A cyber attack is a communications event before it is a technical one: forensics take weeks, but the public narrative forms in hours. U.S. public companies must file an SEC Form 8-K within four business days of deciding an incident is material, and the UK GDPR requires notifying the ICO within 72 hours of becoming aware of a notifiable breach. This playbook covers the first 72 hours of communications.
What is cybersecurity public relations?
Cybersecurity public relations is the practice of managing what customers, reporters, regulators and employees hear about a cyber incident or a security failure. This page covers the crisis side of the discipline: the first 72 hours after a breach, when communications has to work around legal deadlines and a news cycle that moves in hours. The sections below set out who speaks, what each statement says and which audiences need which material.
Which clocks start when a breach is discovered?
Three clocks start at once: a securities disclosure clock, a data protection clock, and the news cycle. The first two are legal deadlines, so communications must be built around them. This table is general information, not legal advice, and counsel should confirm which obligations apply to a specific company.
| Clock | Who it applies to | Deadline |
|---|---|---|
| SEC Form 8-K, Item 1.05 | U.S. public companies | Generally four business days after the company determines an incident is material. The SEC's 2023 rule release allows delay only if the U.S. Attorney General finds a substantial risk to national security or public safety. |
| UK GDPR breach notification | Organizations that control personal data under UK law | Without undue delay and, where feasible, within 72 hours of becoming aware of a notifiable breach, according to the ICO's guidance. |
| The news cycle | Every company | Hours. Reporters and customers are asking before the facts are known. |
Why does breach speed matter for the bottom line?
Breach costs are high enough that a slow or confused response compounds an already expensive event. IBM's 2025 Cost of a Data Breach Report put the average U.S. breach at $10.22 million and the global average at $4.44 million, as CyberScoop reported. IBM also found it took organizations an average of 241 days to identify and contain a breach, and its security leader said faster detection is one of the most effective ways to reduce costs.
Communications is one part of that cost. The forensics take weeks. The narrative takes hours. Whoever wins the first 72 hours defines the story for everyone who reads about it later: customers, regulators, reporters, plaintiffs' lawyers, and the board.
The firms that get breach response right treat it as a corporate reputation event with a technical root cause, not a technical event with a PR problem attached. That reordering is the whole game.
Hour zero: who owns the room?
One incident commander owns the room at hour zero, with one spokesperson, one approved holding statement, and one channel plan. Legal wants to say nothing. IT wants to say nothing until they know everything. Sales wants a script. The CEO wants an answer. Communications has to walk into that room and get a decision inside two hours, because the reporters and the customers are already asking.
If four departments are each drafting language, four departments will each leak language.
What goes in the holding statement during hours 0 to 24?
The holding statement is a short, humane, factual acknowledgment, not a press release. It says that something happened, that the company is taking it seriously, that it is working with law enforcement and outside experts, and that it will update on a specific cadence. It includes no speculation on scope and no numbers the company cannot defend by lunchtime.
Target shows why. In December 2013 it said about 40 million credit and debit cards may have been affected. On January 10, 2014, it said personal information had been stolen from as many as 70 million customers, according to the Associated Press. Target said the second figure was not a new breach but came from its ongoing investigation. Each new number restarted the story. Fewer numbers, held longer, would likely have ended the news cycle sooner. The Target case study covers the rest.
What goes in the customer letter during hours 24 to 48?
The customer letter is the most-read document in a breach, so it must be written for the customer at the kitchen table, not the compliance reviewer in a conference room. It gets forwarded, screenshotted, and read out on cable. It should say in plain English what was taken, what was not, and what the company is doing about it, including any free credit monitoring. A letter that reads as if a lawyer wrote it loses ground the moment it reaches an inbox.
Who needs what during hours 48 to 72?
By day three, three groups of reporters are working the story: the trades, the business desks, and the consumer press. Each needs different material and each works on a different clock. Feeding them from the same one-pager guarantees a bad quote in at least one venue.
| Audience | What they get | Format |
|---|---|---|
| Trade press | The technical response | Background briefing |
| Business desks | Governance and remediation | On-record executive interview |
| Consumer press | What customers should do now | Plain-language FAQ |
The three groups get different reporters and different substance, with one message spine.
What is cybersecurity media relations?
Cybersecurity media relations is how a company deals with the reporters who cover a breach: the trade press, the business desks and the consumer press. The table above sets out what each group gets. The trade press gets a background briefing on the technical response, the business desks get an on-record executive interview on governance and remediation, and the consumer press gets a plain-language FAQ. Name one spokesperson and state an update cadence, so that reporters know when the next information is coming and do not fill the gap with unauthorized sources.
What four failures repeat in breach communications?
Four failures repeat across breaches: silence, blame, legalese, and no cadence.
1. Silence. When a company goes quiet, reporters fill the space with sources who are not authorized and not accurate.
2. Blame. Pointing outward before the internal picture is clear turns a breach into a longer story. Attribution belongs to law enforcement and the forensics firm, not the podium.
3. Legalese. The audience is frightened customers, not a court. Tone matters as much as content.
4. No cadence. Numbers that arrive in pieces, as Target's did, keep the story open. A stated cadence, even "we will update every Tuesday and Friday until this is resolved," is worth more than any single statement.
What does the board need to see?
Directors need a communications posture, not a communications plan, and they need it in one page. The page answers three questions. Who is our spokesperson, and are they trained? What is our escalation ladder for the first six hours? Who is our outside PR counsel, and are they on retainer or on speed dial?
If any answer is "we will figure it out," the company is not ready. Breach response is a muscle built before the incident, and the crisis communication plan guide is the place to start building it.
What should a company do before an attack happens?
A company should settle three things before an attack: who speaks, who decides, and what the first statement says. A cyber incident tests the technology, the leadership, and the communications at once. Companies rarely control the first when it counts. They can control the second and third by rehearsing and resourcing breach communications as a boardroom capability. A breach is remembered for how it was handled, not for how it happened.
Which related cases show breach communications in practice?
Four cases on this site show breach and disclosure communications in practice. The Target data breach shows how numbers that arrive in pieces keep a story open. The Capital One 2019 breach shows an apology that came in the same announcement as the facts. The OpenAI apology in Australia shows how a late disclosure shapes the apology that follows. The British Airways IT failure covers an outage response. The full set sits in the crisis communications library, and the doctrine is in the crisis communications guide.
Originally published May 2016. Updated October 2026.
