Blog

Crisis Communications for Cybersecurity

by Jason Shafton

An incident at a cybersecurity vendor isn't a standard PR problem. Your customers are security practitioners who will scrutinize every word in your statement, your disclosure timeline also serves as a legal document, and your renewal pipeline is paying attention. We run crisis communications designed for that audience.

The Challenge

Your customers understand a packet capture better than most reporters

The audience reading your incident statement includes CISOs, security engineers, and analysts who evaluate claims for a living. A vague phrase like 'no evidence of impact' gets picked apart on security Twitter within the hour. Generic PR language reads as evasive to this crowd, and evasive reads as dishonest.

Disclosure law and narrative control operate on different clocks

SEC 8-K materiality rules, state breach notification statutes, and customer contract SLAs each run on their own clock and don't wait for your messaging to be ready. Legal wants precision and minimal exposure; the market wants speed and clarity. Most vendors have no process for reconciling the two, so the first draft goes out too slow and reads like cover-up, or too fast and creates statements legal has to walk back.

The thing that failed is the product itself

When a logistics company has a data incident, customers ask if their data is safe. When a security company has an incident, customers ask if the entire premise of the vendor relationship is a lie. That's a different category of trust erosion, and it hits renewals, competitive deals, and analyst coverage at once. Standard reputation-repair playbooks built for other industries don't account for that irony.

The board needs a plan before the facts are final

Investors and board members start asking about valuation impact, customer churn, and next funding round optics almost immediately, often before the security team has a confirmed root cause. Founders end up communicating externally and internally at once with incomplete information, and inconsistent messaging between those audiences becomes its own story if it leaks.

How We Support You

We begin by auditing where you really stand, rather than applying a generic crisis template: your current incident response plan, disclosure requirements by jurisdiction and contract, previous public statements if there's a history, and who communicates with whom internally when something goes wrong. Most security companies have a technical incident response plan but no communications counterpart. That gap can turn a contained technical event into an extended trust problem.

Next, we develop the message architecture: a single factual core that legal, the board, customers, and press all work from, with the format and level of detail tailored by audience but no contradictions across them. Every version, from the customer statement and SEC filing to the board update and press response, maps back to the same verified facts and follows the same update schedule.

We write with the technical reader in mind first: describing what occurred in language a security engineer would use, clearly stating what is and isn't known yet, and never diluting the wording in a way practitioners would identify as spin. If something remains unknown, the statement acknowledges that and gives a timeline for the next update.

We align the disclosure timeline with your legal requirements so communications and legal teams follow the same clock, working with outside counsel on 8-K materiality assessments and state notification triggers rather than negotiating them in real time.

For investors and the board, we maintain a separate cadence that's shorter and more frequent, centered on business impact, customer risk, and what remains under verification.

After the acute phase is under control, we move into recovery: a customer-facing retrospective once root cause has been confirmed, direct outreach to at-risk accounts and those nearing renewal, and briefings for the analysts and press who covered the incident, ensuring the record reflects what was fixed as well as what broke.

What we deliver

A security vendor's incident statement isn't read first by journalists. It's read by the CISOs deciding whether to renew, and they know precisely what hedging sounds like.

Our Methodology

We manage crisis communications as a three-phase, 90-day sprint because the acute incident period and trust-recovery period demand different pacing. The first two weeks cover the acute phase: reviewing existing plans, developing the message architecture, putting legal and communications on the same disclosure clock, and having initial statements reviewed by someone who understands what technical audiences recognize as spin. This work moves in days rather than weeks because the clock is already ticking.

Days 15 to 45 focus on stabilization. Updates follow a fixed cadence as facts become firmer, customer and board communications run in parallel from consistent facts, and outreach to at-risk accounts begins before those discussions happen on the customer's terms rather than yours. Days 45 to 90 center on recovery: publishing the retrospective, briefing analysts and press directly, and assessing honestly how the incident affected pipeline and renewals. Unlike a traditional PR retainer, we aren't managing the media narrative in isolation. We coordinate communications, technical incident response, and legal disclosure as a single operation because, in cybersecurity, all three functions succeed or fail together.

The Insights You Want

Right in your inbox. We’ve done the work, and now we’re sharing it with you. Sign up to stay in the loop.

Get The Latest Updates


Enter your email address

Our Working Approach

The engagement begins when you call, not after a proposal process. The first 48 to 72 hours are dedicated to the audit and message architecture because, during a live incident, the first statement shapes everything that follows. We work directly alongside your existing legal counsel and incident response lead rather than replacing either one.

The team is small and senior: one lead owns the message architecture and works directly with your founder or CEO, supported by a writer who manages the volume of drafts for different audiences. We don't assign a large account team to a crisis because events move too quickly for a committee to keep pace.

During the acute phase, the cadence is daily and sometimes more frequent. As the situation stabilizes, we transition to weekly work through recovery, with formal check-ins on day 30, day 60, and day 90 to evaluate where customer and board trust actually stands.

A complete 90-day crisis engagement costs $15K-$40K/month, depending on incident severity, jurisdictional complexity, and whether analyst and press outreach fall within scope. Retainer-based crisis-readiness work completed before an incident is priced separately and costs less.

If your cybersecurity company needs crisis communications leadership, we should talk.

Expand your marketing team output with our experts

Let us take a custom approach to your growth goals by assembling and leading the best-in-class marketing team to support your next stage.

Frequently asked questions

How quickly can you begin if we're already dealing with an incident?

We can join a call within hours rather than days. The first public statement typically goes out within 24 to 48 hours, and its wording matters more than nearly anything else during the engagement. We begin with a rapid review of what has already been said, then develop the message architecture alongside your legal counsel instead of waiting for a completed legal draft.

How much does this cost?

A complete 90-day crisis engagement costs $15K-$40K/month based on the incident's severity, the number of jurisdictions whose disclosure laws apply, and whether analyst and press outreach are included. Crisis-readiness work completed before an incident costs less and is priced separately as a retainer. We'll provide a specific figure after the initial audit call, not beforehand.

How does this differ from a traditional PR firm managing a data breach?

Most PR firms approach a breach disclosure as a generic reputational event and write for a broad audience. Your real audience consists of security practitioners who can detect corporate hedging in a single sentence, operating on a disclosure timeline governed by SEC materiality rules that most PR teams have never worked within. Rather than drafting statements in isolation, we coordinate directly with your incident response and legal teams as one operation.

Do you take the place of our legal counsel or incident response team?

No. We work alongside both teams. Legal is responsible for disclosure requirements and liability exposure, your security team handles root cause and remediation, and we turn verified facts into language that serves customers, press, the board, and regulators without creating contradictions. That coordination is typically the part nobody owns until it has already become a problem.

How do you determine whether this actually worked?

We monitor retention among renewal-stage accounts, whether press and analyst coverage accurately reflects what occurred, whether support ticket sentiment stabilizes following each update, and how board confidence changes across the 30/60/90-day check-ins. We don't use vanity metrics such as impression counts because impressions can't tell you whether a CISO renewed or left.

What happens if the technical facts change after we've issued a public statement?

That occurs in most incidents, which is why our message architecture is built around regular update cadences instead of an initial statement that sounds definitive. A statement that identifies what's confirmed, what's still under verification, and when the next update will arrive holds up better as facts change than one that claims too much certainty.

Is this just for companies in an active crisis, or can we plan in advance?

Planning ahead is the better and less expensive form of this work. We create crisis-readiness plans, pre-drafted statement templates for each scenario, and a clear internal escalation and approval chain, allowing the first 24 hours to follow a plan instead of relying on improvisation. Companies that prepare this way spend far less during a real incident because the structural choices have already been made.

What company size and stage is the best fit for this?

This is designed for Series A through growth-stage cybersecurity companies with roughly $5M-$100M ARR, a real board, enterprise customers conducting security reviews, and genuine disclosure exposure, but without an in-house crisis communications function. Earlier-stage businesses with only a handful of customers generally don't require this structure, while much larger companies often already have it internally.


Related Solutions

Solutions

Top Articles

Frank Growth – Episode 229 – Longevity Medicine’s Dirty Secret with Jim Donnelly

Tuesday, July 21, 2026

Frank Growth – Episode 229 – Longevity Medicine’s Dirty Secret with Jim Donnelly

Episode #229: Jim Donnelly — Franchising longevity medicine without losing medical quality How to scale a medical franchise when you can’t train a local owner to interpret biomarkers. For operators and founders standardizing a complex, high-trust service across many locations. Jim Donnelly scaled Restore Hyper Wellness to 260 locations before starting Humanaut Health, a concierge...
Frank Growth – Episode 224 – The Bootstrapper’s Revenge with Alex Roy

Tuesday, June 16, 2026

Frank Growth – Episode 224 – The Bootstrapper’s Revenge with Alex Roy

Episode #224: Alex Roy — Bootstrapping an AI company for 12 years, no funding He founded an AI company in 2014—when AI was a punchline—bootstrapped it with zero outside capital, and landed Fortune 50 clients. For founders and growth operators figuring out how to build (and sell) AI products in a market that shifts every...
Frank Growth – Episode 234 – Nobody Has The Playbook Yet with Dave Steer

Tuesday, August 25, 2026

Frank Growth – Episode 234 – Nobody Has The Playbook Yet with Dave Steer

Episode #234: Dave Steer on repositioning a brand around AI in three months Webflow’s CMO had 90 days to relaunch the website, reposition the brand, and ship an ad campaign. For marketing leaders whose board just told them to become AI native, and who don’t have a playbook for it. Dave Steer is CMO at...
Frank Growth – Episode 233 – Stop Writing Only for Humans with Jesus Requena

Tuesday, August 18, 2026

Frank Growth – Episode 233 – Stop Writing Only for Humans with Jesus Requena

Episode #233: Jesus Requena — Dropping SEO entirely to optimize for LLMs Sanity stopped producing SEO content and started building pages only machines will read. Roughly 60% of last month’s signups came from LLMs. For B2B growth leaders watching organic traffic fall and trying to work out what replaces it. Jesus Requena is CMO at...

See more

Browse Categories

See more

Ready to unlock your growth?

Book Free Call

We take a custom approach to your growth goals by assembling and leading the best-in-class marketing team to support your next stage.