Stakeholder Communication: What to Say, When, and to Whom
Theory
Prerequisites
- CIR-K001: The PICERL Lifecycle
- CIR-K009: Recovery Planning
Why This Lesson Matters
The best technical IR response can be destroyed by bad communication. A panicked email that over-discloses before facts are confirmed. A legal notification sent too late. An executive briefing that used technical jargon nobody understood. Communication is not a soft skill in IR — it is an operational skill with legal, regulatory, and reputational consequences.
1. Audience Segmentation
Different people need different information at different levels of detail.
| Audience | What they need | What they do NOT need |
|---|---|---|
| Executive / Board | Business impact, cost, timeline to resolution, regulatory obligations | IOCs, log excerpts, technical methodology |
| Legal counsel | Full facts, privilege protection, notification triggers | Technical jargon; they want clean facts |
| Regulator / DPA | What happened, who is affected, what you are doing | Speculation or incomplete information |
| Affected users | What data may be compromised, what they should do | Technical details about the attack |
| Internal IT / engineering | Technical details, systems affected, action items | Regulatory language |
| Media (if applicable) | Short, factual statement only | Anything speculative |
2. The Communication Lifecycle
T+0 to T+1 hour: Internal Escalation
Do not communicate externally until you have enough facts to be accurate. First communication is always internal:
IR Lead → CISO / Security Manager
"We have a confirmed [P1/P2] incident. Affected systems: [list].
Initial access vector: [known/unknown]. Containment in progress.
Next update in 60 minutes."
Short, factual, honest about uncertainty. "Unknown" is acceptable at T+0.
T+1 to T+4 hours: Management Brief
Once you have initial scope:
To: CISO, CTO, Legal
Subject: Incident Update — IR-2026-0608-001
Current status: CONTAINMENT IN PROGRESS
What we know:
- Attacker gained access to WS-042 and SRV-001 via SSH brute force at ~14:30 UTC
- Finance database on SRV-001 may have been accessed (investigation ongoing)
- Both hosts are now isolated; attacker C2 is blocked at perimeter
What we do not know yet:
- Whether data was exfiltrated (investigating)
- Full scope of lateral movement
Regulatory trigger: Possible PIPEDA breach notification if PII was accessed
→ Legal review required within 24 hours
Next update: 2026-06-08 18:00 UTC
T+24 to T+72 hours: Regulatory Notification
Canada — PIPEDA / Law 25: - Notify the OPC within 72 hours of determining that a breach of security safeguards creates a real risk of significant harm - Notify affected individuals "as soon as feasible" after assessing the risk
EU — GDPR / NIS2: - Notify the supervisory authority within 72 hours of becoming aware of the breach - Notify individuals without undue delay if high risk to their rights and freedoms
Key principle: Notify your legal team immediately when you suspect PII may have been accessed. They determine notification obligations — not the technical team.
3. Regulatory Notification Timing
"72 hours" does not mean you have 72 hours to start investigating.
It means you have 72 hours from the moment you KNOW a notifiable breach occurred.
The clock starts at your Identification phase conclusion:
"Confirmed: attacker accessed the PII database."
If you delay investigation → you are extending uncertainty, not resetting the clock.
4. What NOT to Say
These communication failures are common and damaging:
| What was said | Why it was wrong |
|---|---|
| "We have been totally hacked" | Overstates (and panics) before scope is known |
| "We think we are fine" | Underplays confirmed compromise |
| "No data was taken" | Stated before exfiltration investigation was complete |
| "This was caused by [vendor X]" | Assigns blame before root cause is confirmed |
| "Our security is bulletproof now" | Creates unrealistic expectations |
| [Technical details to a journalist] | Provides operational playbook to other attackers |
The golden rule: Say what you know, acknowledge what you do not, and do not speculate.
5. The Exec Briefing Template
A 5-minute executive brief follows this structure:
1. What happened (30 seconds)
"An external attacker gained access to two of our servers on June 8th,
beginning at approximately 2:30 PM. We detected it within one hour."
2. Current status (30 seconds)
"The attacker's access has been cut. Both affected systems are offline
and being investigated."
3. Impact (1 minute)
"The finance database was on one of the affected servers. We do not yet
know if data was taken — we are actively investigating this."
4. What we are doing (1 minute)
"We have isolated the affected systems, blocked the attacker's
communication channel, and engaged our forensics team. Our legal
team is assessing notification obligations."
5. What we need (1 minute)
"We need approval to bring in external IR support. Estimated cost:
$X. We also need the executive team on a call with legal at 5 PM."
No jargon. No IOCs. No log excerpts. Business impact and decisions needed.
6. Common Mistakes
Mistake 1: Communicating facts that later change. Once you say "no data was taken" in a notification, you cannot unsay it. Be conservative — say "investigation ongoing" until you are certain.
Mistake 2: Not involving legal before external communication. Legal privilege may protect investigation communications. Once you communicate outside privilege, that protection is gone. Loop legal in before any external disclosure.
Mistake 3: Over-communicating technical details to non-technical stakeholders. An exec who does not understand what "Pass-the-Hash" is will be confused, not informed. Translate everything to business language.
7. Practice Exercises
-
Write a 3-sentence executive update at T+2 hours for the following scenario: "We have confirmed compromise on 2 hosts. A database containing 8,000 customer records was accessible from the compromised server. We do not yet know if data was exfiltrated."
-
Under PIPEDA, when does the 72-hour notification clock start? Does it start when the incident is detected, or when it is confirmed as a notifiable breach?
-
A journalist calls asking about "the cyberattack we heard about." Write the one-paragraph holding statement your communications team should use.
8. Lab
Assessment mode: quiz
6 scenario questions on: - Which audience receives which type of communication - Whether a described statement is appropriate or should be corrected - Regulatory notification trigger identification - Executive briefing structure
9. Framework Alignment
| Framework | Role | Competency | Confidence |
|---|---|---|---|
| CCSSF-CIR | Cyber Incident Responder | Stakeholder communication and regulatory notification | High |
| CCSSF-ISSO | ISSO / Generalist | Governance, legal obligations, board reporting | High |
| NICE 2.2.0 | Incident Responder | K0270 — Reporting requirements for incident notification | High |
10. Further Reading
- OPC PIPEDA Breach Reporting — https://www.priv.gc.ca/en/privacy-topics/privacy-breaches/respond-to-a-privacy-breach-at-your-business/gd_pb_201810/
- ENISA Incident Reporting Guide — Covers NIS2 notification requirements with templates
- SANS Crisis Communication — Communication-focused IR guidance from the SANS incident handler community
Learning Objectives
["Identify the appropriate audience for three types of incident communication (executive brief, legal notification, affected user notice) and explain what each should and should not contain", "Write a three-sentence executive update that accurately represents a described incident status without speculation, technical jargon, or premature conclusions", "Identify the PIPEDA breach notification trigger and explain the difference between the detection date and the notification clock start date"]
Lesson Outline
Prerequisites → Why this matters → Audience segmentation (table) → Communication lifecycle (T+0 internal, T+4 management, T+72 regulatory) → Regulatory timing (PIPEDA/GDPR clock) → What NOT to say → Exec briefing 5-part template → Common mistakes → Practice exercises → Quiz lab → Framework alignment → Further reading