During a cyberattack, attention naturally turns to the technical side: isolating, analysing, restoring. But the company does not only lose files. Hour after hour, it loses the trust of people who do not understand what is happening.

A customer whose order does not arrive, a supplier who no longer gets a reply, an employee who does not know what to say on the phone: each of them makes up an explanation. And the explanation people invent is almost always worse than reality.

Why is silence the worst option?

The case for silence seems reasonable in the moment. You do not yet know what happened, you are afraid of making things worse, you would rather wait until things are clearer. The problem is that while you wait, others are already watching.

Your website is down. Your e-mails go unanswered. Deliveries are delayed, invoices are not sent, the phone rings unanswered. Your customers do not discover the incident when you announce it: they have already noticed, and they are simply trying to understand.

Silence therefore protects nothing. It just hands the story over to someone else: a customer who tells another customer, a competitor, an employee who confides in someone, sometimes even a message from the attacker themself. You lose the one thing you truly still control, the version of the facts.

What damages trust is not the attack

Customers know that companies get attacked. What they forgive poorly is finding out from someone else, or receiving reassuring information that is contradicted three days later. Credibility does not depend on how severe the incident is, but on how reliable what you say turns out to be.

The real dilemma: too soon or too late

The dilemma is real, and it should not be underestimated. Communicating early means risking stating things that turn out to be false, because at the start of an incident you know almost nothing. Communicating late means letting the void take hold and losing control of the narrative.

The way out of this dilemma comes down to a simple distinction. Separate what you know from what you assume, and communicate only on the former.

You know that your system is unavailable. You know, concretely, what no longer works for the person you are talking to. You know that you have brought in a service provider and launched an investigation. These elements are established, they will not be contradicted tomorrow, you can say them immediately.

On the other hand, you do not yet know how the attacker got in, nor which data was viewed or copied, nor when everything will be restored. These three questions are precisely the ones you will be asked, and they are the ones you should not get ahead of. “We do not know yet, we will let you know as soon as it is established” is a professional answer, not an admission of weakness.

A practical rule follows from all this: a short, reliable message every few hours is better than a complete but risky message after three days. The rhythm reassures just as much as the content.

Who should be told first? Your staff

This is the most common mistake, and the easiest one to avoid. A fine message gets drafted for customers, while everyone forgets that the people who will actually carry it are the ones answering the phone and the front desk.

An employee with no information does not stay quiet. They improvise, or they go silent awkwardly, which is even worse: an embarrassed “I can’t tell you anything” suggests that something serious is being hidden.

So inform the team first, and give them three things: what is happening, in a few sentences, what they are allowed to tell a customer who calls, and the name of the person to forward questions to that they cannot answer. Also specify what they must not do, in particular posting anything on social media or in professional discussion groups.

This is also the moment to give them the immediate technical instructions, the ones detailed in our article on the first 24 hours of a cyberattack.

What should you tell a customer, and in what order?

A good crisis message is short and answers four questions, always in this order, plus a fifth one that is often the most useful.

What the customer wants to knowWhat you write
What happened?One factual sentence, without jargon and without technical detail
What does this change for me?What is unavailable, what is delayed, what still works
What are you doing?The measures underway, in simple terms
When will I hear from you again?A date or time for the next update, one you can keep
Should I be wary of anything?A warning about fraudulent messages sent in your name

This last line deserves a closer look. When a business mailbox is compromised, attackers use it to write to your customers from your own message threads: a fake invoice, a change of bank details, an urgent request. The message looks legitimate because it almost is. Warning your customers and reminding them to verify any change of details by phone, on a number they already know, prevents concrete financial losses. This mechanism is described in our article on business e-mail compromise.

Which mistakes cost the most?

Three reflexes come up constantly, and all three backfire on the company.

Downplaying it. “A small technical issue”, “nothing serious”: if the real scale later comes to light, every reassuring word becomes proof of bad faith, even though in most cases it was only a wish not to worry people.

Promising a date you cannot keep. Announcing a return to normal for the next day when no one can guarantee it condemns you to disappoint a second time. Give instead a time for the next update, which you control, rather than a time for full recovery, which you do not.

Communicating through a compromised channel. This is the most subtle and the most dangerous mistake.

If your e-mail is hacked, the attacker reads your crisis team's discussions

Coordinating the response through the company's e-mail while an intruder has access to it means handing them your strategy, your timelines and your weak points, in real time. They then know exactly when to escalate the pressure and who to write to while impersonating you. As long as the system has not been declared clean, crisis management happens outside the system.

This requires having prepared backup channels in advance: the list of the crisis team’s personal phone numbers, on paper or outside the company network, a messaging group on an independent service, and the direct contact details of your IT provider, your insurer and your lawyer. This list is useless while nothing is happening, and irreplaceable the day you no longer have access to your directory. The full list of contacts is in who to contact after a cyberattack.

Informing your customers to preserve the relationship, and informing the people concerned because the law requires it, are not the same thing. The first exercise is commercial, the second is legal, and fulfilling one does not automatically fulfil the other.

As a general rule, the data protection act sets out two levels. Notification to the Federal Data Protection and Information Commissioner is only due in case of a high risk to the personality or fundamental rights of the people concerned, and it must be made as soon as possible. Contrary to a common belief, Swiss law sets no fixed deadline: the 72 hours come from the European regulation, not from Swiss law. Informing the people concerned, in turn, is required when this is necessary for their protection, or when the Commissioner requires it.

A reassuring commercial message therefore does not necessarily fulfil the legal duty, which requires precise details about the data affected and the measures to be taken. Conversely, a legal notice tells a customer nothing about what they expect on a day-to-day basis. The details of the procedure are covered in reporting a data security breach and in your legal obligations after a cyberattack.

A message template to prepare now

The best time to write this message is today, with a clear head. On the day of the incident, all that is left to do is fill in the blanks.

Template for a first message to customers

Dear Sir or Madam,
Our company is currently affected by an IT incident. Our teams are working with a specialist provider to resolve it.
Concretely for you: [what is unavailable or delayed]. [What still works normally] remains accessible.
A point of caution: as a precaution, be wary of any message received in our name, in particular regarding an invoice or a change of bank details. We never change our details by e-mail. If in doubt, call us on [number].
Next update: [day and time].
You can still reach us on [number], and we thank you for your understanding.

This template comes in three short versions: one for customers, one for suppliers and partners, one for staff. Keep them together with your backup numbers, outside the company network, and review them once a year.

What you can prepare on your own, and what needs outside input

Everything above can be done perfectly well in-house, with no particular budget: listing backup channels, designating a spokesperson, drafting the templates, letting the team know they will be informed first. An SME that has done this is already well above average, and it will gain several precious hours.

On the day of the incident, however, the exercise changes in nature. You have to decide what to say and what to withhold while the facts are uncertain, the technical analysis is not finished, the company’s legal liability and sometimes that of its owner are at stake, and a poorly calibrated sentence can complicate both the customer relationship and the insurance file just as much. This live judgement call cannot be improvised: this is the moment when outside input, used to these situations and able to bring technical analysis and legal duties into dialogue, genuinely changes the outcome.

In other words, preparing your crisis communication is an essential foundation, but it does not replace support at the moment when decisions have to be made. To gauge your overall level of preparedness, the cyber check-up covers the essential points in a few minutes, and the other crisis reflexes are gathered in the Responding to an attack pillar.