On the Friday before Christmas, colleagues from the Aberdeen Group crossed the street to the company’s favorite local watering hole, M.J. O’Connor’s, for the company’s annual holiday party.

On the Friday after Christmas, Boston-based Briar Group disclosed the unauthorized access of names, account numbers, expiration dates, and security information for an unknown number of its customers from 8 local restaurants – including M.J. O’Connor’s – between “sometime in October 2013” and “early November 2013.”

Normally, I might comment about the timeline – for example, how much time elapsed between the actual beginning of the breach, to the public disclosures that a breach had occurred, to the Briar Group finally deigning to acknowledge that their customers had been placed at risk. It’s a timeline that is not at all flattering to the management team – which, ironically, highlights that “the ethical foundation of The Briar Group is built on the honesty, integrity and moral standards of our founder and leadership.” #FAIL

What I’d like to comment instead on is their lame, non-apology apology to their “valued customers”. Read the full text for yourself, but here are some key excerpts (with just a little grouping by me):

  •  We don’t really know what happened
    • “residents and visitors … were the victim of credit card data theft”
    • “the Briar Group’s systems were indeed infiltrated”
    • “still working to determine the exact dates”
    • “your credit card data may not have been stolen or used”
  •  We’ve done everything right – so please keep spending your hard-earned money with us
    • “we want to assure you that the Briar Group takes the security of the personal information and bank data of all of our customers seriously”
    • “all of our systems are PCI compliant and updated regularly”
    • “we can assure you that we are committed in our efforts to protect all credit card data”
    • “we are confident that the system is secure and that it is safe to use credit cards at our restaurants”
    • “we want to extend our sincere apologies to our customers for any inconvenience they may have experienced”
    • “we thank you for your support and patience”
  •  But it’s really your problem at this point, not ours
    • “you can contact your card issuer for more information”
    • “we urge all of our customers during this period to monitor your credit card statements carefully for fraudulent charges”
    • “please see below for information on the various services where you can monitor your credit report”

In other words, you’re on your own. #YOYO

So what it is that makes this, and so many other examples of poor public posturing about security breaches – see, for example, my blog When Security Breaches Hit Close to Home: Snapchat (7 January 2014, and my blog RSA and NSA: Say It Isn’t So, Joe (30 December 2013 – so unsatisfying? What are the elements of a proper apology, and what are these examples missing?

It turns out that this question wasn’t so easy to answer.

My first instinct was to look to one of my personal favorite authoritative sources for issues of right and wrong – where I found that it should probably contain elements of confession (disclosure of offenses, taking responsibility for offenses), contrition (sorrow for offenses committed, resolution not to offend again), and satisfaction (repair of damages caused, penance).

Another source that came up more than once is Dr. Aaron Lazare, from the University of Massachusetts Medical School, who is described as “a leading authority on apology.”

Borrowing heavily from an article by Dr. Lazare, here is my attempt to unify what I found to be a mish-mash of opinions about the elements of an apology.

An effective apology has up to four parts (not all parts are always present):

  •  Acknowledgment of the offense
    • Common understanding of what happened
    • Responsibility and accountability – “I was wrong”
    • Explanation
      • Without conditions
      • Without blaming others
      • Acknowledgement of the effects
        • Expression of regret – “I’m sorry”
        • Attitudes of remorse and humility
        • Reparation
          • Intentions – “It won’t happen again”
          • Restitution – “I’ll make it right”

An effective apology also satisfies at least one of the following psychological needs of the offended party:

  •  Restoration of dignity
  • Acknowledgement of wrongdoing
  • Validation that the offended party was not responsible
  • Assurance against future offenses
  • Justice (i.e., actions have consequences)
  • Reparation (i.e., some form of compensation)
  • Means to express feelings toward the offenders

I actually find this to be a pretty useful framework – and it really does help to give expression to why the Briar Group’s non-apology is so offensive:

  •  They take no responsibility for the breach, or for the communications
  • They offer no real explanation of what actually happened
  • They don’t really acknowledge the effects on their customers – e.g., uncertainty, inconvenience, cost
  • They make no reparation – all the burden is placed on the customer
  • They don’t really meet any of the seven psychological needs – unless possibly we give one point for “assurance against future offenses”

We all understand the deny-and-deflect culture that we live in, driven by lawyers and public relations. But wouldn’t it be refreshing to have a company say something like this instead?

“In spite of our best efforts, our protections failed …

We’re very sorry that you were affected …

We’re taking steps to ensure that it won’t happen again …

Whatever effect it does have on you, we’ll make it right.”

Now that would give real meaning to throwaway phrases like “valued customers” and “we take the security of your information seriously.”

For more research and insights on the topic, visit Aberdeen’s IT Security page.