Index / Investigation and response

Communicating an Incident Internally

kind
Reference
domain
Casework
stage
Investigation and response
read
3 min
assumes
No prior programme in place

Who needs to know, what they need, and the leaks that come from the response rather than the incident.

Insider cases leak, and the leak almost always originates in the response rather than the incident. Deciding communication deliberately is part of containment.

The default is narrow

Start from: who cannot do their job without this information?

That list is shorter than instinct suggests. It is usually the investigator, the approver, legal, one person in HR, and whoever can technically preserve and restrict access.

Not the subject's manager, initially. They may be involved, may inadvertently signal, or may act unilaterally. Bring them in when the process requires it, which is usually at the interview stage.

Not the wider security team. Restrict and log who was told.

Not by email to a distribution list. Use a named channel with a controlled membership, and assume anything written may be disclosed later.

What each audience needs

Legal needs everything, early, including the uncertainties.

HR needs the factual findings and the technical explanation in plain language. They do not need raw logs; they need to understand what the evidence shows and what it does not.

Executives need scope and consequence: what data, how much, whether it left, what is being done, what the exposure is. They do not need the investigation detail, and giving it invites premature conclusions.

The subject's manager, when engaged, needs to know what they must not do โ€” not discuss it, not change the person's work, not alter access.

The workforce, generally, needs nothing during a case. Afterwards, an anonymised lesson may be worth sharing.

Language discipline

Distinguish observed from inferred, in every communication. "The account transferred 4,200 files" is observed. "The employee stole customer data" is a conclusion.

Executives will adopt whatever language you use, and repeat it. If you say "theft" in a status update, that word ends up in a meeting you are not in, before anyone has determined it.

State confidence explicitly. "We have confirmed", "we believe", "we are checking". Undifferentiated statements get read as equally certain.

Avoid naming the person in written updates where it is not necessary. Use a case reference.

Timing

Do not report the first alert upward. Wait until triage has established that there is something. Reporting raw alerts trains executives to expect drama and burns credibility when most resolve as nothing.

Do report early once it is real, even without conclusions. An executive who learns of a significant case late will be more concerned about the delay than the incident.

Set an update cadence and hold to it, including when there is nothing new. Silence produces speculation and inbound questions that consume the investigation.

The regulatory clock

If personal data may have been exposed, notification obligations may apply, and the deadline typically runs from awareness rather than from confirmation.

Involve whoever owns that assessment immediately. The determination of whether a notification threshold is met is not the security team's to make alone, and the clock does not pause while an investigation continues.

After it closes

Tell the people who were involved what the outcome was. Investigators, HR, the approver. Cases that end in silence leave everyone uncertain whether the process worked.

Tell the subject, if they were aware of the investigation and it concluded in their favour. Being investigated and never informed of the outcome is corrosive, and word of it spreads through an organisation quickly.

Consider an anonymised lesson for the workforce, particularly for negligence cases. Local examples are the most effective awareness material available, and they only exist if someone decides to use them.