InsightsINS-10 / Incident communication

Secure communication during a cyberattack

If identity, email or collaboration services may be part of the incident, the response cannot blindly depend on those same systems.

Direct answer

Defensible incident communication starts with a pre-defined trust transition: named roles, an independently reachable fallback channel, concise situation updates, controlled membership and a separate evidence trail. The channel is exercised before it is needed.

Key points
  • The primary channel may be part of the incident and needs a documented replacement.
  • Membership, roles and approvals are re-confirmed at every trust transition.
  • Updates separate confirmed facts, assessments, decisions and the next deadline.
  • Conversation history, incident record and forensic evidence are distinct artifacts.
01

Resolve the channel paradox first

A cyber incident can affect the systems normally used to alert and coordinate the response. If the identity provider is compromised, a successful sign-in may no longer establish the identity expected. If email is affected, an invitation to a replacement channel may itself be manipulated.

The incident plan therefore needs an agreed switch condition and an independent way to confirm the replacement location, participants and trust anchors. A second messenger without independent verification merely moves the problem.

  • Which systems are untrusted in this scenario?
  • Who can declare and end the trust transition?
  • How are destination and participants confirmed out of band?
  • Which data may be processed in the fallback channel?
02

Four roles instead of one crowded chat

At least four responsibilities remain visible: Incident Lead for decisions, Technical Lead for analysis and containment, Communications Lead for consistent updates and Recorder for the timeline. In a small team one person may carry several roles, but the responsibilities stay distinct.

A broad all-hands channel is rarely the right place for every detail. A small decision room, specialist work rooms and a readable information channel reduce noise and accidental disclosure. Membership follows task and need to know.

03

The four-field situation update

Under pressure, long prose is interpreted inconsistently. A robust update uses four fields: confirmed situation, open assessment, decision and next reporting point. Every statement carries time and accountable role.

The format prevents an assumption becoming fact and silence after an update being read as an all-clear.

  • FACT - directly evidenced
  • ASSESSMENT - reasoned but unconfirmed
  • DECISION - approved with accountable role
  • NEXT - next checkpoint or escalation condition
04

Separate evidence, decision and conversation

Chat supports coordination; it is not automatically a forensic evidence system. The incident record should reference decisions and sources while original artifacts remain in a controlled evidence store with integrity and access controls.

The separation also reduces privacy exposure. Participants receive the context required for their role rather than the full evidence collection.

05

Exercise outage and compromise separately

An unavailable channel is obvious. A compromised channel may appear normal and create false confidence. Tabletop exercises must distinguish technical outage from a channel whose identities or content can no longer be trusted.

NIST integrates incident response across cybersecurity risk management and CISA provides communications-specific SOP and exercise guidance. Switching, confirming, working and returning should therefore be measured as a workflow.

06

Returning is a security event

After containment, teams should not drift informally back to the old channel. Identity, endpoints, sessions and integrations are reassessed first; open invitations and old tokens are handled explicitly.

The close records which channel was authoritative for which period, which decisions were transferred and where evidence was preserved.

FAQ / FACTS

FAQ

If identity, email or collaboration services may be part of the incident, the response cannot blindly depend on those same systems.

No. The destination, participants, roles and permitted data also need an independent verification path.

Usually not. Small decision and work rooms plus a separate information channel reduce noise and unnecessary disclosure.

It may support the timeline but does not replace controlled evidence handling with provenance, integrity and access controls.