As breaches become part of everyday business, how has the conversation evolved and what do recent incidents reveal about good — and poor — incident response?
Even as little as five years ago, a company that suffered a breach would come under intense scrutiny, including months of review into how and why the attack had hit — especially if sensitive data was exposed.
While this level of scrutiny still happens, it’s now widely accepted that cyber-attacks will take place, especially targeting high-profile firms. This was all too clear recently when the likes of Coca-Cola, Ernst & Young, Craneware and Abbott all admitted cyber incidents within a few months of each other.
Beyond the breach itself, these disclosures across multiple industries over a short period show a bigger trend. As cyber incidents become more difficult to prevent, customers, regulators and partners are placing greater scrutiny on how organisations respond, recover and communicate when something goes wrong.
How has the conversation evolved and what do recent breaches reveal about good — and poor — incident response?
Changing Expectations
Expectations around cyber incidents have changed. A decade ago, organisations were largely judged on whether they suffered a breach at all. Today, stakeholders understand that “no organisation is immune”, says Doug Jewitt, security consultant at Infinity Group.
He describes how the focus has shifted towards how quickly an organisation identifies an incident, how transparently it responds, and how effectively it recovers. “There is a clear expectation that organisations of all sizes have appropriately sized technical controls in place.”
The recent disclosures involving Coca-Cola, Ernst & Young, Craneware and Abbott show that “timely, substantive communication” can moderate stakeholder reaction, says Tracey Hannan-Jones information security consulting director at UBDS Group. “Silence, delay, or vague statements invite speculation and often cause reputational damage disproportionate to the technical incident. An organisation unable to explain what happened, what it is doing, and what remains unknown signals that it was unprepared.”
The difference between a good and poor response centres around “visibility and context”, says Jeremy Leasher, security architect at Binalyze. He believes the recent attack on healthcare organisation Stryker is a clear example of where things can go wrong.
“The initial statement insinuated there was no ransomware or malware, and that the incident was contained,” Leasher tells IO.
Technically this was accurate, but when it emerged the attack came through a trusted admin tool rather than malware it didn’t matter, says Leasher. “Strategically, it looked like Stryker didn’t understand the threat.”
Regulator Roles
Meanwhile, regulators now play a key part in shaping incident response, including expectations around reporting and disclosure.
The UK general update to data reprotection regulation (GDPR) requires reporting personal data breaches within 72 hours, while the Financial Conduct Authority, EU Network and Information Systems Directive 2 regimes, and the US Securities and Exchange Commission impose additional notification duties. “Regulators increasingly assess not merely whether notification occurred, but its speed, quality, accuracy, and follow-up,” says UBDS Group’s Hannan-Jones.
One of the biggest practical consequences is timing, says David Dumont, partner at Hunton. He points out that many reporting obligations have very short deadlines. “So, organisations may have to devote substantial time and resources to assessing notification requirements and preparing regulator forms almost immediately after becoming aware of an incident, often while the facts are still developing.”
At the same time, the regulator itself has an increasingly important role to play, says Freeths’ data expert Paul Wiggins. He points out that under the Data Use and Access Act, the UK Information Commissioner’s Office (ICO) has stronger enforcement powers. “It is anticipated that the ICO will act as a regulatory gatekeeper, with the hope that this will provide resolution for low value claims,” he tells IO.
Speed, Transparency and Accuracy
While attacks continue to hit firms, many experts believe businesses are becoming better at handling cyber incidents. Dray Agha, senior manager, security operations centre, EMEA at Huntress says things are improving largely because the historical stigma of a breach is fading. “Businesses are recognising that incidents are a ‘when, not if’ reality, allowing them to shift their energy away from hiding the problem and toward minimising the downtime.”
It’s now important that organisations strike the balance between speed, transparency and accuracy during an incident.
Responding well to a breach requires several key steps. Having the right policies and team in place to “spring into action when the time comes” is essential, says Freeths’ Wiggins.
He highlights the importance of a team including external advisers — such as lawyers, PR agents and cyber insurers — which he believes is “fundamental” in shaping the strategy and response to an incident. “Additionally, a willingness to help reassure and support affected data subjects, as well as engaging with supply chain partners who feel the knock-on effects of the incident.”
The organisations that respond best to a breach have done the planning in advance, says Binalyze’s Leasher.
At the core, he thinks they should be able to answer the three basic questions quickly: “Does the attacker still have access? How did they get in? What did they take?”
Communication and transparency are essential and can be “the difference between a cyber incident becoming a business challenge or a reputational crisis”, points out Infinity Group’s Jewitt. “Customers, partners and regulators understand that investigations take time, but they expect honesty, timely updates and clear explanations of what is known, what is still being investigated and what actions are being taken.”
The key is to “communicate what you know, acknowledge what you don’t know and commit to regular updates”, says Jewitt. “Waiting for perfect information can delay critical decisions, but rushing to conclusions can damage trust.”
Strong Governance
Strong governance underpins effective incident response. This means ensuring clear ownership, established processes and informed decision-making before a crisis occurs.
Strong governance ensures that decisions can be made quickly and confidently during a crisis, says Jewitt. “Clear ownership, established escalation paths, and well-understood responsibilities remove uncertainty when time matters most. Organisations that invest in governance before an incident are typically better equipped to manage regulatory requirements, stakeholder communications and recovery efforts when one occurs.”
Stellar incident response cannot be improvised, says UBDS Digital’s’ Hannan-Jones. “Detection matters, but rapid containment depends on clear authority and rehearsed coordination. Technical, legal, communications, and executive teams must work together from the outset. Cyber incidents affecting data, intellectual property, or operations are business events, not simply IT problems. Visible board-level ownership is essential.”
ISO 27001 can strengthen readiness when treated as an operational framework, but certification alone is insufficient, says Hannan-Jones. “Untested plans, poorly understood responsibilities, and IT-only exercises create false confidence.”
She says effective resilience rests on four practised capabilities: “Detect, contain, respond and recover.”
Expand Your Knowledge
Blog: Why Cyber Resilience Remains a Long Way Off for Many UK Businesses
Podcast: Boardroom to Breakroom- Building a Culture of Compliance
Blog: How Can Security Teams Prepare for a Post-Mythos Future?







