Is a cyber-attack necessarily damaging to an organization’s reputation and the source of negative publicity? According to a joint study by the Center for Strategic Studies (CSIS) and McAfee published in 2020, Latin America and the Caribbean has become a new frontier for cyber-attacks and crime at an estimated cost of around US$90 billion per year. In the United Kingdom, there has been a 62 per cent increase in cyber-attacks on organizations since 2020.
How should organizations that have been victims of cyber attacks respond to their stakeholders? The traditional practice has been to conceal these incidents as best as possible from clients and stakeholders to protect the perceived reputation of the organization. But the CSIS/McAfee study, titled The Hidden Costs of Cyber-crime, posits that reputation is largely a matter of the perception by consumers of negligence on the part of an organization to protect their private data. This can result in consumers ending their relationship with an organization or business. This view is supported by a 2017 PWC study which found that 87 per cent of consumers were likely to change suppliers because their handling of customers’ data did not engender their trust.
Yet, “This is not exclusively a matter of preventing an incident. How an organization responds and how open and forthcoming about the situation they are can go a long way in maintaining consumer trust,” the CSIS/McAfee study points out. It continues: “Transparency and informing customers when their financial or personal data may have been compromised are essential to maintain trust and manage a crisis.”
How an organization responds and how open and forthcoming about the situation they are can go a long way in maintaining consumer trust
Cyber-security Measures
As the incidence of cyber-attack rises, consumers expect businesses to implement effective cyber-security measures like the ISO 27001 standards. However, as cyber-attacks become common place, consumers also expect organizations to come clean with them so they can quickly take steps to minimize any fallout in the disclosure of their sensitive information. But this has not been the case in most organizations. The CSIS/McAfee study finds that “only 26 per cent of organizations that had security incidents in 2019 shared information about the most severe incident with clients or customers.”
Even less organizations (24 per cent in the US) reported severe cyber security breaches to the media, while 22 per cent of the organizations surveyed did not report the incidents to the media. “This was well in line with the average across regions. Communicating with clients and customers does not appear to be a priority in most countries…only 345 out of 1,332 companies informed their clients that they had experienced a cyber incident,” according to the CSIS/McAfee study.
In a case in Jamaica, with which I am familiar, The Gleaner newspaper carried a front-page story about a cyber-attack on an educational institution. The organization did not deny the attack occurred; and admitted, furthermore, that some administrative processes were compromised by the attack.
Consumers expect organizations to come clean with them so they can quickly take steps to minimize any fallout in the disclosure of their sensitive information.
Internally, the organization ramped up communication. This began with senior management informing the Director of Corporate Communication about the incident and maintaining an open communication channel between him and the Chief Information Officer. The protocol was established that Corporate Communication (Corp Com) was responsible for informing stakeholders and the media. Of course, Corp Com had to decode the Information Technology (IT) jargon to effectively explain the situation to stakeholders.
Trustworthy Information
Questions and inquiries came in fast and furious from various stakeholders. The concerns were collated, and the responses shared in the form of regular bulletins. Care was taken to update internal stakeholders first before the information was disseminated to the media, recognizing that information released internally could be shared simultaneously with external publics. The point being made is that the information had to be consistent to engender trust by the internal and external publics.
A cyber-attack presents its own unique communication challenges. For example, other IT problems are likely to be attributed to the cyber-security breach. Corp Com quickly and clearly pointed out the distinction. Another unique challenge was that the main source of communication -the office network and systems- was compromised and, therefore, could not be a channel of communication. This requires the identification of alternative communication channels when formulating the crisis communication plan for a cyber-attack.
In the case of this educational institution, communication with employees was facilitated through the Internet external to the organization –one of the positive side effects of the COVID-19 pandemic, as most employees were working remotely and using their home WIFI services.
Another challenge was to avoid disseminating critical and confidential information that could endanger the integrity of the IT network and systems. Some of the inquiries from stakeholders involved that aspect but no information was disclosed.
Leave a Reply
You must be logged in to post a comment.