How CISOs should handle cybersecurity breaches

Chief information security officers often say the hardest part of a cybersecurity incident isn’t stopping the attack. It’s deciding when to tell customers what happened—and how much to share while details remain unclear.
Disclosing too early risks inaccuracies, unnecessary panic, or legal complications. Waiting too long can leave customers without time or information to protect themselves or meet their own reporting requirements. Security leaders emphasize that developing a notification strategy during an active incident is already too late.
Context shapes how—and when—companies disclose
No two organizations face identical risks or obligations. A company processing 500 billion transactions daily, like Zscaler, handles sensitive operational data but doesn’t store customer content. That distinction shapes how its security team approaches communication during a breach. Other factors—industry, jurisdiction, business model, and whether the company is public or private—also determine disclosure timing and content.
Most CISOs agree on three broad priorities, even if they don’t always state them openly: human safety comes first, legal obligations take precedence over contractual ones, and protecting customers matters more than protecting shareholder value.
Related: Quantum tech fuels new economic growth
Five principles for deciding when to notify customers
Security leaders say the focus shouldn’t be on whether to notify but on what customers need to act. In the first 72 hours of an incident, teams often have incomplete data, competing theories, and no clear narrative. Meanwhile, customers are in crisis mode, trying to answer urgent questions: Do we need to act now? Are we at risk? What can we tell our board or regulators?
Customers don’t expect absolute certainty, but they do need usable information. With that in mind, security leaders recommend five principles for disclosure:
- Prepare in advance. Define triggers, decision rights, and escalation paths before an incident. Without this, the loudest voice in the room sets priorities when pressure mounts.
- Prioritize harm reduction. Don’t wait for perfect attribution or root cause. If customers can reduce risk by patching, changing credentials, or adjusting service use, speed outweighs a polished explanation.
- Use legal requirements as a guide. Regulatory obligations, especially across borders, may force earlier disclosures than the business prefers. Legal teams should collaborate in communication, not just control it.
- Don’t make choices for the customer. Different customers have different needs. Provide clear, actionable information and let them decide how to respond.
- Stay disciplined and compassionate. Overconfident statements can cause lasting damage. Lead with verified facts, clear caveats, and consistent updates. Balance professionalism with empathy to reduce confusion and mistrust.
Regulators are now examining these issues more closely. The U.S. Securities and Exchange Commission requires public companies to disclose material cybersecurity incidents within four days of determining their impact. The European Union’s NIS2 directive imposes similar deadlines, with penalties for late or incomplete disclosures. These rules don’t remove ambiguity, but they push companies to plan ahead.
The uncertainty of an incident is inevitable. The only difference is whether a company enters it with a coordinated plan across security, legal, communications, and business teams—or scrambles to create one under pressure.
