Explaining What’s Happened in a Cyberattack Is Challenging

It seems that everyone has a view on whether retailers M&S and the Co-op have communicated well during the recent cyberattacks that have disrupted their operations and attracted intense media coverage. Computer Weekly invited me to share my perspective, which they published as an op-ed on 1 May (link here). We’ve captured the key points for techUK’s members and readers here.
Even for those of us who spend our careers helping companies manage the impact on their reputation of cyber incidents, it’s hard to judge from the outside how well the response has been handled. It’s dependent on too many invisible factors. But, having worked on hundreds of crises, in UK Government and the private sector, I’d make five points.
Firstly, no crisis response is perfect. Even the best-drilled teams are making decisions with imperfect information and under stress. What matters isn’t the mistakes, but how you adjust as you make them.
Secondly, tempo, tone and voice are all pivotal in a crisis. You may not have all the details, and in a cyber incident it’s crucial to provide information at a pace that recognises that “the facts” often change. But you should find ways to engage high-priority audiences. And the person delivering the message matters: M&S’s communications have been proactive, with a well-judged tone, shared directly from its leadership to customers, via channels like Instagram, and signed by their CEO, demonstrating ownership of the issue from the very top.
Thirdly, communications and operations must be integrated, so one can inform the other in real-time. One challenge in all cyber incidents – the M&S and Co-op incidents are no exception – is aligning messaging with the operational picture and potential evolution of the incident.
Fourthly, the crisis landscape is constantly shifting. One striking feature in recent cyber incidents is that threat actors are increasingly ready to use media engagement as a way to strengthen their hand in the ransom negotiations. We’re also seeing attackers contact a wider range of stakeholders, from employees to clients, to further pressure victims.
Lastly, communicating about cyber incidents differs in important ways from other crises. As I wrote in the Computer Weekly op-ed:
“Overall, the most critical thing is to align the communications with the operational response and manage people’s expectations accordingly, both internally and externally. Common mistakes we see in our work – and mistakes that we try to help companies avoid – include:
Saying too much too soon. It never ceases to amaze me – even after having worked on dozens of incidents – how often forensic evidence evolves over time, fundamentally changing the understanding of the incident. This can be hard to handle from a communications perspective, particularly if you’ve told your customers that their data wasn’t stolen, only for them to later discover that it was. Being an unreliable narrator is one of the fastest ways to lose trust.
Saying too little for too long. Not knowing all the facts doesn’t mean you shouldn’t provide advice, both internally and externally, on what to do if, for example, operations have been disrupted.
Getting the tone wrong. Companies are often keen to praise themselves for the speed and effectiveness of their response, or describe themselves as victims. If people’s sensitive data has been lost, they might not see you as the victim, but as being to blame.
Forgetting that threat actors read the news, too. Communications around a cyber incident are complex, with multiple audiences to consider. One of those audiences is the threat actor, especially when they’re trying to use media as part of their ransom negotiation.
“We’ve seen plenty of incidents handled well, with customers, suppliers, investors, regulators and staff all updated regularly and honestly, so people understood that the company was doing all it could to mitigate the impact on them. However, we should all – whether we’re M&S or a much smaller company destabilised by a cyber incident – keep learning how best to handle communications around it.”
Hopefully, your next crisis is a long way off. Or it might be right round the corner. Either way, it’s worth paying attention to how other companies are handling their own crises, including cyber incidents, and making sure that you’re as ready as possible. Good luck!
Mikey Hoare is a crisis specialist at communications advisory firm Kekst CNC



