# Incident Communications Templates

**Obfuscation Hub Toolkit — starter template (Release 0.1)**

> Adapt to your organization before relying on these. They are educational
> starting points — not legal advice. Anything leaving the organization about
> data exposure must be reviewed by counsel and, where applicable, your
> cyber-insurance carrier's approved process **before** it is sent.

---

## Ground rules (set these before an incident)

- **One spokesperson.** Name: [name]. Everyone else redirects questions.
- **Approval rule for external words:** [e.g., "Counsel + CEO sign-off, no exceptions"].
- **Internal cadence:** updates every [60/120] minutes during active response,
  even when the update is "no change." Silence breeds rumor.
- **Say what you know, mark what you don't.** Early overstatement ("no data was
  accessed") is the sentence most often retracted later. Prefer "we have no
  evidence at this time of X; investigation continues."
- **Never speculate about attribution, method, or blame** in written updates.

---

## 1. Internal status update (recurring)

> Audience: response team + informed leadership. Channel: [out-of-band channel].

**Subject:** [INC-###] Status update #[n] — [short incident name] — [time + timezone]

- **Status:** [Investigating / Contained / Recovering / Closed]
- **What we know (facts only):** [2–4 bullets, each traceable to evidence]
- **What we are doing now:** [current actions + owners]
- **What has changed since last update:** [or "No change."]
- **Business impact right now:** [systems/processes affected, workarounds]
- **Next update:** [time]. Questions to [spokesperson].

*Do not include:* guesses about cause, blame, or legal conclusions.

## 2. Executive brief (on request or at escalation)

> Audience: leadership/board. Length: half a page. Lead with decisions, not chronology.

**Subject:** [INC-###] Executive brief — [short incident name]

- **Bottom line:** [One sentence: what happened, current status, business impact.]
- **Decisions needed from you:** [e.g., approve vendor cutoff despite payroll
  timing / approve external notification / none at this time]
- **Risk picture:** [data exposure status in one honest sentence; regulatory or
  contractual clocks that may be running]
- **Response status:** [contained? recovery ETA? who is engaged — IR firm,
  counsel, insurer]
- **Cost/impact so far:** [downtime, hours, known expenses]
- **Next brief:** [time]

## 3. External holding statement (customer/partner facing)

> Use when questions arrive before investigation completes. **Counsel review
> required.** Keep it to what is true today; commit only to a follow-up.

We are aware of [a service disruption / a security matter] affecting
[service/system]. We took steps immediately upon discovery to [contain the
issue / protect customer data / restore service], and an investigation is
underway [with outside specialists, if true]. At this time we have no evidence
that [customer data was accessed] — if that changes, we will notify affected
[customers/partners] directly and promptly. We expect to provide a further
update by [date/time]. Questions: [contact channel].

*Remove any clause you cannot stand behind under oath. Fill nothing in by
reflex — every bracket is a decision.*

## 4. Vendor notification (when YOUR incident may affect them, or theirs affects you)

**Subject:** Security notification regarding [shared service/integration] — [INC-###]

We are investigating a security incident that may involve [the integration/
credentials/data path] between our organizations. As a precaution we have
[rotated keys / suspended the integration / reset accounts]. We ask that you:
[preserve relevant logs from (date range) / confirm no anomalous activity /
provide your security contact]. Our contact for this matter: [name, channel].
We will share relevant findings as the investigation allows.

## 5. Closure / all-clear (internal, then external where owed)

**Subject:** [INC-###] Closed — [short incident name]

- **Summary:** [What happened, in three factual sentences.]
- **Impact:** [Final assessment — systems, duration, data status.]
- **What we changed:** [Controls/process improvements, without oversharing
  security detail externally.]
- **Evidence and log location:** [internal only — path/retention]
- **Post-incident review:** scheduled [date]; blameless; notes to [location].

External closure notes should thank recipients for patience, state final
impact honestly, and describe improvements at the "we strengthened
authentication controls" level of detail — not configurations.

---

## Notification-obligation quick sheet (fill in annually)

| Obligation | Trigger | Clock | Owner |
| --- | --- | --- | --- |
| Cyber-insurance carrier | [per policy] | [e.g., "without undue delay"] | [name] |
| Customer contracts with breach clauses | [list customers/clauses] | [e.g., 48–72h] | [name] |
| Regulators (if applicable) | [e.g., state breach laws, sector rules] | [varies] | [counsel] |
| Key vendors / MSP | [shared-system involvement] | [reasonable promptness] | [name] |

---

*Source: Obfuscation Hub Toolkit. Pairs with the incident response checklist in
the same kit. Verify current authoritative guidance at cisa.gov and with your
counsel and carrier.*
