Skip to content
Incident Response

Ransomware Crisis Communication: The 72-Hour Plan for Management

|
|
7 min read

In the first 72 hours after a ransomware attack, what you say matters more than what IT does. You can get the tech right and still stumble on how you talk about it. Then you lose trust, risk fines, and face damage claims later. This playbook is for management, not for IT.

Who Wants to Talk to You After Hour Zero

In the first hours, all of these groups will reach out to you, whether you like it or not:

  • Staff: what should we tell customers? Can we still work? Who is liable?
  • Customers: why is your email down? When will it work again? Is our data affected?
  • Regulators: BSI (NIS-2), the data protection authority (GDPR), and maybe BaFin or a sector body.
  • Insurer: first notice, damage review, and consent for forensics.
  • Media and social networks: rumors spread faster than facts.
  • Maybe the attacker too, with a ransom demand and a threat to publish your data.

Hour 0 – 6: What Management Does in Person

  1. Set up a crisis team: management, the CISO or IT lead, the DPO, legal counsel, and an outside IR partner. Meet in person or over an E2E-encrypted channel.
  2. Key point: do not talk over the hacked systems. Use your own emergency phones and a separate mail account. Best of all is a Matrix/Jitsi channel that the attack did not touch.
  3. Bring in forensics: securing evidence starts now. Don't restart anything, and don't "quickly fix" anything. Take disk images first.
  4. Tell the insurer: many policies need a first notice within 24 h. If you are late, you risk losing your cover.
  5. First message to staff: short, factual, no guessing. "We have a security incident. We are looking into it and will keep you posted. Please don't talk to outsiders beyond the approved messages."

Hour 6 – 24: Talking to Regulators

GDPR Art. 33 requires you to notify the supervisory authority within 72 h once you suspect a personal data breach. NIS-2 Art. 23 requires an early warning to the authority in charge within 24 h. The clock starts once the suspicion of a major incident firms up.

Keep in mind: an early warning is not a final report. It only says: "We have what looks like a major incident. Here is what we know so far." You can update it later. A late report is far worse than an incomplete one.

Hour 24 – 48: Talking to the Outside World

By now at the latest, you need written message templates. Management, legal, and the DPO must approve them:

  • Customer email: what happened (in one sentence) and what it means for them. Which data may be affected, what you are doing, where things stand, and how they can reach you.
  • FAQ on the website: easy to find, updated often, with a timestamp.
  • Status page: shows which services are back. Host it outside if your own site is hit.
  • Rules for staff: who may say what to outsiders? In most cases, only the named spokesperson. Everyone else refers questions to that person.

Hour 48 – 72: Media and the Detailed Regulator Report

If the media has heard about it, or the attacker goes public, issue a press release before you are asked. Don't wait to react. Say what happened, what you are doing, what you don't know yet, and when the next update comes. Avoid guessing.

Regulators expect a more detailed interim report by the end of the 72 h. With an integrated platform, you can deliver the audit trail, asset list, incident rating, and affected data types in hours, not days.

What Management Avoids in Every Statement

  • "We were the victim of a hacker attack": this is passive and defensive. It sounds like you are playing it down. Say instead: "On day X we detected a security incident."
  • "No data is affected", when you don't know that yet. Taking it back later destroys trust.
  • Blaming staff or suppliers: legally risky and harmful to your image.
  • Talking about the ransom in public: talks with the attacker belong in a separate, private channel with forensics and legal.

Prepare Now, Not During the Incident

  • Crisis message templates: staff mail, customer mail, press release, and FAQ. Approved in advance by management, legal, and the DPO.
  • Out-of-band channel: one that the attack can't reach. Ideally a Matrix server on separate infrastructure.
  • Status page hosted outside: on Hetzner, Cloudflare, or similar, not in your own data center.
  • Forensics partner contract: a retainer with a fixed response time. Don't negotiate during the incident.
  • Yearly tabletop exercise: management runs it in person. At least once, bring in a crisis PR advisor.
  • D&O and cyber policy: keep the emergency numbers on management's phones.

Conclusion

In the first 72 hours of a ransomware attack, communication is thin ice. One wrong step and it breaks. Management needs a written 72 h plan, templates, an out-of-band channel, and a tabletop exercise. If all of this is in place before the incident, you can act when it happens. If you improvise during the incident, you risk fines, trust, and lawsuits.