What to Tell Clients, Staff, and Insurers After a Breach
A cyber breach creates two problems at once.
The first is technical: stopping the attacker, protecting systems and understanding what happened.
The second is communication.
Employees want to know whether they can work safely. Clients want to know whether their information is affected. Insurers want prompt notification and evidence that the organisation is following its incident-response obligations.
Handled well, communications can reduce confusion, protect customers and preserve trust. Handled badly, they can create contradictory statements, unnecessary panic and legal problems that last longer than the technical incident.
The rule is simple:
Communicate early enough to be useful, but never guess.
Communicate While the Investigation Is Still Developing
You rarely know the full impact when the first message must be sent.
That does not mean remaining silent. It means separating confirmed facts from matters still under investigation.
The UK National Cyber Security Centre recommends incident communications that are clear, consistent, authoritative, accessible and timely. It also advises organisations not to minimise or misrepresent an incident in a way that creates future difficulties.
A useful early update might say:
We identified suspicious activity affecting part of our Microsoft 365 environment this morning. We have contained the affected accounts and are investigating the scope with specialist support. At present, we have not confirmed whether personal information was accessed. We will provide another update by 3 p.m.
That is more trustworthy than declaring that no data was affected before the evidence has been reviewed.
Create One Authoritative Message
During an incident, information can quickly become inconsistent.
IT may describe a “compromised account,” management may call it a “system outage,” and an employee may tell a customer that “we have been hacked.”
Nominate one person or small communications group to approve internal and external messaging. Technical, legal, operational and customer-facing teams should work from the same confirmed incident summary.
The NCSC recommends assigning individuals to deliver the organisation’s internal and external message and ensuring communications are coordinated throughout the response.
Maintain a short communications record containing:
- What has been confirmed
- What remains unknown
- Which groups have been notified
- The wording sent
- The time of each update
- Who approved it
- When the next message is due
This prevents people from relying on old drafts or contradictory assumptions.
What to Tell Staff
Employees should normally hear about a significant incident before they encounter rumours, customer questions or media coverage.
The first staff message should explain:
- What has happened in plain language
- Which systems or accounts are affected
- What employees must do immediately
- Which actions they must avoid
- Where to report suspicious activity
- Whether normal work should continue
- When the next update will be provided
For example:
We are investigating a security incident involving several Microsoft 365 accounts. The affected accounts have been blocked, and our IT team is reviewing access and email activity. Do not approve unexpected MFA requests, open unusual file-sharing messages or discuss the incident externally. Continue working unless your manager or IT instructs you otherwise. Report anything suspicious to the service desk by telephone.
Employees do not need every forensic detail. They need instructions that help contain the incident.
Give Staff Specific Actions
Avoid vague advice such as “remain vigilant.”
Tell employees exactly what behaviour is required.
Depending on the incident, that might include:
- Stop using an affected device.
- Disconnect from the network.
- Do not delete suspicious messages.
- Do not reset passwords until instructed.
- Reject unexpected MFA prompts.
- Verify payment requests by telephone.
- Do not reconnect OneDrive synchronisation.
- Forward media enquiries to the nominated contact.
- Report customer concerns through a dedicated channel.
Specific instructions reduce well-intentioned actions that could destroy evidence or spread the attack.
Do Not Blame the Employee
An early breach message is not the place to identify the person who clicked a phishing link, approved a prompt or lost a device.
Public blame discourages employees from reporting mistakes quickly. It can also expose personal information and create unnecessary HR issues.
Describe what happened to the organisation rather than speculating about individual fault.
A more useful message is:
An employee account was accessed by an unauthorised party.
Not:
An employee caused the breach by clicking a phishing email.
The investigation can examine individual actions later through the appropriate HR, legal and security processes.
What to Tell Clients
Not every cyber incident requires an immediate message to every customer.
Client notification becomes more important when:
- Their personal or confidential information may be involved
- Fraudulent messages were sent from your systems
- Your service is unavailable
- Their access credentials may be affected
- They need to take protective action
- A contract requires notification
- Continued silence could expose them to further harm
The message should focus on what the client needs to know and do—not on protecting the company from embarrassment.
Include:
- A clear description of the incident
- When it was discovered
- The information or services potentially affected
- What you have done to contain it
- What the client should do
- How they can contact you safely
- When further information will be available
Give Clients Practical Protective Advice
Where customer information may have been exposed, the notification should explain the likely risk and the steps the recipient can take.
Advice may include:
- Be alert for phishing messages.
- Do not trust payment changes received by email.
- Contact your bank regarding suspicious transactions.
- Reset a password if the affected service stored credentials.
- Enable multifactor authentication.
- Verify future communications using known contact details.
- Report unusual messages to a dedicated incident address or telephone number.
The ICO advises affected people to watch for suspicious emails, texts and websites and to contact banks or document issuers when financial or identity information may be involved.
Do not issue generic warnings that leave clients guessing whether they are affected.
Explain What Data Was Involved
Where possible, say whether the incident involved:
- Names and contact details
- Account information
- Financial records
- Identity documents
- Health or employment information
- Email content
- Login details
- Customer documents
Avoid broad statements such as “some data may have been accessed” when you already know which categories are involved.
Where the investigation is incomplete, state that clearly:
Our current investigation indicates that names, email addresses and invoice information may have been accessed. We have not identified payment-card details in the affected system. This assessment remains under review.
That wording distinguishes evidence from uncertainty.
When Individuals Must Be Informed
Under the UK GDPR, an organisation must notify affected individuals without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms.
The communication should describe the nature of the breach, provide a contact point, explain likely consequences and describe measures taken or proposed to address it. Not every breach requires individual notification, but every personal data breach should be assessed and documented.
This is a legal-risk assessment, so obtain appropriate data-protection or legal advice rather than deciding purely on reputational concerns.
Remember the ICO Deadline
Where a personal data breach is likely to result in a risk to individuals, the organisation must report it to the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it.
The clock begins when the organisation becomes aware of the breach—not when the attacker first gained access. The ICO recognises that the full investigation may not be complete within 72 hours, so an initial report can be supplemented as more information becomes available.
Do not wait for perfect certainty before beginning the assessment.
Start an incident log immediately and record:
- When the breach was discovered
- The systems involved
- Categories of people and records affected
- Likely consequences
- Containment measures
- Reasons for reporting or not reporting
The ICO provides a self-assessment tool for organisations unsure whether the reporting threshold has been met.
What to Tell Your Cyber Insurer
Notify your insurer or broker as early as your policy requires.
Do not wait until the investigation is complete, systems have been rebuilt or customers have been contacted. Policies may contain notification conditions, approved-provider requirements and restrictions on incurring costs without consent.
Your initial notification should normally include:
- Policy number
- Date and time the incident was discovered
- Brief description of what happened
- Systems, accounts and locations affected
- Current operational impact
- Containment steps already taken
- Whether personal information may be involved
- Whether fraud, ransomware or extortion is suspected
- External specialists already engaged
- A named incident contact
Cyber policies may cover forensic investigation, legal advice, customer notification, public relations, regulatory response and business interruption. The exact support and conditions depend on the policy.
Use the insurer’s emergency number or breach-reporting route where one is provided.
Do Not Appoint Expensive Specialists Without Checking
During a serious incident, urgent outside help may be necessary.
However, some insurance policies require you to use an approved incident-response, legal, forensic or communications provider. Appointing another firm without informing the insurer could affect reimbursement.
That does not mean delaying essential containment. It means contacting the insurer promptly and documenting why urgent decisions were made.
Ask:
- Which forensic providers are approved?
- Is legal counsel included?
- Is public-relations support available?
- Does the insurer require consent before expenditure?
- Which evidence must be preserved?
- How often are progress updates required?
Keep a record of every conversation and claim reference.
What Not to Tell People
Avoid statements that are unsupported, defensive or likely to become inaccurate.
Do not say:
- “No data was accessed” before confirming it.
- “The incident is fully resolved” while monitoring continues.
- “It was only one account” without reviewing lateral activity.
- “Customers are not at risk” without completing the risk assessment.
- “We have contacted all affected people” when the population is still changing.
- “The attacker has been removed” if persistence mechanisms remain under investigation.
Also avoid publishing detailed technical information that could help the attacker, such as current containment gaps, unpatched systems or the exact accounts still being investigated.
Use a Simple Update Structure
Every update can follow the same format:
What happened?
One or two factual sentences.
What have we done?
Containment, investigation and recovery actions.
What do you need to do?
Clear instructions for the audience.
What happens next?
The time of the next update and contact details.
For example:
We identified unauthorised access to one employee mailbox on Monday morning. The account has been secured, active sessions revoked and external forwarding removed. Some clients may have received fraudulent payment instructions; do not act on any bank-detail change sent by email without telephone verification. Our investigation is continuing, and the next update will be issued tomorrow at 10 a.m.
Prepare Separate Messages for Separate Audiences
One message rarely works for everyone.
Staff need operational instructions. Clients need impact and protective actions. Insurers need policy and incident details. Regulators need a structured risk assessment. Suppliers may need warnings about fraudulent communications.
Create separate drafts, but ensure they use the same confirmed facts.
A useful communications matrix might look like this:
Audience | Main need |
Staff | What to do and how to continue working |
Clients | What happened, impact and protective action |
Suppliers | Fraud and payment-verification warnings |
Insurer | Incident facts, costs and required assistance |
ICO or regulator | Risk, data categories and response measures |
Media or public | Confirmed facts and service impact |
Common Breach-Communication Mistakes
Waiting Until Every Detail Is Known
People are left exposed while the investigation continues.
Communicating Too Early Without Coordination
Different departments issue conflicting statements.
Downplaying the Incident
Later evidence makes the organisation appear misleading.
Sending Technical Jargon to Clients
Recipients do not understand what they should do.
Forgetting Internal Staff
Employees learn about the breach from customers or social media.
Failing to Notify the Insurer Promptly
The organisation misses access to approved specialists or risks breaching policy conditions.
Promising an Update and Missing It
Trust falls even when the technical response is progressing well.
Breach Communication Checklist
Before sending a message:
- Confirm the known facts.
- Separate facts from assumptions.
- Identify the audience.
- Obtain legal, privacy and technical input.
- Check contractual and insurance notification requirements.
- Provide practical actions.
- Include a safe contact route.
- State when the next update will be issued.
- Record who approved and received the message.
During the incident:
- Keep messaging consistent.
- Correct inaccurate statements promptly.
- Update clients when the risk changes.
- Keep staff informed about operational instructions.
- Maintain insurer and regulator contact.
- Preserve copies of all communications.
Final Thoughts
After a breach, silence can create as much confusion as poor communication.
Tell staff what they need to do. Tell clients what may affect them and how they can protect themselves. Tell insurers early enough for them to provide the response services included in the policy.
Be clear, factual and honest about uncertainty.
You do not need to know everything before communicating. You do need to avoid guessing, minimising or making promises the investigation cannot yet support.
The strongest incident message usually contains four things:
What happened. What you have done. What the recipient should do. When they will hear from you again.
Need Help Managing Communications After a Cyber Breach?
Hamilton Group can help your organisation contain, investigate and communicate during a Microsoft 365 or wider cybersecurity incident.
Our experts can help you:
- Build breach-notification templates
- Coordinate staff and client communications
- Investigate compromised Microsoft 365 accounts
- Preserve logs and evidence
- Assess affected users, mailboxes and files
- Support insurer and legal-response teams
- Prepare an incident timeline
- Create customer and supplier warnings
- Review incident-response procedures
- Run post-incident tabletop exercises
Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts for support responding to and communicating after a cyber breach.