Cybersecurity Awareness Blog

Cybersecurity Communication: From Awareness to Crisis Response

Everyone did the cybersecurity training. It’s logged, dated and signed off. Then, eight months later, someone on the service desk approves a login request from a voice that sounds exactly like an IT colleague, but is anything but. That gap, between what you’ve communicated and what people do under pressure, is where most incidents start. Verizon’s 2025 Data Breach Investigations Report puts the human element in 60% of breaches.

Two phases decide how much damage an attack does. The time before it, when alertness that should prevent an incident either holds or quietly erodes. And the first hour after, when your people either know what’s happening and react accordingly, or start guessing. Both are communication challenges.

1. The time before

This half of the job is security awareness: everything you do to keep people ready before the attempt arrives. It’s work with no deadline. No product launch date, no outage, no one downstairs waiting on an answer. So this work competes with everything that’s actually shouting, and it has to win anyway. What it’s protecting is one person’s judgment, on one ordinary afternoon, with someone convincing involved.

Attackers don’t break in, they get let in

Firewalls, encryption and multi-factor authentication all work as designed. They’re only as strong as the person who can be talked around them. Good attackers don’t break your controls, they borrow a colleague’s hands. They work with what makes people good at their jobs: wanting to help, respecting authority, moving fast under pressure.

AI took away the tells. Phishing emails no longer read like bad translations, and a cloned voice on the phone sounds like someone you’ve spoken to 100 times. “Watch out for spelling mistakes” used to be useful advice. Now it’s closer to a liability. Which is why knowing isn’t doing. The question was never whether your people can define phishing. It’s whether they’ll catch it at 4pm on a Friday, with someone impatient on the line and 12 things still open.

Spotting it is only half the skill. Training that stops at recognition leaves people with nothing for the moment they miss one. Someone who’s just clicked needs to know what happens next, and if their first instinct is to say nothing and hope for the best, you’ve lost the hours that matter most.

Then there’s the decay. The week after a session everyone is sharp, and then the workload comes back, procedures turn into muscle memory, and new colleagues join months after the training. The sharpness drains out slowly enough that it never registers. That’s what’s actually wrong with annual training.

Keep training small, and keep it running

Training that holds up is smaller and more frequent. Short, visual, tied to what’s circulating right now instead of a fixed curriculum. It only works if it doesn’t interrupt, so you reach people in the gaps: the screen they walk past on the way to the canteen, the PC they return to after a coffee break, the phone in their pocket between rounds. More visibility doesn’t have to mean more disruption.

Repetition does the real work. Not saying more, but saying the same few things often enough that they’re always on top of mind, tied to what attackers are doing this quarter rather than a definition of phishing from three years ago. It also fixes the June problem. When awareness runs continuously, the colleague who starts halfway through the year gets the same drip as everyone else.

Cover the second half too, not just the spotting. What to do in the 10 minutes after a click: who to call, what to disconnect, and that reporting it fast beats reporting it neatly.

Then measure it. A short knowledge check turns “we communicated it” into “we know which teams it reached, and which one it didn’t.” That’s the difference between an activity and management. The measurement lets you aim: intensity up where the gaps show, down where it’s holding.

Cybersecurity Awareness Netpresenter

2. When an incident hits

Ransomware locks the systems, or one phishing mail turns into a breach. Now it’s getting facts to people fast, while you still only have half of them yourself. You’re not the first source your people hear from. The rumors beat you by minutes, every time. They’ll act on whatever reached them first, whether or not it came from you.

The crisis you can’t see

Prevention is never 100% secure, so the second half of the job starts when something gets through. Two crises run at once. The operational one is easy to spot: systems down, processes stalled, people unable to work. The information crisis is invisible and does just as much damage.

Someone watches a terminal fail mid-shift, or gets a message in the group chat on their phone, and builds an explanation from whatever’s available. This causes a reaction that might be totally inappropriate for the situation. Or the person lacks information and makes the crisis worse by doing exactly the things he or she shouldn’t be doing.

Meanwhile the tools you’d normally reach for are pull channels. Email and intranet wait for someone to come and get the message, which is shaky on a normal Tuesday and broken during an incident that may have taken them down with it. And the people furthest from a mailbox are the ones on the floor, in the truck, or with the customer. They’re also the ones standing in front of your customers when the questions start.

So the message reaches part of the organization and stops. Head office knows, the sales representatives on the road don’t. That gap is where the rumors grow. The reflex fix is to send it to everyone. Now you’ve pulled three sites off their work over an incident affecting one, and spread unease into parts of the business that were fine.

Reach the right people with the right message, fast.

What people need then is narrow and urgent. What’s happening. What’s true right now, even when the honest answer is “we’re still investigating.” And what they should, or shouldn’t, do themselves.

That last one carries more weight than it looks. Don’t reconnect the machine, don’t open anything else from that sender, don’t answer a customer or a journalist with a guess, and here’s the number to call if you think you’re affected. Instructions stop a second incident landing on top of the first, and they give people something to do other than speculate.

Also, speed beats completeness. A short, factual message now is worth more than a full picture an hour from now, because in that hour the rumor gets there first. Sequence matters here as well. Most attention during an incident goes outward, to the press statement, the customer email, the regulator, because those deadlines are legal ones. The internal message should be ready before the external one, or travel alongside it.

Then reach. Everyone who needs it, at a desk or nowhere near one, should get the message: use TV screens, desktops and mobile apps. Even SMS when the network is down. Redundancy means routes that survive your own infrastructure going dark, and the floor hearing it at the same moment as head office. However, if the incident is contained to one site, system or department, that’s where the message goes. The affected team gets instructions, everyone else a short status or nothing. That isn’t tidiness, it’s keeping the rest of the company working while you fix the part that isn’t.

“You can make a crisis worse with poor communication, but you can prevent escalation with good communication. No communication? Then you have a real problem,” says Frank Hoen, founder of Amber Alert Europe and CEO of Netpresenter.

Cybercrisis alert Netpresenter

Two kinds of communication, one platform

These two halves can be covered by one system. This is where the Netpresenter platform comes in.

Netpresenter Smart Campaigns covers the slow half, keeping awareness alive with short messages across PCs, TV screens and mobile phones, plus knowledge checks that show where alertness is real and where it’s assumed.

Netpresenter Alerts covers the fast half. Pre-set scenarios mean you press a button instead of deciding under pressure, messages hit every screen at once with SMS as a fallback, and targeting sends them to the site or department involved rather than to everyone.

Are you prepared?

You can patch a server. You can’t patch a person, and you wouldn’t want to, because the instincts attackers exploit are the same ones that make someone a good colleague. What you can do is keep people sharp over time, and reach exactly the right people fast when it counts. The next threat won’t announce itself. The only real question is whether your people are ready to prevent it, and whether they hear it from you first when it couldn’t be.

Two questions for your team. Would someone catch a convincing request from a hacker next Tuesday? And if they didn’t, how fast would everyone else know? If either answer is a shrug, get in touch with one of our experts today. We’re happy to help you out.

Photo
Joey Pernot

Joey is Netpresenter’s Content Manager. His passion is to inspire and educate through engaging and creative content. Joey loves to spend time with friends and travel the world.