Skip to content
atlas

Communication plan

Also known as: crisis communication plan

A plan for who tells what to whom during a crisis - staff, customers, authorities and the press.

Draft - this entry has not been reviewed yet.

Formal

The part of the contingency plan that names who may speak for the organisation and sets approval steps, prepared messages, contact lists and reporting deadlines for internal and external communication during an incident.

In plain English

Like agreeing in advance who in the family calls grandma with bad news, so she does not hear it first from the neighbours.

In practice

When member data leaks from a pension fund, the plan says only the director speaks to the press, members get a prepared message in e-Boks, and Datatilsynet is notified within 72 hours.

Why it matters

Confused or late messages can do more harm to trust than the incident itself, and missing a reporting deadline set by law can bring fines.

Technical deep dive

NIST SP 800-34 Rev. 1 lists the crisis communications plan as one of the plan types around an information system contingency plan, and ISO 22301:2019 clause 8.4.3 requires procedures for warning and communication, covering communication with interested parties, the media and, where relevant, national or regional authorities, including how communication is recorded. NIST SP 800-61 addresses the same need from the incident-response side: who may share what with law enforcement, other response teams, suppliers, customers and the media, and the rule that information sharing is decided in advance rather than improvised.

A working plan contains a stakeholder map (staff, management, board, customers, citizens or patients, suppliers, insurers, regulators, police, media, partners), named spokespersons with deputies, an approval chain with a maximum turnaround time, pre-approved holding statements for the most likely scenarios, and channel choices for each audience. It also defines a single source of truth, usually a situation log owned by the crisis team, from which all messages are derived, so that the press office, customer service and the regulator do not receive conflicting versions.

The legal deadlines drive the timing more than any communications preference. Under GDPR Article 34 the controller must inform affected data subjects without undue delay when a breach is likely to result in a high risk to them, in clear and plain language describing the nature of the breach, the likely consequences, the measures taken and a contact point. Article 34(3) allows a public communication instead when individual notice would involve disproportionate effort. NIS2 Article 23(1) requires entities, where appropriate, to notify recipients of their services of significant incidents likely to affect them, and Article 23(2) to tell recipients potentially affected by a significant cyber threat what measures they can take. These external messages and the regulatory reports must be consistent, because regulators and journalists compare them.

Cyber incidents add constraints that ordinary crisis communication does not face. Email, Teams and the intranet may be compromised or monitored by the attacker, so the plan needs out-of-band channels such as phone trees on paper, SMS services or a separate messaging platform prepared in advance. Statements should avoid premature claims such as "no data was taken" before forensics confirms it, since corrections damage trust more than an honest "we are investigating". Ransomware groups also contact customers and journalists directly, which the plan should anticipate.

Relationships

Sources & further reading

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.