During a confirmed data breach, technical responders, the corporate communications team and a business unit manager each begin contacting affected customers and a regulator with their own versions of events. The information security manager wants external communications during incidents to be authoritative and consistent. Which arrangement should the incident response plan define to achieve this?
- AA requirement that each affected business unit notify its own customers promptly using the wording it judges most reassuring to its relationships
- BA standing instruction that the technical responders publish factual status updates directly, since they hold the most accurate view of the incident
- CA single approval authority and designated spokesperson channel through which all external incident communications must be cleared before release Correct
- DA rule that no external party is told anything until the forensic investigation has fully closed and every fact is verified
Why A is wrong: Devolving wording to business units feels responsive and customer-friendly, but it produces conflicting, unreviewed messages that create legal exposure and undermine the credibility of the organisation's response.
Why B is wrong: Responders do hold the freshest technical detail, but raw technical updates released without legal and communications review can disclose unconfirmed facts and create obligations the organisation cannot yet meet.
Why C is correct: Routing every external message through one approval authority and spokesperson keeps notifications consistent, legally reviewed and aligned with the organisation's position, which is the governance control for incident communications.
Why D is wrong: Waiting for full certainty seems prudent and avoids errors, but it ignores mandatory notification deadlines and stakeholder duties that often require communication well before an investigation closes.