---
title: Communication is key when responding to a cybersecurity incident
description: communication responding to a cybersecurity incident
image: https://businessinsights.bitdefender.com/hubfs/clock.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Privacy and Data Protection](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)

 By [**Graham Cluley**](https://businessinsights.bitdefender.com/author/graham-cluley) / Jan 26, 2018

# Communication is key when responding to a cybersecurity incident

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/communication-responding-cybersecurity-incident&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/communication-responding-cybersecurity-incident&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/communication-responding-cybersecurity-incident&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/communication-responding-cybersecurity-incident&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/communication-responding-cybersecurity-incident&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/communication-responding-cybersecurity-incident&utm_medium=social&utm_source=facebook)

There’s an old joke that goes something like this: “To err is human, but to really screw things up you’ll need a computer.”

 

Of course it’s funny, but as we all know computers just do what they’re told (or programmed) to do.  They’ll do it to the letter, time and time again, without thinking.

And if someone hasn’t had the foresight to predict every situation that a computer program may encounter (unexpected end of file, divide by zero, too much data to fit into the space allotted for it) then things might go wrong.

In short, it’s probably fairer to say:

“To err is human, but to really screw up you’ll need a human to program a computer.”

The point is that even the most carefully thought through systems and processes might contain bugs and unexpected wrinkles which only come to light when something disastrous happens.

Earlier this month something bad happened in Hawaii.  A mistake by a human operator saw [a computer system send a terrifying message to residents of Hawaii](https://www.grahamcluley.com/hawaiis-ballistic-missile-false-alarm-user-interface-failure/), warning that a missile was about to strike:

“Ballistic missile threat inbound to Hawaii.  Seek immediate shelter. This is not a drill.”

Thankfully, the message turned out to be a false alarm.  But it took a full 38 minutes for the follow-up “Don’t panic” message to be sent to citizens who had been scurrying to find shelter or reach loved ones.

There has been [much said](https://arstechnica.com/information-technology/2018/01/heres-how-to-make-sure-hawaiis-missile-warning-fiasco-isnt-repeated/) about how it was possible for an incorrect missile warning message to be sent, but I’m actually more interested in why it took so long to communicate the truth to a petrified public.

One issue seems to have been that although there were processes in place for sending out missile warnings, there weren’t such smoothly-run systems for releasing corrections rapidly.

Furthermore, the office of Hawaii’s governor David Ige knew that it was a false alarm just two minutes after the alert had been sent state-wide to mobile phones.  And yet it took Ige 17 minutes to send a tweet saying there was no missile threat.

> There is NO missile threat. [https://t.co/qR2MlYAYxL](https://t.co/qR2MlYAYxL)
> 
>  — Governor David Ige (@GovHawaii) [January 13, 2018](https://twitter.com/GovHawaii/status/952244930117738496?ref_src=twsrc%5Etfw)

The reason? The Governor of Hawaii had a simple [explanation](http://www.staradvertiser.com/2018/01/22/breaking-news/after-false-missile-alarm-ige-couldnt-log-on-to-twitter/). He forgot how to log into Twitter:

“I have to confess that I don’t know my Twitter account log-ons and the passwords, so certainly that’s one of the changes that I’ve made. I’ve been putting that on my phone so that we can access the social media directly.”

Clearly he wasn’t following the example set by some of the staff at Hawaii’s missile alert agency, who were [keeping their passwords on Post-it notes](https://hotforsecurity.bitdefender.com/blog/hawaiis-missile-alert-agency-keeps-its-password-on-a-post-it-note-19461.html).

On reflection it’s clear that human error, compounded by poor user interface design, caused the bogus missile alert to be sent out.  Such things shouldn’t happen, but – unfortunately – sometimes they do happen.

And when they do happen you need to ensure that you have a communication strategy in place.

You may not know precisely what form a cybersecurity incident may take inside your organisation, but you should plan now with your internal teams the possible scenarios – and make a communication strategy a key part of your response plan.

That means not only determining who needs to be told about an incident inside your business, but also how it will be communicated internally to staff, your customers, your partners, the press, and regulatory bodies.

Think now about how social media might be able to help you get a message out to your clients and the media, especially if other systems (such as your website) may not be operating effectively.

Don’t leave it until you are in the middle of a rainstorm to remember where you packed away the umbrellas.

Because you may try to blame the incident itself on technology somehow fouling up, but the truth is that many of those watching you will end up judging you less by what went wrong, and more by how you handled the fallout. 

### Explore More Topics

- [Enterprise Security (752)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (203)](https://businessinsights.bitdefender.com/topic/threat-research)
- [SMB Security (179)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [Ransomware (167)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (138)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (136)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (131)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (125)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (120)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (78)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (72)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (56)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (39)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (20)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (5)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/mishandling-cyber-risk-management-is-risky-business?hsLang=en-us>

### [Mishandling Cyber Risk Management is Risky Business](https://businessinsights.bitdefender.com/mishandling-cyber-risk-management-is-risky-business?hsLang=en-us)

<https://businessinsights.bitdefender.com/could-industry-follow-department-of-defense-security-lead?hsLang=en-us>

### [Could Industry Follow DoD Cloud Security Lead?](https://businessinsights.bitdefender.com/could-industry-follow-department-of-defense-security-lead?hsLang=en-us)

<https://businessinsights.bitdefender.com/will-companies-need-a-chief-artificial-intelligence-officer-caio?hsLang=en-us>

### [Will Companies Need A Chief Artificial Intelligence Officer (CAIO)?](https://businessinsights.bitdefender.com/will-companies-need-a-chief-artificial-intelligence-officer-caio?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Graham Cluley",
    "url" : "https://businessinsights.bitdefender.com/author/graham-cluley"
  },
  "datePublished" : "2018-01-26T10:10:00.000Z",
  "headline" : "Communication is key when responding to a cybersecurity incident",
  "image" : [ "https://businessinsights.bitdefender.com/hubfs/clock.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/communication-responding-cybersecurity-incident",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```