What information should be disclosed during an investigation? How should one communicate with clients? As an independent consultant in cybersecurity and crisis management, Asmaa Nesbane shares her approach to effective communication following a data breach.
Scientists confirm: This is the most effective way to get your cat’s attention, according to new research
Elderly Couple Refuses Reserved Seats—Viral Train Standoff Sparks Fiery Debate on Courtesy
- How should a company approach the initial hours after a data breach is discovered? What should their first communication reflex be?
- Is it wise to communicate with clients before having all the facts, or is it better to wait until the full scope is known, even if it may seem less responsive?
- What details should be shared or withheld while the technical investigation is ongoing?
- How should one speak to affected clients without using technical jargon or sounding alarmist? Do you have any advice to share?
- According to you, who is the most appropriate person to speak out when a data breach is confirmed?
- What are the most common communication mistakes you’ve observed following a data breach?
- Beyond the initial press release, how can trust be sustainably restored with clients in the weeks following? What actions should be prioritized, and which should be avoided, in your opinion?
From Intermarché to the DGFiP and state digital infrastructures, France saw a spike in data breaches during the summer of 2026, raising consistent concerns about communication strategies. Should one wait to understand the full extent of an incident before speaking to clients, or is it better to communicate established facts even amid uncertainty? To answer these, we spoke with Asmaa Nesbane, an independent consultant specializing in cybersecurity, crisis management, and resilience. She outlines for BDM the best practices and pitfalls to avoid after discovering a data breach.
Why You Should Never Reheat These Foods in the Microwave – The Hidden Dangers Experts Warn About
I tried the top 5 guard dogs—here’s what makes these breeds the ultimate protectors
Asmaa Nesbane, Independent Cybersecurity Consultant
As an independent consultant, Asmaa Nesbane provides guidance on cybersecurity, crisis management, and resilience. She assists organizations in preparing for cyber crises, business continuity, and awareness, and also contributes to higher education.
How should a company handle the initial hours after discovering a data breach? What should the first communication reflex be?
Communication should be integrated into the crisis management team.

Simultaneously, internal communication should provide clear instructions:
- Emphasize confidentiality,
- Specify that only authorized personnel may communicate externally,
- State that employees will be updated as information becomes available.
Lastly, external communication must differentiate between confirmed information and details that are still under verification.
Is it advisable to communicate with clients before having all the facts, or should one wait until the full scope of the incident is clear, even at the risk of seeming unresponsive?
One should neither delay until all facts are known nor share unverified information.
The company can initially communicate the confirmed details, clarify that investigations are ongoing, and update information as it becomes available.
It is better to adopt a “we do not know yet” stance than to provide information that may later need to be corrected.
What information should be shared or withheld while the technical investigation is ongoing?
Confirmed facts, the consequences for those affected, and protective measures should be shared.
Conversely, speculations about the source, perpetrator, or the scope of the attack, as well as technical details that could jeopardize the investigation, should be avoided.
How to communicate with affected clients without using technical jargon or sounding alarmist? Do you have any advice?
Recommendations should be tailored to the actual situation. For instance, there’s no need to request a password change if the data compromised does not include login credentials.

The tone should be factual, neither downplaying nor exaggerating the situation.
In your opinion, who is the most suited to address the public when a data breach is confirmed?
The choice depends on the severity and the message. The company leader, cybersecurity head, or DPO (Data Protection Officer) might be appropriate depending on the context.
What’s crucial is that all communication is coordinated by the crisis management team and that a clear spokesperson is designated.
What are the most frequent communication mistakes observed following a data breach?
Quickly understating the scope is a common mistake: initially announcing a limited impact, only to have to correct the statement days later.
Extended silence is also risky, especially if clients learn about the incident through the media. Additionally, using complex jargon and making guarantees that cannot be ensured should be avoided.
An openly incomplete disclosure is better than a false assurance.
Beyond the initial statement, how can trust with clients be sustainably restored in the following weeks? What actions should be prioritized, and which should be avoided, according to you?
Trust is not rebuilt with a single statement, but through subsequent actions.
It’s essential to continue providing information, explain corrective measures, and maintain a point of contact. Promises like “this will not happen again” should be avoided.
Instead, the company should demonstrate that it has learned from the incident and is better prepared for the future.
Similar Posts
- Top 5 Cybersecurity Courses: Boost Your Expertise Now!
- Received a Strange Email from Instagram? Don’t Worry, Your Account is Safe!
- Master Cybersecurity Skills: Top 5 Courses to Boost Your Expertise!
- Telegram Founder Pavel Durov Targeted in Russian “Terrorism” Probe: Details Inside!
- Tech Salary Guide 2026: Discover France’s Highest-Paying Digital Jobs!

Jordan Park writes in-depth reviews and editorial opinion pieces for Touch Reviews. With a background in UI/UX design, Jordan offers a unique perspective on device usability and user experience across smartphones, tablets, and mobile software.