In the event of a data breach, organizations must anticipate media exposure by developing a trusting relationship with the media, training their CISO in communication, and communicating at the right time to control the story of the attack.
Gone are the days when organizations could hide data leaks from the media. “Prepare your crisis communication, because we cannot hide a cyber attack: the information will be found on the web,” even warned Patrick Touak, general commanding COMCYBER-MI, during the 2026 edition of Ready For IT, in front of an audience of DSI and RSSI. The media coverage of data leaks has in fact never been so important, amplified by ever more numerous cyber influencers who sometimes announce data leaks without verifying their authenticity, according to Stéphanie Ledoux, founder of Alcyconie, a company specializing in cyber crisis management.
“Some influencers do not contact the organizations concerned before announcing a data leak. This has been the case for some of our clients. These influencers do not have the same practices as journalists, which many organizations do not know. By acting in this way, these influencers impose their narrative during the cyber crisis. This is very uncomfortable for the organizations attacked, because they then have to react to an imposed version of the facts. We provide preparation for the media coverage of the cyber crisis by taking this into account. new phenomenon. This preparation is based on several stages and the adoption of reflexes to implement before and during the cyber crisis.
Steps to prepare for media pressure before the crisis
“Organizations are afraid of the media coverage of cyberattacks because it can harm their brand and the relationship of trust that they have built over years with their customers, their partners, their employees, and all other stakeholders,” observes Guillaume Granier, director of the strategic communications department at FTI, a consulting company specializing in crisis management. To avoid weakening this relationship of trust, the organization must identify upstream all stakeholders to be informed in the event of a cyber crisis: regulatory authorities such as the CNIL, customers, commercial partners, etc.
Establish a map of the actors to contact
After having identified all of these actors, the organization must develop a map specifying the functions and contact details of each of them. “We recommend such mapping so that the organization does not forget to contact anyone on the day of the crisis,” observes Stéphanie Ledoux. “It is indeed necessary to prevent customers, especially large ones, from learning of a data leak through the media rather than directly through the organization,” says Guillaume Granier. Otherwise, they could see their supplier’s desire to hide the incident, which would risk altering the relationship of trust they have with them.
Maintain media relations
“The organization must make the effort to maintain this relationship of trust with all these stakeholders so that they are attentive when a cyber crisis occurs.” These relationships must include journalists and decision-makers to mobilize to transmit the correct information about the crisis. This is also the opinion of Jaguar’s former CISO, Ashish Shrestha, who was confronted with the high-profile cyberattack that hit the car manufacturer in 2025. “CISOs must develop their community of trust with journalists, press relations, communicators, etc. They must maintain an ongoing relationship with ethical journalists in whom they trust, to transmit them the correct information. This will allow them to reduce the impact of media speculation when a cyber crisis occurs.”
Make the CISO a spokesperson
Finally, according to Guillaume Granier, organizations must train their press officers, where they have them, or their communications teams, in cyber crisis management. However, it is preferable that it is the CISO who is trained in the role of spokesperson, rather than a communicator, according to Stéphanie Ledoux. His mastery of the technical aspects of the incident allows him to respond more precisely to questions from the press, whether general or specialized, during a cyber crisis.
Communication reflexes to adopt during the crisis
When the cyber crisis breaks out, preparation is no longer enough: the organization must implement what has been anticipated and adopt the good reflexes acquired during regular exercises. The biggest difficulty is then to communicate as accurately as possible and at the right time.
Communicate neither too early nor too late
“Faced with a cyber attack, we must neither react too early nor react too late, according to Guillaume Granier. The risk of communicating too early is to give inaccurate information on the type of data leaked, on the number of customers affected, etc. In a cyber attack, we must respect the time of the investigations to find out more about the origins and effects of the attack. We have already seen organizations which communicated too early, then which had to correct what they had communicated. They pay dearly for it in terms of credibility. But, on the other hand, the organization must not communicate too late either because it must control the story of the attack, and not allow itself to be overwhelmed by the media. “We must not leave the chair empty. The sooner the organization communicates, the better,” says Stéphanie Ledoux.
“If the organization does not communicate as soon as possible, it is the influencer who will do so. Then afterward things get out of hand and the organization will have to react to the influencer’s or a journalist’s version of the facts. The organization is not obliged to know everything about the causes and effects of the cyber attack in order to communicate. It can simply explain that it is facing an incident and that it is mobilizing the necessary means to resolve it. When the incident has already been claimed by attackers, we might as well take note of the fact that it exists by explaining that investigations are taking place. This allows us to occupy the field, not to be in the reaction, and to reassure all stakeholders,” advises the cyber crisis professional.
Master the story by recalling the facts
When the organization decides to communicate, “it must respect certain basic rules: recall the facts to control the story, explain the measures put in place to resolve the incident, such as notification to the competent authorities, filing a complaint, or the means mobilized. The organization must also show empathy towards the stakeholders affected by the attack. It must publish a short and effective press release, so that it is distributed on social networks”, affirms Stéphanie Ledoux.
Certain errors must absolutely be avoided: “The organization must not victimize itself or exonerate itself, because this is perceived as lacking in responsibility. Also, we must not beat around the bush by not using certain terms to minimize the situation. For example, some clients sometimes want to describe a cyberattack as a computer failure, hoping that this will be less frightening. We do not recommend this because this can be blamed on the organization afterwards. Some will indeed assert that the organization has not correctly qualified the situation.”
Speak with one voice
Finally, the attacked organization must prescribe instructions to its employees aimed at ensuring that they all adopt the same version of the facts. And for good reason. “Customers who want to be reassured will seek to know more by getting closer to employees with whom they are in contact. However, if everyone provides different elements of language, it will be discordant and will give the image of an organization overwhelmed by the situation,” concludes Stéphanie Ledoux.