Who’s Talking? (Why That Can Cost You Everything in a Breach)

You've been breached, now what?
Microphone being held toward a business professional outside an office while a camera crew films in the background, representing media communication during a cybersecurity breach

Breach Series # 2

The Communication Breakdown That Turns a Cyber Incident Into a Reputation Crisis for Oklahoma Businesses

Last week, you met Jodi.

She didn’t mean to become the face of your company.

She was trying to help. Trying to answer questions. Trying to make sense of a situation no one had explained to her.

But in the absence of a plan…

She became your spokesperson.

And that’s where things go from bad… to expensive.


The First Mistake: Assuming “Someone” Is Handling Communication

In the middle of a cyber incident, leadership often assumes:

  • IT is handling it
  • Legal will step in if needed
  • Someone will send an email
  • Someone will talk to the media

But here’s the reality:

If communication isn’t clearly defined before the incident… it’s already broken during it.

And when communication breaks down:

  • Employees start guessing
  • Customers start assuming
  • The public starts speculating

That’s how a contained incident becomes a public crisis.


What Actually Needs to Happen (And When)

Frameworks like those from the Cybersecurity and Infrastructure Security Agency emphasize one critical truth:

Communication is not reactive. It’s pre-assigned.

Before a breach ever happens, leadership should already know:

1. Who Is the Spokesperson

This is one person (or a very small group), typically:

  • CEO
  • COO
  • Designated communications lead

Not:

  • Front desk staff
  • Employees
  • Vendors

Because once multiple voices start speaking, you lose control of the narrative.


2. What Employees Are Allowed to Say (and NOT Say)

Here’s the uncomfortable truth:

Employees will talk because

  • They’re confused
  • They’re scared
  • They want to be helpful

Without guidance, they may:

  • Talk to reporters
  • Post on social media
  • Speculate internally (which leaks externally)

So What Should Employees Say?

Give them something simple, repeatable, and safe:

“I’m not the right person to speak on this, but our leadership team is actively handling the situation and will provide updates.”

That’s it.

What Employees Should NOT Say

This is where things go sideways fast.

Employees should avoid:

  • Confirming a breach before it’s verified
  • Guessing what happened (“I think it was a phishing email…”)
  • Assigning blame (to themselves or others)
  • Sharing internal details about systems, data, or impact
  • Posting anything related to the incident on social media

Because once it’s said…

It’s public.

And once it’s public…

It’s permanent.


The Real Fix Isn’t Silence, It’s Direction

Telling employees “don’t say anything” isn’t enough.

You have to give them:

  • A clear response
  • A clear escalation path
  • A clear understanding of who is allowed to speak

Because without direction…

Someone will step in and fill the gap.

And that’s how situations like Jodi’s happen.

A simple internal directive like:

“All external communication must go through leadership”

…can prevent a situation like Jodi’s entirely.


3. When Legal Gets Involved

Timing matters more than most people realize.

Say too little → you look like you’re hiding something
Say too much → you create liability

Legal counsel should guide:

  • What is confirmed vs. suspected
  • What language is used
  • What must be disclosed under regulations

Because once something is said publicly…

You don’t get to take it back.


4. Who Notifies Your Customers (And How)

This is where trust is either built… or lost.

Customers don’t expect perfection.

But they do expect:

  • Transparency
  • Timeliness
  • Clarity

If they hear about your breach from:

  • Social media
  • The news
  • Another customer

You’ve already lost control and probably your customer… and trust… and the list goes on and on..


Why This Matters More in Oklahoma Right Now

With evolving data breach expectations and regulations, businesses, especially in healthcare, finance, and public sector—are under increasing pressure to:

  • Notify affected individuals quickly
  • Provide accurate information
  • Demonstrate “reasonable safeguards”

Communication is no longer just PR.

It’s compliance.

And getting it wrong can lead to:

  • Fines
  • Lawsuits
  • Loss of contracts
  • Long-term reputation damage

The Real Cost of Getting This Wrong

Let’s go back to Jodi for a second.

In less than 30 seconds, she:

  • Confirmed a breach publicly
  • Assigned blame (to herself and your company)
  • Created a narrative before facts were verified

Now imagine that scenario scaled:

  • A reporter misquotes the situation
  • A customer posts online
  • Competitors start using it against you

All before leadership has even had a chance to respond, how do you handle a situation like this?


What Strong Organizations Do Differently

Organizations that handle breaches well don’t get lucky.

They prepare. Do you remember having to do fire drills and tornado drills at school? Same concept, but different rules apply.

They have:

  • A defined communication plan
  • A trained spokesperson
  • Internal messaging ready to deploy
  • Legal and IT aligned before anything is said

They don’t eliminate the breach…

They control the response.


Coming Next Week…

Communication is only one piece of the puzzle. Because even if you say everything perfectly…

What happens when your systems are still down?

Next week, we’re breaking down:

  • How businesses operate during a cyber incident
  • What happens when payroll, phones, and systems stop
  • And why most organizations can’t function without IT

A Question for Leadership

Right now, TODAY –

  • Who would speak for your company in a crisis?
  • Would your employees know what to do?
  • Would your message be clear… or chaotic?

Or would you be figuring it out… while Jodi is already talking to the media?

Missed the previous blogs in this series?

Breach Blog #1

You Might Also Like