Skip to main content
Category: Incident Response

Crisis Communications

Also known as: Crisis Communication, Crisis PR
Simply put

Crisis communications is how an organization collects, manages, and shares information when it faces a serious event that threatens its reputation or operations, such as a data breach or security incident. The goal is to respond quickly and openly with the media, employees, and the public in order to protect the organization's brand and maintain trust. It focuses on messaging and information flow rather than on the technical work of resolving the underlying incident.

Formal definition

Crisis communications is the process of collecting, processing, and disseminating information relevant to addressing a crisis that poses a threat to an organization's reputation or operations. In practice it encompasses stakeholder messaging, media engagement, and coordinated internal and external communication executed under time pressure, and it is typically governed by a predefined crisis communication plan and strategy. Within a security context it functions as a distinct discipline that runs parallel to technical incident response: it manages narrative, stakeholder trust, and disclosure obligations rather than performing containment, eradication, or recovery. A virtual CISO may advise on how communications integrate with the broader incident response program and governance structure, but the drafting, approval, and delivery of crisis messaging is commonly led by communications, legal, and executive functions, with legal and organizational accountability remaining with the client organization and its officers. Effectiveness depends heavily on advance planning, defined roles, stakeholder access, and organizational maturity, and outcomes may vary by organization; it should not be conflated with the technical remediation of the incident itself.

Why it matters

When a security incident such as a data breach becomes public, the way an organization communicates can shape stakeholder trust as much as the technical response itself. Crisis communications exists to collect, process, and disseminate information that is important to addressing the crisis, with the primary goal of protecting the organization's reputation while engaging with the media, employees, and the public in an open and timely manner. Poorly managed messaging can compound the damage of an incident, while a coordinated and transparent response can help preserve trust during a period of intense scrutiny.

It matters for security leaders because crisis communications is a distinct discipline that runs parallel to technical incident response rather than a substitute for it. Containment, eradication, and recovery address the underlying incident, but they do not manage the narrative, stakeholder relationships, or disclosure obligations that surface simultaneously. Organizations that treat these as the same function often find that technical remediation is underway while messaging lags, contradicts itself, or fails to reach key audiences under time pressure.

A common mistake is assuming that a virtual CISO or an incident response team will handle communications by default. In many organizations, the drafting, approval, and delivery of crisis messaging is led by communications, legal, and executive functions, with legal and organizational accountability remaining with the organization and its officers. Effectiveness typically depends on advance planning, defined roles, and stakeholder access, so organizations that wait until a crisis is underway to determine who speaks and what is said are often disadvantaged.

Who it's relevant to

Executives and Organizational Officers
Because legal and organizational accountability for security decisions and disclosures typically remains with the organization and its officers, executives are often central to approving and delivering crisis messaging. They set the tone for how the organization engages with the media and the public and carry responsibility for maintaining stakeholder trust during a threat to reputation or operations.
Communications and PR Teams
Communications functions commonly lead the drafting and delivery of crisis messaging, managing media engagement and the flow of information to internal and external audiences. Their work focuses on narrative and stakeholder trust rather than the technical resolution of the incident, and it is most effective when guided by a predefined crisis communication plan.
Legal and Compliance Functions
Legal teams are often involved in reviewing and approving crisis messaging, particularly where disclosure obligations arise from a security incident. They help ensure that public statements are consistent with the organization's legal position, given that accountability for disclosure decisions remains with the organization.
Virtual CISOs and Security Leaders
A virtual CISO may advise on how crisis communications integrate with the broader incident response program and governance structure, helping ensure that technical response and messaging are coordinated. This is an advisory and directional role; the vCISO generally does not draft, approve, or deliver crisis messaging, and does not assume the legal accountability that remains with the client organization and its officers.
Incident Response Teams
Technical responders handling containment, eradication, and recovery must coordinate with the communications function so that public messaging reflects an accurate understanding of the incident. They provide the factual basis for messaging but do not typically own the communications process itself, since crisis communications is a distinct discipline running parallel to technical response.

Inside Crisis Communications

Crisis Communications Plan
A documented set of procedures defining how an organization communicates internally and externally during a security incident or crisis. In many engagements, a virtual CISO advises on the governance and structure of this plan but does not typically execute operational incident response or serve as the organization's official spokesperson unless explicitly contracted.
Stakeholder Identification and Notification
The process of mapping who must be informed during a crisis, including executives, boards, employees, customers, regulators, and partners. A vCISO often helps define escalation paths and notification thresholds, while accountability for the final decision to notify usually remains with the client organization and its officers.
Regulatory and Legal Notification Obligations
Requirements to notify affected parties or authorities under frameworks and regulations such as GDPR, HIPAA, or applicable breach notification laws. A virtual CISO can support readiness and advise on where obligations may apply, but does not typically assume legal accountability for meeting them and generally coordinates with legal counsel who determines regulatory triggers.
Message Coordination and Approval Workflow
Defined roles for drafting, reviewing, and approving communications so that messaging remains consistent and legally reviewed. This often involves legal, communications, and executive functions rather than the security leader alone; a vCISO typically advises on accuracy of technical content rather than owning public messaging.
Internal Escalation and Decision Authority
The chain of command and predefined decision rights that govern when a communication is released and by whom. A vCISO advises and directs on how these structures should function, but organizational accountability for decisions usually remains with the client's officers.
Post-Incident Communication and Lessons Learned
Follow-up communications and internal reviews conducted after a crisis to inform stakeholders of outcomes and improvements. A vCISO often contributes to governance-level reviews and program improvement rather than performing hands-on operational remediation.

Common questions

Answers to the questions practitioners most commonly ask about Crisis Communications.

Is crisis communications the same as a virtual CISO's incident response duties?
No, and conflating the two is a common mistake. Crisis communications refers to the coordinated messaging to stakeholders, employees, customers, regulators, partners, and sometimes the public, during and after a disruptive security event. Incident response execution, such as containment, forensics, and remediation, is a separate operational function. A virtual CISO typically advises on and helps structure the communications strategy as part of governance and readiness, but the hands-on technical response and the actual drafting and issuing of external statements often fall to other roles, including legal counsel, communications or PR teams, and operational responders. A vCISO's involvement usually centers on strategy, escalation decisions, and ensuring communications align with the broader risk posture rather than performing the communications work directly.
Does engaging a virtual CISO for crisis communications planning mean they become accountable for what the organization says during a breach?
Generally no. A virtual CISO advises and directs, but legal and organizational accountability for public statements, regulatory notifications, and disclosure decisions typically remains with the client organization and its officers. The content and timing of breach notifications often involve legal counsel and executive leadership who hold that accountability. Unless a specific contract states otherwise, a vCISO's role is to help the organization prepare, structure, and rehearse crisis communications, not to assume liability for the messages issued. Buyers should not assume the engagement transfers regulatory or legal accountability to the advisor.
How does a virtual CISO help an organization prepare crisis communications before an incident occurs?
In many engagements, a virtual CISO supports readiness by helping define escalation paths, identifying which stakeholders need to be informed, and ensuring communications planning is integrated into the broader incident response and governance framework. This may include helping the organization pre-establish approval workflows, coordinate with legal and communications functions, and align messaging expectations with any applicable notification obligations. The value of this preparation typically depends on organizational maturity, stakeholder cooperation, and clearly defined scope.
What is typically out of scope for a virtual CISO regarding crisis communications?
A virtual CISO generally does not draft or issue press releases, act as a media spokesperson, manage public relations, or perform the operational tasks of an incident response team unless explicitly contracted. Legal drafting of regulatory notifications is usually handled by counsel. The vCISO's contribution is often advisory and coordinating, helping ensure communications decisions reflect sound risk management, rather than executing the communications function itself. Scope should be defined explicitly in the engagement agreement.
How should crisis communications planning connect with frameworks the organization already uses?
Crisis communications planning is often aligned with an organization's broader incident response and governance structure, which may reference frameworks such as NIST CSF or standards like ISO 27001. These frameworks address incident handling and communication as part of overall security program readiness. A virtual CISO can help map communications planning to relevant framework expectations and any applicable regulatory notification requirements, but supporting this readiness does not guarantee compliance or certification, which depend on organizational implementation and verification by appropriate parties.
What factors determine whether a virtual CISO's crisis communications support delivers value?
Value typically depends on organizational maturity, the degree of client cooperation, access to key stakeholders such as legal, executive leadership, and communications teams, and a clearly defined scope. Because a virtual CISO usually works part-time and often remotely, effectiveness improves when the organization has established internal ownership for executing communications and when the vCISO's advisory role is integrated early rather than only during an active crisis. Outcomes vary by provider and engagement structure.

Common misconceptions

A virtual CISO handles crisis communications execution, acting as the spokesperson and running incident response during a breach.
A vCISO typically provides strategy, governance, and executive-level guidance on crisis communications planning. Hands-on incident response execution and serving as the official spokesperson are generally out of scope unless explicitly contracted, and public messaging often sits with legal and communications functions.
Engaging a virtual CISO transfers legal and regulatory accountability for breach notifications to the vCISO or their firm.
Accountability for security and notification decisions usually remains with the client organization and its officers. A vCISO advises and directs and can support notification readiness, but does not assume liability or regulatory accountability unless a contract specifies it.
A crisis communications capability is purely a technical function owned by security.
Crisis communications is a governance and business risk function that spans legal, communications, executive leadership, and security. A vCISO contributes technical accuracy and program governance but relies on cross-functional cooperation, and its value depends on organizational maturity, defined scope, and stakeholder access.

Best practices

Define the vCISO's crisis communications scope explicitly in the engagement contract, clarifying whether responsibilities include advisory planning only or extend to spokesperson or execution roles.
Document escalation paths, notification thresholds, and decision authority in advance so that accountability remains clearly assigned to the client's officers during an incident.
Coordinate crisis messaging through a defined approval workflow that involves legal, communications, and executive stakeholders rather than security leadership alone.
Support regulatory notification readiness by mapping where obligations under frameworks such as GDPR or HIPAA may apply, working alongside legal counsel who determines regulatory triggers.
Ensure the vCISO has access to relevant stakeholders and decision-makers, since crisis communications value depends heavily on organizational cooperation and maturity.
Conduct post-incident reviews to capture lessons learned and improve the crisis communications plan, treating it as an ongoing governance function rather than a one-time deliverable.