Cyber Security and Crisis Communications: What Every Organisation Needs to Know

When most people think about cyber security, they picture IT teams hunched over servers, implementing firewalls and running virus scans. What they don’t picture is the communications professional sitting across the table in the crisis meeting – but perhaps they should.

At LLPR, we’ve seen first-hand how cyber incidents have evolved from technical IT problems into full-blown reputational crises. With cyber attacks now occurring every 39 seconds globally, it’s not a question of if your organisation will face a cyber incident, but when – and how well you’ll communicate when it happens.

image of a man experiencing a cyber attack

The communications challenge of cyber incidents

Cyber attacks create a uniquely difficult communications environment. You’re racing against attackers who deliberately seek media coverage to pressure you into paying ransoms. You need to notify affected individuals within strict regulatory timeframes (72 hours to report to the ICO), yet you’re communicating with incomplete information while systems are down and investigations are ongoing.

Add to this the complexity of managing multiple audiences simultaneously – employees, customers, regulators, media, suppliers – each requiring different messages through potentially compromised communication channels, and you have one of the most challenging crisis scenarios your organisation could face.

 

The three threats you need to understand

 

  1. Ransomware: It’s not just encryption anymore

Gone are the days when ransomware simply locked your systems. Today’s attacks involve “double” or even “triple” extortion: systems are encrypted, data is stolen, and attackers threaten to contact your customers directly or target your supply chain partners unless payment is made.

For organisations holding customer financial data, such as hotels, travel companies, and charities with donor information, the communication implications are immediate and severe. Regulatory notification requirements kick in, customer trust hangs in the balance, and media interest intensifies rapidly.

  1. Social engineering: Your people are the target

Here’s the uncomfortable truth: 25% of people still fall for phishing attacks. But modern phishing looks nothing like the obviously fake emails of the past. AI now generates perfectly written, highly personalised messages that reference real projects, colleagues, and recent activities scraped from social media.

Your team members, particularly those in customer-facing or communications roles, can be particularly vulnerable without appropriate training in cyber attack awareness. They receive unsolicited emails daily, are expected to respond quickly, and have publicly available contact details. In short, they’re relationship builders who are naturally trusting and willing to engage.

This makes them attractive targets and potential entry points for attackers into your organisation.

 

  1. Supply chain compromise: The weakness you didn’t know you had

Attackers have realised that targeting software platforms used by thousands of organisations creates a massive attack surface. One breach of a widely-used booking system, payment processor, or cloud service could expose your organisation and your customers.

The communication challenge? You’re managing an incident you didn’t cause, but you’re still responsible for maintaining trust with affected stakeholders.

 

Why AI changes everything

Artificial Intelligence hasn’t just made attacks a bit more sophisticated; it’s fundamentally changed what’s possible. AI-powered attacks now include:

  • Perfect phishing emails with flawless grammar, personalised content, and contextually appropriate timing
  • Deepfake videos and voice cloning that can impersonate your executives giving instructions
  • Automated malware that evolves to evade detection

By the end of 2026, experts predict AI may overtake human error as the primary cause of successful cyber attacks. The sophistication level has jumped dramatically, while the barrier to entry has plummeted.

 

The critical role of communications in your cyber response

This is why your communications team is essential to your cyber security strategy:

  1. They translate technical to human. IT teams speak in systems and code. Communications professionals translate that into clear, empathetic language that your affected customers, employees, and stakeholders can understand and act upon.
  2. They balance competing pressures. Legal counsel wants delay for certainty. IT needs investigation time. Leadership wants the problem to disappear. Your communications team navigates these tensions to determine the right strategy that protects both compliance and reputation.
  3. They manage complex stakeholder landscapes. Different audiences need different information at different times through different channels. For example, a pension scheme member requires different communication than a current employee or international customer.
  4. They understand that reputation recovery defines long-term survival. Technical recovery is important, but how your organisation communicates during crisis defines your character and determines whether customers, clients, and partners stay with you afterwards.

 

What good preparation looks like

The organisations that manage cyber incidents most effectively are those that prepared before the crisis hit:

  • Pre-approved communication templates for different scenarios and stakeholder groups
  • Micro sites (dark sites) – standalone websites hosted separately from main infrastructure that can be activated when primary systems are compromised
  • Translated materials ready for international audiences
  • Established relationships with specialist support providers (many cyber insurance policies include crisis communications support)
  • Practiced protocols through simulation exercises that test not just IT response but communication workflows

Every hour your organisation invests in preparation saves days in crisis response – and potentially protects years of reputation building.

 

The human cost of poor communication

At a recent CIPR Crisis Communications Network event, an ICO specialist shared a personal story that perfectly illustrates why communication matters. Their family had a Christmas tradition of ice skating annually. The ice rink experienced a data breach but never notified customers.

The family was left with financial uncertainty, not knowing if credit card details were compromised. Trust in the organisation completely eroded. They no longer go ice skating there – a tradition and customer relationship destroyed, not by the breach itself, but by the silence that followed.

Poor communication doesn’t just risk regulatory fines. It destroys customer relationships, creates genuine distress, and causes long-term reputational damage that far outlasts the incident itself.

 

The attacker’s media strategy

Understanding how threat actors use media helps you counter their tactics. Attackers deliberately seek publicity because it creates urgency, demonstrates they really have your data, increases the likelihood of ransom payment, and makes negotiations public – all of which makes it harder for your organisation to control the narrative.

They publish data samples on dark web forums, tip off journalists directly, create countdown timers, and contact your customers or employees. Their goal is simple: get ahead of your communication plan and force you into reactive mode.

This is why proactive, transparent communication – even when information is incomplete – is essential. It’s better to acknowledge an ongoing investigation than allow attackers or media speculation to define the story.

 

Where to start

If your organisation hasn’t considered the communications dimension of cyber security, start by asking these questions:

  • Do we have pre-approved communication frameworks for a data breach scenario?
  • Have we mapped all stakeholder groups who would need notification?
  • Do we have backup communication channels if primary systems are compromised?
  • Have our spokespeople been trained for cyber incident media response?
  • Do we understand our cyber insurance coverage, including communications support?
  • Have we practiced our response through simulation exercises?

At LLPR, we work with clients across hospitality, travel, charity, and family business sectors – all areas which are increasingly targeted by cyber criminals. We help organisations prepare communication strategies before incidents occur, and provide expert counsel when crisis strikes.

Because in today’s threat landscape, cyber security isn’t just an IT issue: it’s a communications imperative.

Crisis Hotline 01202 701828 / Option 1