Communication is the practice of keeping the right people informed, accurately and on time, throughout an incident. It spans internal stakeholders, external parties, legal counsel, and regulators, ensuring that each audience receives what it needs without spreading confusion, speculation, or premature claims.
Within the Response phase, communication is a parallel track that runs from the first confirmed incident through resolution. Technical response addresses the threat itself, but an incident is also an organizational event with obligations to employees, customers, partners, and authorities. Poor communication can compound harm, eroding trust or breaching notification duties, even when the technical response is sound.
In practice, communication involves briefing leadership and affected teams, coordinating with legal to understand disclosure obligations, and preparing clear messages for customers or the public when required. Many jurisdictions and contracts impose specific notification timelines for certain kinds of breaches, so legal and regulatory communication must be timely and precise. Internally, a single source of truth and defined spokespeople prevent mixed messages. Effective communication is planned in advance, with templates, contacts, and decision points ready, so that during an incident the organization informs rather than improvises.
References#
- NIST SP 800-61, Computer Security Incident Handling Guide
- CISA, Incident reporting guidance