I recently proposed a checklist / report card for Incident Response communications, based on some ideas developed in an earlier blog about when security breaches hit close to home.

Why do we need this? Because even if your organization has done all the right things and still been breached, you still have to communicate to your customers about an awkward and unpleasant topic. And there are certain things your customers will want to know: What happened? Who is accountable? What steps are being taken to prevent it from happening again? How will I be made whole?

Use the framework to help develop your IR communications, and it’s a checklist. In future blogs, I plan to use it to assess actual IR communications, and assign them a letter grade – which makes it a report card. (Thinking back on past examples, most would receive a low grade.)

Here, I’m also using the framework to describe what not to do in developing your IR communications, by making another entry in my series of blogs on the Screwtape CISO.

It’s been a while, so if you aren’t already familiar with the concept … “The Screwtape CISO: Memos of Advice on Worst Practices in IT Security” is my nod to the great C.S. Lewis, author of  The Screwtape Letters. The Screwtape CISO is meant to shine a light on the thought processes and actions that result in “worst practices” in IT security and compliance initiatives, through a series of intercepted memos from an external “advisor” to an ordinary chief information security officer in a typical enterprise. Sometimes recognizing the worst practices in our own organizations is the best impetus towards positive change.

In the Screwtape version of the Incident Response Communications Report Card, certain people in your organization – e.g., general counsel, marketing and public relations – would never want to admit any wrongdoing, accept any responsibility, or acknowledge any liability.

So, for example, where the framework actually suggests that you acknowledge the incident by establishing a common understanding of what happened, and by accepting responsibility and accountability the consequences – the Screwtape version of the framework suggests just the opposite: reveal as little as possible about what happened, and avoid responsibility and accountability like the plague.

Here, then, is the Screwtape CISO version of the Incident Response Communications Report Card:

Incident Response report card (Screwtape CISO version) Derek Brink Aberdeen

As I have expressed before – e.g., see Why Say ‘Failures’, ‘Flaws’, ‘Faults’, or ‘Fiascos’ – When You Can Say ‘Glitch’? (28 October 2013) – organizations should be held accountable for their decisions about risk when they do go wrong, and as their customers we should not tolerate their misuse and perversion of language to try to avoid doing so. Lawyers, marketers and PR firms may have driven the deny-and-deflect culture that we now live in, but these approaches are successful only because we collectively have been passive enough to accept them.