If you work in cybersecurity, the past month might have been the best of times – and maybe the worst of times.
It seems like there isn’t a day that goes by without some sort of data breach, no matter your industry. Retail, aviation and even politics have fallen foul of the dreaded “data breach” or “cyber-attack”.
How you respond to a crisis plays a big role in how well you recover financially. Reputation is a bit harder to measure though financials are relatively straightforward. The most recent research points to a share price drop of 35% on average and a 427-day average to recover – if at all.
Those figures are quite something.
I remember doing my first crisis communications course at the UK’s Public Relations and Communications Association (PRCA) about eight years ago. The figures trotted out then were more anecdotal though not dissimilar to the most recent research.
No time to reminisce, let’s cut to the chase with something more interesting.
For me (and I hope for you), interesting is the response structure of two recent breaches in Australia is worth addressing. Specifically, one of the more infamous breaches of the past year – Qantas – and a breach associated with one of the more famous people in Australia – Clive Palmer and his United Australia Party and Trumpet of Patriots party.
Both Qantas and the Palmer organisations fell afoul of nefarious cyber actors this year, and alerted people it had happened and that data had been compromised.
But here’s the rub. One of the two groups acted with empathy and understanding, set up a free help hotline and apologised unreservedly for what it saw as a breach of trust and confidence – as well as data.
The other did not. I’ll leave you to join the lines as to who did what.
You’re in a crisis – what you should do now?
The underlying theory encompasses three parts: preparation, response and recovery. We’ll focus on “response” here.
Under that subheading, Transparency and Honesty, Speed and Accuracy, Empathy and Concern, and Media Management are key.
Qantas demonstrated, in my mind, all of the above. The airline said how it happened, it contacted people within 48 to 72 hours, customer emails were thoughtful and plentiful and – well – media management-wise it did well, too; selective but open.
If we’re being nitpicky about it, the speed of the CEO doing a first broadcast interview took perhaps a day or two longer than many would have expected and liked – Europe does have the internet after all. If we can get a client to do a broadcast piece with the ABC, commenting on the breach and what consumers can and should be wary of on the same day the news has broken, then I would imagine Qantas could turn the wheels faster to make a similar thing happen.
But I wasn’t on the Qantas team internally and I feel for them because they probably didn’t sleep for a week.
Considering this, Qantas’s speed and accuracy of customer communications were commendable. Emails went out alerting people, further emails were personalised with the specific data that was breached and apologies were abundant.
The standout lines for me, which were good’uns in terms of empathy, were “we sincerely apologise for this incident and recognise the uncertainty it has caused. Our customers trust us with their personal information, and we take that responsibility seriously” and “we know that data breaches can feel deeply personal and understand the genuine concern this creates for our customers. Right now, we’re focused on providing the answers and transparency they deserve”.
Objectively, these are great; they are empathetic and acknowledge fault without being over the top contrite. We can even see how getting this right means that fiscal recovery is entirely possible.
Qantas’ share price on 1 July was $10.76, dropping to $10.52 on 2 July when the hack was revealed, but recovering and gaining consistently up to 18 July, when it cracked $11.
I’m no stockbroker nor economist (I can barely add 2 and 3) but the public’s memory isn’t that short so I’m absolutely putting that down to the solid, caring and clear communications from the airline.
Of course, a class action is being mooted, complaints abound and various other things are in the wild – like using ChatGPT to format the mass apology – which is moving that share price down again though we can look beyond that.
The classic strategy stuck – and stuck remarkably well.
You’re in a crisis – what you should not do
Your first major mistake would be to ignore the important principles of transparency, empathy and speed. You do that at your peril.
For instance, you wait for more than a month to tell people and then, in the same breath, tell them you won’t be contacting them individually to clarify what data of theirs has been potentially compromised because it has been deemed “impracticable”.
In any crisis scenario this is absolutely the opposite of what you should consider. In both cybersecurity and crisis communications, it is pretty far from best practice.
This is the statement that was issued by Clive Palmer’s UAP. It lacks many aspects of Crisis Management 101. If you aren’t interested in the minutiae of it all, then just know that this made our team cringe when we read the statement.
And to the consequences.
It’s a strange one – the UAP is no longer a registered political party, and ToP has no seats. In any case, it doesn’t seem like that much will happen. Whether the honesty of reporting the breach to the OAIC is ever called into question and taken further may be worth keeping an eye on, perhaps. Will there be a fine? Will there be any further action from government organisations? Aside from the ridicule, you couldn’t say what was going to happen.
So you haven’t had a crisis
Lucky you, try to keep it that way.
But if you haven’t embraced that first stage of crisis communications – preparation – then at the very least you may want to partner with a team of experts to help you formulate a plan and materials so that you can weather the initial storm.
I know some people, if you’d like.