Privacy Ref Blog

Crisis Communication Plans and Data Breaches

Think of a data breach as not only a possibility, but also a likely crisis scenario for your company. A breach will cost your company not only money but can deeply damage its reputation.

When was the last time your company reviewed its crisis communication scenarios and, most importantly, added data breach to the top of this list?

Response Plan

Dianna Fletcher is the Founder and President of Fletcher Media, experts in assisting organizations in working with the media during crisis situations.

Sounds simple, right; a data breach is an emergency and your company will respond with the same steps as every other crisis. But a data breach is unique and vastly different from other situations. If your company is hit by a natural disaster, such as an earthquake or flood, there’s an instant and obvious action and reaction.

A data breach; not so much. Hackers are invisible and lethal in their own way. You may first find out you’ve been hit via stakeholders, customers or investigators.

Your response plan will be completely different from a physical or natural disaster.

Response Team

This team may look different from your team for other crisis scenarios. Along with legal counsel, your team will include PR professionals, web designers, social media consultants, an IT forensic team, insurance representatives, and law enforcement or investigatory representatives.

Media Train Spokespeople

At some point in a data breach response scenario, it is important for senior management to reach out and speak directly to those customers who are impacted. It’s part of the empathy and transparency that should be part of every crisis scenario.

But with a data breach, your privacy professional or someone with deep IT knowledge may work with the media. Identify and media train those people BEFORE the crisis happens.

Define Stakeholders

Data breach notification laws require direct notification to those impacted (consumers), but the reach goes beyond customers. Define all stakeholders and consider messages for all.

Assess your “Bank of PR”

What is your ongoing relationship with local and regional media contacts as well as your industry’s media outlets and bloggers? If you don’t have a solid media relationship, hire a PR professional to make those contacts. Build on your “Bank of Good PR” before a crisis hits.

If your company’s data is breached, your company is a victim. But for the media, the story is about the obvious victims, your customers.

Privacy Ref provides consulting and assessment services to build and improve organizational privacy programs. For more information call Privacy Ref at (888) 470-1528 or email us at

Posted on August 6, 2014 by Dianna Fletcher
Tags: , ,

« »

No Responses

Comments are closed.

« »

Subscribe to our mailing list

Please fill out the form below.


Want to find out more?

Simply go to the contact page, fill out the form, and someone from Privacy Ref will be in touch with you. You can also send an email to or call (888) 470-1528.


April 16, 2018

IAPP Training Classes
Privacy Ref is proud to announce that we are an official training partner of the IAPP. You now have the opportunity to learn from one of our knowledgeable privacy professionals using the most respected training content in the industry. The robust interactive training offered, aids in the understanding of critical privacy concepts. The contents of the courses are integral to obtaining your privacy certifications and to educate your new team. Learn more here.

Latest Blog Posts

July 9, 2018

Don’t Forget Basic Communication
Most of us have been wrapped up in GDPR preparations for several months. While there are many organizations "not quite there yet", many others have made great strides towards compliance. As we continue to do assessments for clients, both GDPR and General Privacy,  I have been surprised at the frequency of the gap between a privacy official describing their organization's data subjects, information collected, and business processes  with the reality of what is happening. Continue reading this post...

California – The Next GDPR?
Starting January 1, 2020, if you are a for-profit company doing business in California, you may have new data privacy compliance obligations. Specifically, California just enacted the California Consumer Privacy Act of 2018 (the country’s strictest data privacy law to date), placing new privacy mandates on certain businesses with respect to the personal information of consumers (defined as natural persons who are California residents). Many aspects of the new law smack of EU-GDPR influences, such as a new and improved (in other words, broader) definition of personal information and the inclusion of guaranteed consumer rights with respect to such personal information. If your business is already in compliance with the EU’s GDPR, the California law will be nothing new to you. For other businesses, however, you have 18 months to get with the program. Continue reading this post...

Other Recent Posts