What to Tell Customers After a Cyber Incident
Poor communication turns a manageable cyber incident into a reputational one. Say too much too soon and you retract it later; say nothing and rumour fills the silence. Getting the customer message right is one of the highest-stakes decisions of any incident, and it is far easier when you have thought about it in advance rather than drafting under pressure.
This guide covers what to tell customers after a cyber incident, when, and how. It is a companion to our full cyber incident response plan guide, and the free Cyber Incident Response Toolkit includes ready-to-adapt communication templates.
The three principles
Whatever the incident, the same principles hold: be timely, be accurate, and be transparent, while being careful not to speculate about cause or scale before you actually know. Customers forgive businesses that handle an incident honestly. They do not forgive being misled, or finding out from someone else. The aim is to tell people what they need to know to protect themselves, without guessing at things you cannot yet confirm.
Do you even need to tell customers?
Not every incident requires a customer message. Ask two questions. First, does the incident affect customers directly, for example their data, their service, or their money? Second, is there something they need to do, such as watch for fraud, reset a password, or use an alternative service? If the answer to both is no, a public statement may do more harm than good. If personal data was involved and there is a high risk to the people affected, you may have a legal duty to inform them, which is a different and stronger obligation. Our data breach versus cyber incident guide explains when that applies.
The holding statement
In the first hours, before you have the full picture, a short holding statement buys you time without overcommitting. It should confirm you are aware of an issue, that you are taking it seriously and investigating, what customers should do in the meantime if anything, and when they can expect an update. It should not guess at the cause, the scale, or who was responsible. For example: “We are aware of a technical issue affecting [service] and are investigating as a priority. We take the security of your information seriously and will provide an update by [time]. We are sorry for any inconvenience.”
The follow-up, once you know more
When you understand what happened, a fuller update can explain, in plain language, what occurred, what information or service was affected, what you have done about it, and what, if anything, customers should do. If people need to take a protective action, make it clear and easy. If the news is reassuring, say so plainly. Keep the tone calm and factual, not defensive or over-apologetic.
Who speaks, and through what channel
Only designated people speak publicly. Everyone else, however well-meaning, points enquiries to them. Decide this in advance, because during an incident is a bad time to discover three people are giving customers three different stories. Choose channels your customers actually use and can trust, and remember that if your own email is compromised, you may need an alternative way to reach people. A single, consistent source of updates beats scattered messages every time.
What to avoid
- Speculating about cause, scale or blame before you know.
- Promising things you cannot yet confirm, such as “no data was affected”, before you have checked.
- Going silent and letting rumour fill the gap.
- Technical jargon that leaves customers more worried, not less.
- Different people saying different things.
Want the templates ready before you need them?
Our free toolkit includes adaptable staff, customer and supplier communication templates, so you are editing a sensible starting point rather than writing from a blank page during a crisis. We can also help you build a simple incident communications plan.
Frequently asked questions
Be timely, accurate and transparent, without speculating about cause or scale before you know. Tell customers what they need to know to protect themselves, what you are doing about it, and when they will hear more. A short holding statement early is usually better than a detailed one you have to retract.
No. If the incident does not affect customers directly and there is nothing they need to do, a public statement may do more harm than good. However, if personal data was involved and there is a high risk to the people affected, you may have a legal duty to inform them, which is a separate and stronger obligation.
In the first hours, before you have the full picture, if customers are affected or need to act. It should confirm you are aware and investigating, say what customers should do in the meantime, and give a time for the next update, without guessing at the cause or scale.
Only named, designated people, agreed in advance. Everyone else routes enquiries to them. This keeps the message consistent and stops three people giving customers three different stories at the worst possible moment.
Related reading: the full Cyber Incident Response Plan guide, data breach versus cyber incident, and the free Cyber Incident Response Toolkit with communication templates.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


