Not hacked, yet still in the headlines: the new reality of crisis communication
By Sandra Klein (Editor) und Hanna Greve (Account Director)
A cyberattack hits an external service provider or partner. Data has been leaked, the headlines are out, and suddenly your own company is in the spotlight. Not because it was the target of the attack, but because it’s somehow part of it. Welcome to perhaps the most unpleasant discipline of crisis communication: the crisis in your own supply chain caused by someone else. This article shows how companies should react in exactly this scenario—namely, quickly, precisely, and without self-sabotage in their communications.
In theory, the situation may be clear: The attack took place elsewhere; your own IT has not been compromised. In practice, however, the reality is different: Anyone belonging to the same corporate group or working with a compromised service provider is automatically perceived as part of the story. This makes sense to the media, to customers, and certainly to employees.
The result: Questions pour in before there is even any clarity internally. And this is exactly where the problem begins.
The cardinal mistake: waiting until “everything is clarified”
Many organizations react defensively by reflex in this situation. First investigate, then coordinate, and then communicate. At first glance, this sounds reasonable, but it is strategically wrong. Because crisis communication does not follow internal governance, but rather external dynamics. And these are usually fast, loud, and rarely patient.
This means: If you say nothing in the first few hours, you leave the power of interpretation to others. And experience shows they won’t give it up voluntarily. To avoid such a situation as much as possible, companies must take various measures in a specific order.
However, before the first statements are released to the public, key facts must first be clarified, responsibilities defined, and potential impacts realistically assessed. It is precisely these preparatory steps that determine whether communication in a crisis situation provides clarity or causes additional damage.
First step: Establish clarity about your own status
The first step requires a clear internal assessment of the situation. No fluff, no speculation. The one crucial question is:
- Are we affected—yes or no?
Building on that:
- What is known for certain?
- Which statements from the service provider or parent company are legally sound?
- Where are there still uncertainties?
Important: Facts and assumptions must be strictly separated. Communication based on assumptions is one of the quickest ways to the next level of escalation.
Second measure: Employees are multipliers
Anyone who immediately thinks of public relations has already lost the battle. That’s because the real communication front is internal. Employees are approached directly—by customers, partners, or in their personal lives. If they don’t have answers, people will create their own narratives, and those are rarely helpful.
That is why the following rule applies without exception:
- internal initial information before external communication
- clear guidelines instead of room for interpretation
- specific “do’s and don’ts” for handling inquiries
Third Measure: Demonstrate Presence with a Holding Statement
The expectation of “knowing everything right away” is untenable in cyber crises. What matters is an early, controlled start to communication. That is exactly what the holding statement is for. It constitutes a company’s first official response to an incident—at a time when many details are often still unclear. The goal is to transparently outline the current state of knowledge, demonstrate a sense of responsibility, and at the same time make it clear that the situation is being actively addressed. At the same time, such an initial statement creates the necessary leeway to review further information in a structured manner and communicate it effectively later on.
An effective minimal statement, for example, is: “The incident involves the parent company. As of now, we are not affected. We are continuously monitoring the situation. Please direct external inquiries to the communications team.” This statement may not sound elegant, but it is effective.
Companies should keep the following in mind: No one will be criticized for not knowing all the details immediately. However, they will certainly be criticized for saying nothing at all.
Fourth measure: One narrative instead of five versions
As soon as the first inquiries come in, it becomes clear whether the situation will remain stable or spiral out of control. The biggest risk factor here is inconsistent communication. When sales, HR, and management make conflicting statements, it creates exactly what is most damaging in a crisis—namely, contradiction.
The solution, however, is unspectacular but absolutely essential:
- define three to five key messages
- create a central Q&A document
- synchronize all internal spokespersons
The goal is clear: No matter who you ask, the answer should always be the same.
Fifth measure: Address stakeholders differently
Crisis communication demands speed. Nevertheless, time pressure must not lead companies to rely on one-size-fits-all messages. Yet this is exactly what often happens: The same message is sent simultaneously to customers, partners, employees, and the media. In practice, this scattergun approach rarely works. This is because each target group assesses an incident from a different perspective, has different information needs, and expects answers to different risks and consequences:
- Customers want to know if their data is secure
- The media seeks context and accountability
- Employees need guidance and reassurance
The challenge lies in addressing all these perspectives without straying from the central message.
Cyber incidents are unique: Silence is not an option here
While a tactical wait-and-see approach may be possible in other crises, a different logic applies to cyberattacks. As soon as data is potentially compromised, a legitimate public interest arises. Those who fail to communicate proactively then risk more than just bad press—namely, a lasting loss of trust.
Or to put it bluntly: It is better to articulate uncomfortable truths yourself than to have to correct others’ interpretations later.
External support: not a luxury, but an accelerator
In theory, all of this can be handled internally. In practice, however, what is often lacking is precisely what is in shortest supply during a crisis: time. External communications experts therefore primarily take on three functions:
- Bringing structure to a dynamic situation
- Accelerate decision-making processes
- Ensure consistent communication
Continuous monitoring of the media landscape is particularly valuable. After all, what appears to be a controlled process internally may have long since developed a momentum of its own externally.
Conclusion: It is not the cause of the crisis that determines the damage to reputation, but how it is handled.
A cyberattack in the supply chain—whether on a partner, a service provider, or the parent company—is not merely a technical problem. It is a reputational risk that spreads rapidly. And it also affects those who are not even operationally impacted. The crucial question, therefore, is not whether communication takes place, but how quickly, clearly, and consistently it occurs.