What to Do in the First 72 Hours of a Data Breach Crisis
This marketing crisis playbook provides a concrete hour-by-hour plan for the first three days after a data breach, helping marketing leaders minimize customer trust erosion with pre-built messaging templates and channel sequencing grounded in real brand responses.
Hour zero is not when marketing starts “thinking about messaging.” It is when the company decides whether customers will hear one clear version of events or five half-compatible ones from a banner, an account manager, a support macro, a CEO note, and a reporter’s call.
A marketing strategy for data breach crisis work has one job in the first 72 hours: reduce uncertainty for the people who must act. Customers need to know what happened, whether they are affected, what to do next, and when the company will update them. Employees need the same source of truth before they answer tickets, sales calls, partner questions, and social comments. Marketing does not determine the forensic facts. Marketing owns the sequencing, message tiers, channel discipline, and update cadence once facts are confirmed enough to communicate.

| Window | Marketing lead action | Do not move forward until |
|---|---|---|
| Before breach | Prepare roles, templates, approval path, status-page shell, support macros, customer segments, and agency/legal contacts. | Every owner knows who can approve what after hours. |
| Hour 0-6 | Open the command center, confirm the working facts with security and legal, freeze speculative messaging, and create one source of truth. | The team has a written fact log, named spokesperson, and next update time. |
| Hour 6-12 | Map affected audiences, draft internal and external message tiers, and secure legal review on holding statements. | Support, sales, executives, and regional leads have aligned language before customers receive email. |
| Hour 12-24 | Send initial affected-customer notification when confirmed enough, publish a dedicated webpage, activate social monitoring, and brief frontline teams. | Every public channel points back to the same update source. |
| Day 2 | Issue remediation progress, launch support services where appropriate, update FAQs, and measure contact-center pressure. | Customers can see what has changed since the first notice. |
| Day 3+ | Move into a sustained cadence: scheduled updates, executive accountability, customer enablement, and longer-term trust repair. | Emergency response has become a controlled operating rhythm. |
Before the Breach: Build the Assets You Will Not Have Time to Invent
The worst time to decide who owns the breach webpage is the night the breach webpage is needed. Preparation is not a binder full of brand values. It is a short list of assets that keep the first day from becoming a drafting committee.
- A named crisis communications lead with backup coverage for nights, weekends, and holidays.
- A single-source-of-truth document that records confirmed facts, unknowns, approved language, audience impact, owners, and next update time.
- Pre-approved holding statements for employees, customers, partners, investors, media, and social channels.
- A status-page or dedicated-webpage template that can publish quickly without waiting for a redesign.
- Support macros, sales talk tracks, customer-success escalation rules, and an internal FAQ.
- A legal and security review path with named approvers and maximum response times.
The Federal Trade Commission’s data breach response guidance tells businesses to designate a single point person for releasing information and to create a communications plan for affected audiences before misleading statements spread. [1]
That recommendation sounds obvious until 11 people are editing three drafts in separate docs. The single point person is not there to slow the company down. She is there to stop unauthorized certainty, duplicate promises, and “quick clarifications” that later need to be corrected.
There is also a financial argument for rehearsal, as long as marketing does not overclaim it. IBM’s 2025 Cost of a Data Breach Report found that organizations with incident response plans saved $2.66 million per breach, while AI and automation saved $1.9 million and reduced detection time from 241 days to 51 days. [2]
That $2.66 million is not a “good comms saves millions” proof point. It includes technical response, security operations, legal work, and other incident-response capabilities. It still matters for marketing leaders because communications is one of the functions that either benefits from a rehearsed response or turns the incident room into a second incident.
Hour 0-6: Open the Command Center and Lock the Truth Source
The first six hours are for control, not performance. Marketing should not publish a clever apology, reassure customers beyond the evidence, or ask legal to bless a paragraph that security has not verified. The useful move is to create the operating room where facts can enter cleanly and leave consistently.

The first working document should be brutally plain:
| Field | What belongs there |
|---|---|
| Confirmed facts | Only facts security, forensics, legal, or executive incident command have cleared. |
| Known unknowns | Questions customers will ask that the company cannot yet answer. |
| Audience impact | Which customer, employee, partner, or public groups may be affected. |
| Approved language | Exact phrasing that can be used in email, support, sales, web, and social. |
| Do-not-say list | Claims that sound comforting but are not yet established. |
| Next update | Time, owner, and channel for the next internal and external update. |
The command center needs security, legal, customer support, customer success, sales, comms, demand gen, web, social, and executive representation. That does not mean everyone writes. It means each team has someone who can say, “If we send this email at 5 p.m., here is what will happen to tickets, renewals, partner escalations, and paid campaigns.”
Marketing should immediately pause or review automated campaigns that could collide with the breach message: nurture emails, promotional banners, retargeting ads, lifecycle pushes, webinar reminders, customer newsletters, and scheduled social posts. Nothing says “we are coordinating carefully” like a breach notice followed 20 minutes later by a cheery upsell email.
The First Holding Statement
A holding statement is not a substitute for customer notification. It is the bridge between discovery and confirmed customer-specific details. It should say what is known, what is not known, what the company is doing, and when the next update will arrive.
We are investigating a security incident involving [system/product/service]. Our security team is working with [internal/external experts, if confirmed] to determine what happened and whether customer data was affected.
At this time, we have confirmed [confirmed fact]. We have not yet confirmed [unknown that matters to customers].
We will provide the next update by [time/time zone] at [dedicated page or channel]. If we determine that your account or data was affected, we will contact you directly with the steps you should take.The sentence “we do not know yet” is acceptable if the next sentence gives customers a time and place to look. It is not acceptable if it leaves support to absorb the uncertainty without an answer path.
Hour 6-12: Map Audiences Before Drafting the Big Email
Most messy breach communications are not caused by bad writers. They are caused by one message trying to serve too many audiences. A customer whose payment data may be exposed, an enterprise admin whose users may be affected, an employee answering calls, and a journalist asking for confirmation do not need the same level of detail at the same moment.

| Audience | First need | Primary channel | Owner |
|---|---|---|---|
| Employees | What happened, what they can say, what they must not speculate about. | Internal memo, Slack/Teams post, manager cascade. | Comms with HR and legal. |
| Support and customer success | Macros, escalation rules, affected-account lookup process, support-service details. | Help desk, enablement doc, live briefing. | Support leadership with comms. |
| Sales and account teams | Account-specific language, renewal guidance, executive escalation path. | Sales enablement hub, live standup. | Revenue leadership with comms. |
| Affected customers | Whether they are affected, what data or service may be involved, what to do next. | Direct email, in-product notice, admin portal. | Marketing/comms with legal and security. |
| Unaffected customers | Whether they need to take action and where to find updates. | Status page, account notice, FAQ. | Marketing/comms. |
| Public, media, and social audiences | Confirmed statement, update location, spokesperson path. | Dedicated webpage, press statement, monitored social replies. | PR/comms. |
Internal first does not mean hiding the breach. It means the people who will receive the first wave of customer reaction should not learn about it from the email they are supposed to explain. Give employees a narrow script, not a novel.
Internal employee guidance:
We are investigating a security incident involving [system/product/service]. Do not speculate about cause, scope, attacker identity, or customer impact.
If a customer asks whether they are affected, use this response: "We are actively investigating and will contact affected customers directly if action is required. The latest confirmed information is available at [URL]."
Escalate questions from regulators, media, large customers, partners, or legal representatives to [owner/channel].
Next internal update: [time/time zone].This is where legal belongs in the room, not downstream as a late-stage blocker. Legal should help prevent overstatement and preserve required notification paths. Marketing should push back when caution turns every sentence into fog. “We are investigating” is fine. “We take security seriously” as the main message is not.
Hour 12-24: Notify, Publish, Monitor, and Stop Channel Drift
The first customer notification is the highest-pressure asset in the first day. It does not need literary polish. It needs a usable sequence: what happened, what information may be involved, what the company has done, what the customer should do, what support is available, and when the next update will arrive.
Buffer’s 2013 response remains useful because it shows the value of moving quickly with plain language. The company emailed all customers within two hours of discovering the incident, its founder communicated directly, and Buffer later said 6.3% of users were affected. [3]
That case is old, and no team should pretend 2013 social-account compromise dynamics map perfectly to every 2026 data incident. The enduring lesson is narrower and more useful: when the company knows enough to warn customers about an action they may need to take, a fast, specific customer email beats waiting for a perfect narrative.
Initial affected-customer notification:
Subject: Important security update about your [Company] account
We are writing to let you know about a security incident involving [system/product/service].
What we know: [confirmed facts only].
Information involved: [data categories confirmed or believed involved, with careful wording].
What we have done: [containment step, password reset, access revocation, investigation support, law enforcement/regulator notification if confirmed].
What you should do now: [specific customer actions].
Support available: [hotline, credit monitoring, help center, dedicated email, account team].
We will update this page by [time/time zone]: [URL]. If we learn that additional action is required, we will contact you directly.Do not send customers to a generic homepage, blog category, or press release archive. Publish a dedicated page that becomes the canonical location for current updates, FAQs, support-service details, and timestamps. Marriott’s 2018 response to a breach affecting 500 million guests is a stronger operational model than many apology-heavy responses because it paired prompt notification with comprehensive details, free credit monitoring, and a dedicated webpage. [4]
Dedicated webpage structure:
Last updated: [date/time/time zone]
Current status: [one-paragraph summary]
Who may be affected: [audience or account group]
Information involved: [confirmed categories]
Actions we have taken: [containment, investigation, support, notification]
What customers should do: [specific steps]
Support options: [hotline/email/credit monitoring/account contact]
Next update: [date/time/time zone]
Previous updates: [reverse chronological log]Once that page is live, every channel should point there. The email links to it. The website banner links to it. Social replies link to it. Support macros link to it. Sales language quotes it. Executives should not improvise a richer version in LinkedIn comments because they are frustrated by the lack of nuance.
Social Response Posture
Social is not where a breach should be investigated in public. It is where the company proves whether it is organized. The social team needs approved replies, escalation triggers, and permission to avoid debates that cannot be resolved in a thread.
Social reply posture:
We are investigating a security incident involving [system/product/service]. The latest confirmed information and customer guidance are available here: [URL]. We will update that page by [time/time zone].
If you believe your account is affected or need account-specific support, please contact [support channel]. For your security, do not share personal or account information in public replies.Escalate posts from journalists, regulators, elected officials, major customers, partners, employees sharing internal information, or users posting screenshots of alleged stolen data. The social team should not be asked to decide in the moment whether a claim changes the company’s legal exposure.
What Delay Teaches, Without Turning It Into a Morality Play
Target and Equifax are often used as shorthand for “bad breach response.” That is too tidy. The more useful lesson is what happens when customers sit in an information vacuum while the story grows around the company.
Target waited days to acknowledge its 2013 breach involving 110 million records, used vague language, and did not lead with upfront customer support; secondary sources citing congressional testimony and legal settlements put direct costs at $148 million. [5]
Equifax delayed disclosure for six weeks after a 2017 breach involving 147 million Social Security numbers, then faced confusing customer messaging, bipartisan hearings, and a settlement exceeding $700 million. [6]
Those numbers do not prove that faster marketing alone would have prevented the financial outcomes. Breach severity, legal exposure, technical failures, and regulatory scrutiny all matter. They do show why vague public language and slow customer guidance make the communications job harder with every passing hour.
Message Tiers: Say Less Publicly, More Directly, and Nothing Speculative
The company should not publish everything it knows everywhere. It should publish the right level of confirmed information to the right audience. Public statements can stay narrower than affected-customer notices. Customer notices can be more actionable than press statements. Support scripts can be more procedural than both.
| Tier | Use when | Content |
|---|---|---|
| Tier 1: Holding statement | Incident confirmed, customer impact not yet confirmed. | Acknowledges investigation, names the affected system if confirmed, gives next update time. |
| Tier 2: Potentially affected customer notice | A customer group may be affected, but account-level confirmation is incomplete. | Explains possible impact, protective steps, support path, and update cadence. |
| Tier 3: Confirmed affected customer notice | Customer impact is confirmed enough to require direct guidance. | Details information involved, required action, remediation, support services, and direct escalation. |
| Tier 4: Public statement | Media, social, partners, or broad customer base need a reference point. | Short confirmed statement with link to canonical update page. |
| Tier 5: Executive message | The company needs senior accountability after operational basics are in place. | Owns responsibility, avoids speculation, reinforces customer support and next steps. |
The trap is treating the CEO note as the center of the response. It is not. The center is the customer action path. An executive message can help after customers know what to do. Before that, it often burns time the support team needed.
Day 2: Move From Notification to Remediation
By day two, the company should be able to show movement. That does not mean the investigation is complete. It means the update should tell customers what has changed since the first notice: containment progress, account protections, service restoration, support options, credit monitoring where appropriate, law-enforcement or regulatory contact if confirmed, and a clearer FAQ.
- Update the dedicated page with a timestamp even if the main change is “no new affected groups confirmed.”
- Send a follow-up email to affected customers only when there is new customer-action information or a meaningful status change.
- Expand support coverage before the next customer email lands, not after call volume spikes.
- Give sales and customer success an account-prioritization list and executive escalation rules.
- Review paid media, lifecycle campaigns, product announcements, webinars, and executive content for tone and timing.
Red Banyan’s 2026 guide frames breach notification as “an opportunity to demonstrate responsibility” and argues that organizations that exceed minimum legal requirements tend to emerge with reputations more intact. [7]
That is the right standard for day two. Minimum compliance may satisfy a filing requirement. It does not necessarily answer the customer’s practical question: “What are you doing for me right now?”
Day-two status-page update:
Last updated: [date/time/time zone]
Since our last update, we have [new confirmed remediation step]. We have [customer support action, such as expanded hotline hours or account protection].
At this time, we have not confirmed [important unknown]. We are continuing to investigate with [internal/external experts, if confirmed].
Customers who [specific condition] should [specific action].
Next update: [date/time/time zone].Status Pages Matter When the Scope Is Still Moving
Change Healthcare’s 2024 incident is a more current reminder that a company may need to communicate long before the full scope is understood. IBM’s crisis communication guide describes a dedicated status webpage with daily-updated restoration timelines, while also noting that weeks passed before the full scope was understood; IBM cites the estimated cost at $2.45 billion. [8]
That is not a clean success story. It is more useful than a clean story. When service disruption, investigation, customer impact, and remediation are all changing at different speeds, a status page prevents every channel from becoming its own rumor market.
A good status page does not pretend the company knows everything. It makes the uncertainty navigable. It shows what changed, what is still being investigated, who should take action, and when the next update will arrive. The timestamp is not decoration. It is the customer’s proof that someone still owns the room.
Day 3 and Beyond: Shift to Cadence, Accountability, and Trust Repair
By the third day, the emergency communications motion should start becoming an operating cadence. If the breach is still active or the scope is still unclear, updates may remain daily. If the immediate customer-action need has stabilized, weekly updates may be enough until resolution. The cadence should be stated publicly and kept.
- Maintain a visible update log with dates, times, and material changes.
- Keep support macros aligned with the latest page before each update goes live.
- Publish deeper customer guidance only after it has been reviewed by security and legal.
- Separate executive accountability from customer instructions so neither weakens the other.
- Document what slowed the first 72 hours while the people involved still remember it.
Employee communication remains part of the strategy after the first notice. Verizon’s 2025 Data Breach Investigations Report found that 82% of breaches involve the human element, which makes employee communications training relevant to prevention as well as response. [9]
For marketing, that means the post-incident content plan should not become reputation gloss. Useful trust-repair content explains what changed: account protections, security practices, customer controls, training, vendor review, reporting improvements, and product changes when confirmed. If the company cannot say what changed yet, it should not publish a victory lap.
Teams building the recovery layer can borrow from adjacent crisis playbooks. A breach that stalls campaigns has a different operating problem than a viral service failure, but the need for controlled sequencing is similar; the current Fairlife ransomware marketing impact case is useful for teams dealing with campaign freeze decisions, while United Airlines' crisis recovery marketing playbook is more relevant once the work shifts from urgent notification to longer-term recovery.
The 72-Hour Rule
The first 72 hours do not have to answer every question. They do have to prove that the company can tell the truth it knows, name the truth it does not know, route customers to the right action, and keep its own teams from contradicting each other.
Marketing cannot investigate the breach. Marketing can keep the response legible. In a crisis, that is not polish. It is infrastructure.
References
- Data Breach Response: A Guide for Business, Federal Trade Commission
- Cost of a Data Breach Report 2025, IBM, 2025
- Buffer has been hacked — here is what's going on, Buffer, 2013
- Marriott Announces Starwood Guest Reservation Database Security Incident, Marriott, 2018
- Target Data Breach, U.S. Congress
- Equifax Data Breach Settlement, Federal Trade Commission
- Data Breach Response Communications Guide, Red Banyan, 2026
- Crisis communication guide, IBM
- 2025 Data Breach Investigations Report, Verizon, 2025
This is a record of what happened and what was tested, not legal advice. Compliance determinations require qualified counsel.