Advising communications leaders
FRENGESIT中文한국어日本語DEIndia · ENहिन्दी
← All news and perspectivesOpinion / Cybersecurity & trust

Cybersecurity Month: the cross-Channel supplier must be ready to explain an outage

A British supplier serving European customers needs an incident communication process that works across jurisdictions and time zones.

ENISA's 30 September announcement places workplace skills within October's Cybersecurity Month. [1]

A British supplier serving European customers needs an incident communication process that works across jurisdictions and time zones. October's awareness campaign is a useful moment to test that process. The important question is whether the French customer can obtain an accurate service update while the British technical team is still investigating.

What the news means in this market

The exercise can begin with an unavailable ordering platform and a disputed delivery estimate. Identify who can acknowledge the problem, which channel remains usable and how a local customer receives the next update. Specialist advisers should assess applicable reporting duties separately; a communications rehearsal should not invent a universal notification rule.

Awareness is useful only if a response is possible

A cybersecurity campaign can help people recognise a suspicious message, but recognition is only the first step. Employees need to know how to report a concern, what information to preserve and where to obtain help without fear of automatic blame. A customer needs to know which channel is genuine and how to verify a request. If those routes are unclear, a poster campaign can create anxiety without improving the organisation's ability to respond. Communications should therefore be tested as part of the operating process: can a person identify the right action and reach someone who can actually act?

Prepare the explanation before the facts are complete

During an incident, technical understanding develops over time. A public statement must distinguish verified facts, matters under investigation and actions already taken. It should not claim that no information was affected simply because no effect has yet been confirmed. Equally, it should not repeat an unverified allegation as a finding. Prepare language that can express uncertainty precisely and identify when the next update will be provided. The legal, security, operational and communications teams should share the same factual record. This allows the organisation to be responsive without turning speed into speculation or reassurance into an unsupported guarantee.

Explain how essential services will continue

A hypothetical supplier may restore its main website while order processing remains unavailable. Announcing that systems are back could then mislead customers about what they can do. Explain restoration by service and state any temporary limitations. Provide practical alternatives where they exist, including ways to confirm an urgent request. A recovery update should be written from the user's perspective, not just the infrastructure team's status board. That approach also helps internal teams identify gaps: a technical milestone is not complete recovery if customers still cannot obtain the service for which they depend on the organisation.

Protect people from secondary confusion

An incident can create opportunities for impersonation and false instructions. Publish a stable reference point and make clear which channels the organisation will use for updates. Do not ask people to provide sensitive information through an improvised process without a legitimate, reviewed purpose. Customer-facing teams need a consistent explanation of how to verify a communication. Internally, ensure that people working away from the office can access reliable guidance if ordinary systems are unavailable. The message should reduce uncertainty about what to do next. Repeating technical detail without practical direction can leave the audience more informed about the incident but no better protected.

A second source to put the issue in context

ENISA provides public guidance and resources for cybersecurity awareness. [2]

For an organisation operating between the United Kingdom, the United States and continental Europe, the practical challenge is to connect a common corporate position with different public debates. A British programme is not an EU programme, and an American political argument does not determine the situation of a French subsidiary. The analysis should identify the market concerned, the decision-maker and the evidence available. Local teams need enough authority to explain those differences without changing the underlying facts. This is where communications can support international judgement: by making the differences understandable before they become contradictory public promises.

Do not make employees carry the whole narrative

The human factor is often discussed as though every incident begins and ends with an individual's mistake. That framing can obscure design, workload, access management and supervision. It can also discourage early reporting. A useful awareness programme explains the behaviour expected of employees while acknowledging the systems and support the organisation must provide. Communications teams should avoid presenting a training completion rate as proof that the organisation is secure. The relevant question is whether the process helps detect, report, contain and learn from problems. Those capabilities require cooperation, not a search for a convenient person to blame.

Rehearse the cross-border decision chain

International organisations should test who can approve a statement when an incident affects more than one market. Different stakeholders may require different information, but the underlying facts should remain consistent. Local legal obligations need specialist assessment; a global communications template cannot determine them. A rehearsal can reveal delays caused by time zones, unclear authority or inaccessible contact lists. It can also test whether a local team is permitted to acknowledge a service problem before headquarters has completed its full assessment. The result should be a decision process that supports accurate local information while preserving a coordinated account of the event.

Recovery must include an account of what changed

The end of the immediate disruption is not necessarily the end of the reputational issue. Explain the restored services, the remaining limitations and the improvements the organisation can substantiate. Avoid promising that an incident can never recur. Where an investigation is continuing, state that clearly and commit only to updates that can realistically be provided. A useful internal review examines the communication process alongside technical response: which questions went unanswered, which approvals were too slow and which instructions caused confusion? This turns the awareness campaign into a continuing capability rather than an annual reminder detached from real operating conditions.

Scope of this analysis

This article distinguishes the dated public information cited above from our editorial interpretation. The practical scenarios are hypothetical; they do not describe an undisclosed client assignment or an independently measured result. An event programme establishes an announced agenda, not conclusions that participants have necessarily reached. Company decisions should be assessed with the relevant operational and specialist teams before public commitments are made.

Sources and context

  1. ENISA, 30 September 2026
  2. ENISA — European Cybersecurity Month

Read in another language

Deutsch · Español · 한국어 · 中文 · Italiano · 日本語 · English — India · हिन्दी

These editions address the same subjects with context adapted for their readers.

Discuss your challenge

A short introduction is enough to start: your organisation, the decision at hand, the audiences involved and your deadline. Confidential documents can follow through an agreed channel.

Email Belief System