Crisis Communications
Crisis communications is how an organization collects, manages, and shares information when it faces a serious event that threatens its reputation or operations, such as a data breach or security incident. The goal is to respond quickly and openly with the media, employees, and the public in order to protect the organization's brand and maintain trust. It focuses on messaging and information flow rather than on the technical work of resolving the underlying incident.
Crisis communications is the process of collecting, processing, and disseminating information relevant to addressing a crisis that poses a threat to an organization's reputation or operations. In practice it encompasses stakeholder messaging, media engagement, and coordinated internal and external communication executed under time pressure, and it is typically governed by a predefined crisis communication plan and strategy. Within a security context it functions as a distinct discipline that runs parallel to technical incident response: it manages narrative, stakeholder trust, and disclosure obligations rather than performing containment, eradication, or recovery. A virtual CISO may advise on how communications integrate with the broader incident response program and governance structure, but the drafting, approval, and delivery of crisis messaging is commonly led by communications, legal, and executive functions, with legal and organizational accountability remaining with the client organization and its officers. Effectiveness depends heavily on advance planning, defined roles, stakeholder access, and organizational maturity, and outcomes may vary by organization; it should not be conflated with the technical remediation of the incident itself.
Why it matters
When a security incident such as a data breach becomes public, the way an organization communicates can shape stakeholder trust as much as the technical response itself. Crisis communications exists to collect, process, and disseminate information that is important to addressing the crisis, with the primary goal of protecting the organization's reputation while engaging with the media, employees, and the public in an open and timely manner. Poorly managed messaging can compound the damage of an incident, while a coordinated and transparent response can help preserve trust during a period of intense scrutiny.
It matters for security leaders because crisis communications is a distinct discipline that runs parallel to technical incident response rather than a substitute for it. Containment, eradication, and recovery address the underlying incident, but they do not manage the narrative, stakeholder relationships, or disclosure obligations that surface simultaneously. Organizations that treat these as the same function often find that technical remediation is underway while messaging lags, contradicts itself, or fails to reach key audiences under time pressure.
A common mistake is assuming that a virtual CISO or an incident response team will handle communications by default. In many organizations, the drafting, approval, and delivery of crisis messaging is led by communications, legal, and executive functions, with legal and organizational accountability remaining with the organization and its officers. Effectiveness typically depends on advance planning, defined roles, and stakeholder access, so organizations that wait until a crisis is underway to determine who speaks and what is said are often disadvantaged.
Who it's relevant to
Inside Crisis Communications
Common questions
Answers to the questions practitioners most commonly ask about Crisis Communications.