Join CIPR
team meeting
iStock / Pixelfit
PUBLIC RELATIONS
Friday 9th October 2026

When you can’t control the story: transparency in a cyber crisis

Transparency is the strongest defence when organisations lose control of the story during a cyber crisis.

There is a moment in every serious cyber incident that communications teams rarely talk about. It is the moment you realise the story is already being written elsewhere, and the author does not have your best interests in mind.  

Imagine that someone has posted a countdown on a dark web leak site. A researcher on the other side of the world is narrating your outage to 15,000 followers. Your own staff are comparing notes in a group chat that no policy reaches. Somewhere in a “war room”, a comms lead is still waiting for legal to bless the first sentence of a holding statement that the internet decided it no longer needed 20 minutes ago. 

That moment is the whole problem in miniature. The technical detail of a cyber incident is genuinely hard, but it is not the hard part for communications. The hard part is the oldest one in the business: holding on to trust while the organisation is under pressure and the ground is moving beneath it. 

What has changed is not the challenge. It is the physics of the environment in which the challenge now plays out, one where information travels instantly and arrives often without context. Are you ready for this? 

In that environment, transparency has stopped being a matter of tone. It is the only strategy that survives contact with reality. 

The first to know 

In a cyber incident, the victim is rarely the first party to understand what has happened to them. Threat actors publish stolen data on public leak sites, often before an organisation has finished confirming the intrusion internally. 

Those claims are then indexed and made searchable by public trackers such as ransomware.live — an open, continuously updated register that lists ransomware victims and the data their attackers say they hold, scraped straight from the criminal leak sites themselves.

It surfaces a named victim within hours, sometimes before that organisation has confirmed the breach to itself. Go and look, because your customers, your regulators and your competitors already have. 

Security researchers reverse-engineer the anomaly while your IT team is still scoping it. Customers notice the outage before anyone has named a cause. Employees form their own conclusions in channels you cannot see. 

This is why “hold until we know everything” has quietly become the most dangerous instinct in the room. It sounds prudent. It feels defensible. But by the time the flawless statement is signed off, the narrative has already set elsewhere, and every word you eventually publish is now read as a correction rather than a lead. 

The organisation has to operate as though it is one voice among many. That is not a failure of preparation. It is the new baseline. 

Silence is not neutral 

When an organisation says nothing, people do not wait politely. They fill the gap, and the material they fill it with moves inexorably towards the worst case. Even well-meant silence can and will be misinterpreted as guilt.

Equifax is the case study that refuses to age. In 2017, attackers moved through its systems for seventy-six days before anyone noticed. The company knew internally by late July and did not tell the public until 7 September; roughly six weeks of chosen silence, justified at the time as the responsible need to establish scope. 

During that window, three senior executives sold close to $1.8 million in stock. When disclosure finally came, the consumer site set up to let 147 million people check their exposure was hosted off Equifax’s own domain, carried a flawed security implementation, and reportedly returned near-random results. 

The bill ran past $1bn once settlements, litigation and remediation were counted. The CEO, CIO and CSO all left. 

None of that was the breach. The breach was a missed patch (software maintenance procedure). Everything expensive that followed was a communications and accountability failure wearing a 10 phrases that should (probably) never appear in your crisis communications costume. 

The lesson is not that Equifax was careless with a server. It is that the silence became the crisis. 

Transparency is the antidote, but it is worth being precise about what it means. It does not mean releasing every technical detail the moment you have it. It means refusing to leave a vacuum, because misinformation will fill the void. 

Honesty is credibility, especially when the news is bad 

Audiences are more cyber-literate than most organisations give them credit for, even when they cannot articulate it. They already know breaches happen, systems fail, and capable attackers are patient and everywhere. 

What they will not forgive is being managed. Vague language, minimisation, the passive voice deployed to smother an admission – these are the tells they now read instantly, and they cost you more than the bad news ever would. 

Barri-Jon Graham is the co-founder of ArcaSecure UK, which is a cyber-security and governance consultancy. He has over 20 years’ experience in security and intelligence and has led on cyber strategy and operational resilience initiatives across public and private sectors, including critical national infrastructure. Barri-Jon’s blog was first published by the CIPR Crisis Comms Network. 

Further reading

Crisis comms: Lessons learned from the British Library cyber-attack

A view from the coalface of one of the biggest cyber-attacks to date

10 phrases that should (probably) never appear in your crisis communications