Breach Series # 2
The Communication Breakdown That Turns a Cyber Incident Into a Reputation Crisis for Oklahoma Businesses
Last week, you met Jodi.
She didn’t mean to become the face of your company.
She was trying to help. Trying to answer questions. Trying to make sense of a situation no one had explained to her.
But in the absence of a plan…
She became your spokesperson.
And that’s where things go from bad… to expensive.
The First Mistake: Assuming “Someone” Is Handling Communication
In the middle of a cyber incident, leadership often assumes:
- IT is handling it
- Legal will step in if needed
- Someone will send an email
- Someone will talk to the media
But here’s the reality:
If communication isn’t clearly defined before the incident… it’s already broken during it.
And when communication breaks down:
- Employees start guessing
- Customers start assuming
- The public starts speculating
That’s how a contained incident becomes a public crisis.
What Actually Needs to Happen (And When)
Frameworks like those from the Cybersecurity and Infrastructure Security Agency emphasize one critical truth:
Communication is not reactive. It’s pre-assigned.
Before a breach ever happens, leadership should already know:
1. Who Is the Spokesperson
This is one person (or a very small group), typically:
- CEO
- COO
- Designated communications lead
Not:
- Front desk staff
- Employees
- Vendors
Because once multiple voices start speaking, you lose control of the narrative.
2. What Employees Are Allowed to Say (and NOT Say)
Here’s the uncomfortable truth:
Employees will talk because
- They’re confused
- They’re scared
- They want to be helpful
Without guidance, they may:
- Talk to reporters
- Post on social media
- Speculate internally (which leaks externally)
So What Should Employees Say?
Give them something simple, repeatable, and safe:
“I’m not the right person to speak on this, but our leadership team is actively handling the situation and will provide updates.”
That’s it.
What Employees Should NOT Say
This is where things go sideways fast.
Employees should avoid:
- Confirming a breach before it’s verified
- Guessing what happened (“I think it was a phishing email…”)
- Assigning blame (to themselves or others)
- Sharing internal details about systems, data, or impact
- Posting anything related to the incident on social media
Because once it’s said…
It’s public.
And once it’s public…
It’s permanent.
The Real Fix Isn’t Silence, It’s Direction
Telling employees “don’t say anything” isn’t enough.
You have to give them:
- A clear response
- A clear escalation path
- A clear understanding of who is allowed to speak
Because without direction…
Someone will step in and fill the gap.
And that’s how situations like Jodi’s happen.
A simple internal directive like:
“All external communication must go through leadership”
…can prevent a situation like Jodi’s entirely.
3. When Legal Gets Involved
Timing matters more than most people realize.
Say too little → you look like you’re hiding something
Say too much → you create liability
Legal counsel should guide:
- What is confirmed vs. suspected
- What language is used
- What must be disclosed under regulations
Because once something is said publicly…
You don’t get to take it back.
4. Who Notifies Your Customers (And How)
This is where trust is either built… or lost.
Customers don’t expect perfection.
But they do expect:
- Transparency
- Timeliness
- Clarity
If they hear about your breach from:
- Social media
- The news
- Another customer
You’ve already lost control and probably your customer… and trust… and the list goes on and on..
Why This Matters More in Oklahoma Right Now
With evolving data breach expectations and regulations, businesses, especially in healthcare, finance, and public sector—are under increasing pressure to:
- Notify affected individuals quickly
- Provide accurate information
- Demonstrate “reasonable safeguards”
Communication is no longer just PR.
It’s compliance.
And getting it wrong can lead to:
- Fines
- Lawsuits
- Loss of contracts
- Long-term reputation damage
The Real Cost of Getting This Wrong
Let’s go back to Jodi for a second.
In less than 30 seconds, she:
- Confirmed a breach publicly
- Assigned blame (to herself and your company)
- Created a narrative before facts were verified
Now imagine that scenario scaled:
- A reporter misquotes the situation
- A customer posts online
- Competitors start using it against you
All before leadership has even had a chance to respond, how do you handle a situation like this?
What Strong Organizations Do Differently
Organizations that handle breaches well don’t get lucky.
They prepare. Do you remember having to do fire drills and tornado drills at school? Same concept, but different rules apply.
They have:
- A defined communication plan
- A trained spokesperson
- Internal messaging ready to deploy
- Legal and IT aligned before anything is said
They don’t eliminate the breach…
They control the response.
Coming Next Week…
Communication is only one piece of the puzzle. Because even if you say everything perfectly…
What happens when your systems are still down?
Next week, we’re breaking down:
- How businesses operate during a cyber incident
- What happens when payroll, phones, and systems stop
- And why most organizations can’t function without IT
A Question for Leadership
Right now, TODAY –
- Who would speak for your company in a crisis?
- Would your employees know what to do?
- Would your message be clear… or chaotic?
Or would you be figuring it out… while Jodi is already talking to the media?
Missed the previous blogs in this series?