
07.09.2026 crisis-communicationransomwareincident-responsestakeholder-management
For years, crisis communication after a cyberattack followed a reliable sequence: detection, internal escalation, initial forensic assessment, legal review, and only then a controlled, jointly agreed external statement. That model has broken down in 2026. Brett Callow, Managing Director for cybersecurity and data privacy communications at FTI Consulting, puts it bluntly: threat actors now contact business partners, customers and media directly, often before victims detect an attack. That strips the victim organization of the one thing crisis communication traditionally relied on: control over the timing of the first public statement.
Callow describes the consequence without ambiguity: the ransomware landscape has shed the predictability that once made incident response manageable, because threat actors now contact business partners, customers and media directly, often before victims detect an attack. That very unpredictability is what makes pre-incident planning non-negotiable. Organizations that have not locked down communications plans, identified response teams and established clear internal protocols before an attack hits are not ready, Callow says.
This aligns with figures from Sygnia’s 2026 CISO Survey: 90% of organizations would struggle to coordinate stakeholders during a significant incident, and 75% say delays or uncertainty around legal and communications involvement slow down decision-making. Sygnia’s prescribed fix isn’t a new plan but targeted additions to existing ones — specifically cross-functional tabletop exercises that include legal and communications alongside security, and metrics tracked against containment outcomes instead of policy review dates.
A recent ScienceDirect paper on crisis communication in cyber incidents sharpens the picture further: unlike most crises where organizations communicate once the disruptive event has passed, in cyber crises they must communicate while the crisis itself is still unfolding, simultaneously engaged in internal processes such as negotiations or ongoing forensic investigations. Any public statement can therefore influence ongoing negotiations or the forensic evidence trail — a conflict of interest classic PR crisis manuals were never designed to handle.
The situation is further complicated by a new type of scam. A group calling itself “Ransom Busters” emails ransomware victims offering, for a fee, to delete stolen data or supply decryption keys — and according to GRIT researchers, these communications can reach victims even before the original ransomware operators publicly identify the victim or disclose the attack. For an IR team, this means that while internal triage is still underway, a second, unverifiable voice claiming to speak for the attackers may already be making demands with its own credibility agenda. GuidePoint forensic analysts found identical attacker fingerprints across two investigated cases, supporting the assessment that the sender is one of the attackers behind those intrusions themselves running the confusing secondary communication channel.
CISA’s advisory on Medusa ransomware shows this pattern structurally embedded in the group’s operating model: if the victim does not respond to the ransom note, Medusa actors contact victims directly by phone or email — in parallel with a public leak site running a countdown. The ongoing fragmentation of the ransomware ecosystem into more, smaller groups only amplifies this dynamic, as more actors compete simultaneously for attention and leverage.
For IR and communications teams, this yields concrete requirements. First, holding statements for different scenarios — encryption, exfiltration-only, third-party compromise — need to be legally pre-cleared and ready to deploy, not drafted mid-crisis. Second, organizations need a documented, rehearsed escalation chain that activates security, legal, and communications simultaneously rather than sequentially. Third, dark web and leak-site monitoring belongs in the standard toolkit, so a company doesn’t learn about its own incident from a journalist’s call or a customer’s inquiry. Fourth, every communications plan should explicitly address the scenario of an unverified third party claiming to speak on the attackers’ behalf — with a clear internal rule never to pay or engage such contacts without forensic verification.
The core lesson: crisis communication is no longer an afterthought to technical incident response but a parallel, equally prioritized workstream running from minute one — because whoever speaks first controls the narrative.
← Back to overview