Learning Objectives:

  • Understand the principles of crisis communication in cyber incident response.

  • Develop communication strategies for internal and external stakeholders.

  • Coordinate with regulators and law enforcement during cyber incidents.

  • Maintain public trust through transparent communication.

5.1 Principles of Crisis Communication

Crisis communication is essential for maintaining trust and confidence during a cyber incident. The ECB’s TITUS crisis communication exercise was designed to “test the cohesiveness of the response of an important part of the financial market” and to “identify areas for further improvement” . The exercise involved more than 300 staff members and technical experts from all participating institutions .

The FSB’s framework identifies “coordination and communication” as a key component of incident response, which “coordinates with stakeholders to maintain good cyber-situational awareness and enhances the cyber-resilience of the ecosystem” .

Key Principles:

  • Timeliness: Communicate promptly.

  • Accuracy: Communicate accurate information.

  • Transparency: Communicate transparently.

  • Consistency: Communicate consistently.

  • Reassurance: Reassure stakeholders.

5.2 Communication Strategies

The ECB’s TITUS exercise highlighted the importance of “timeliness of communication flows” and “aligning crisis communication frameworks” . The exercise aimed to “verify the compatibility of stakeholders’ and national crisis management procedures in the context of events with cross-border impacts” .

Key Communication Strategies:

  • Internal Communication: Communicating with internal stakeholders, including employees and management.

  • External Communication: Communicating with external stakeholders, including regulators, law enforcement, and the public.

  • Media Management: Managing media communications.

  • Stakeholder Engagement: Engaging with stakeholders to maintain trust.

5.3 Coordinating with Regulators and Law Enforcement

Coordination with regulators and law enforcement is essential during a cyber incident. The Central Bank of Eswatini’s Guidelines require financial institutions to plan for information-sharing through trusted channels in the event of an incident and to participate actively in information-sharing groups and collectives . The G7 Cyber Expert Group conducts cross-border coordination exercises to strengthen the collective ability of authorities to respond to cyber incidents .

Key Coordination Activities:

  • Regulatory Notification: Notifying regulators of the incident.

  • Law Enforcement Coordination: Coordinating with law enforcement agencies.

  • Information Sharing: Sharing information with other financial institutions.

  • Cross-Border Coordination: Coordinating with authorities in other jurisdictions.

The G7 2026 Cross-Border Coordination Exercise (CBCE) tested key improvements identified through previous simulations and workshops focused on incident response, recovery, and crisis communication, further advancing collective preparedness . The exercise brought together ministries of finance, central banks, bank supervisors, and market authorities, fostering a unified response .

5.4 Maintaining Public Trust

Transparency is essential for maintaining public trust during a cyber incident. The Central Bank of Eswatini’s Guidelines require financial institutions to determine beforehand which types of information will be shared, with whom, and how information provided to the financial institution will be acted upon . The G7 exercise aimed at “enhancing the collective capacity of authorities to respond to cyber events that could potentially disrupt the provision of critical financial services” .