5.2.4. Incident Response Communications
💡 First Principle: Waiting for complete certainty before communicating about an incident routinely costs an organization its regulatory notification window and its stakeholders' trust — staged, honest communication under uncertainty beats silence followed by a late, complete answer.
Regulatory breach notification requirements typically run on fixed clocks (commonly 72 hours from awareness under regimes like GDPR) that do not pause for investigation to finish. Effective incident communication issues staged updates — "we are aware of an issue and actively investigating; here is what we currently know and don't yet know" — to regulators, affected customers, and internal stakeholders, rather than delaying until the full scope is confirmed, which often breaches the notification deadline entirely.
⚠️ Exam Trap: Communication is sometimes delayed until the full scope of an incident is known, out of fear of communicating incomplete information. The correct answer favors staged, honest communication that meets regulatory timelines, since waiting for full certainty often breaches disclosure deadlines.
Reflection Question: Forty-eight hours into a suspected breach with a 72-hour notification requirement, your team still doesn't have a complete picture of what data was accessed. Should you wait for certainty before notifying, or communicate what's currently known? What does your answer weigh against what?