A data breach is difficult enough. But when stakeholders believe an organization delayed disclosure, minimized the impact, or withheld material information, the communications response can become more damaging than the original intrusion.
Uber’s 2016 breach is still a useful warning. The company learned about the incident in November 2016 but did not disclose it for more than a year. The fallout quickly moved beyond cybersecurity and became a story about leadership, governance and trust. The lesson isn’t that organizations should rush out before they know the facts. It’s that silence needs to be intentional, short-lived and backed by a clear process for deciding what can responsibly be shared.
Breach notification rules are not one-size-fits-all. They can change based on the state, the industry, the type of information involved and the kind of organization affected — for example, whether it is a public company, healthcare provider, financial institution, government agency or private business. Public companies may also have separate federal securities-disclosure obligations once a cybersecurity incident is considered material.
In a low-trust environment, people will fill in the blanks if an organization looks unavailable or evasive. A strong first response explains what is known, says what is still being checked, names the steps being taken and tells people when they will hear more. This is the “radical context” approach we introduced in July: show people how you are working toward answers instead of simply asking them to wait.
Tips for readers:
- Pre-draft a breach holding statement that includes known facts, immediate protective actions, and a promised time for the next update.
- Establish a documented disclosure decision process involving security, legal, communications, and executive leadership—before an incident tests it.
