are all crucial components of a successful crisis communications strategy.
In our most recent
board perspectives report, we shared lessons learned from Mandiant’s Crisis Communications response specialists’ first-hand experience addressing cybersecurity crisis communications. Their guidance below covers key questions to ask of your C-suite, IT, and security leadership, and four key phases of the crisis communications response.