CRISIS MANAGEMENT · FINANCIAL SERVICES

How should an organization respond to a publicly disclosed cyberattack without worsening the loss of trust ?

A European banking institution suffers a successful cyberattack on a system containing customer data. The incident is technically stabilized. The remaining question is no longer technical.

It is this: what should we say now, and how will that decision be interpreted by customers who do not all have the same relationship with money, data and the institution ?

A woman sitting at her kitchen table looks at a message on her phone in the natural morning light.
DECISION
How to communicate, and when
POPULATION
Retail and business customers
CONTRAINTE
A decision in a matter of hours
KEY ISSUES
Trust · credibility · duration
  • TOO LITTLE

    Silence is read as concealment

  • TROP

    Precision can amplify perceived severity

  • TOO LATE

    The information is reliable, but trust is already damaged

THE PROBLEM

After a cyberattack,
the decision is no longer
just technical.

The incident is contained, but the organization must simultaneously balance the speed of communication, the degree of transparency, the level of detail disclosed, acknowledgment of responsibility, protection of its reputation, reassurance of its customers, regulatory risk and the risk of media amplification.

These trade-offs do not cancel one another out. Saying too little creates distrust. Saying too much can amplify perceived severity. Waiting makes the information more reliable, but can be read as concealment.

The question is therefore not: how do we reassure ? It is: which response actually protects trust when it is reassessed several weeks later ?

  • initial trust in the institution
  • actual exposure to the incident
  • intensity of digital-service use
  • sensitivity to data protection
  • previous experience of fraud
  • financial exposure
  • dependence on the banking app
  • understanding of security issues
  • general attitude toward financial institutions
  • anxiety about digital risks

TIMING

A decision made
in a few hours.
Effects over several months.

The legal notification window extends to 72 hours. The window customers actually tolerate in the simulated reactions is shorter: beyond 48 hours, the content of the communication no longer offsets the delay.

  1. T0

    The attack is detected internally. The exact extent of the exposure has not yet been established.

  2. T + A FEW HOURS

    The incident becomes public. The organization must decide what to say, to whom, and with what level of detail.

  3. T + 24 HOURS

    Customers, media and social networks interpret the response as much as the incident itself.

  4. T + A FEW DAYS

    Initial perceptions begin to settle. What was not said becomes more costly to disclose.

  5. T + SEVERAL WEEKS

    Trust is restored or deteriorates over time, depending on the consistency between what was announced and what was done.

THE SIMULATION

The same incident.
Five ways
to talk about it.

The five strategies were tested against the same population to isolate the effects of timing, level of detail, acknowledgment of responsibility and the protection measures announced.

  1. 01ATTENDRECommunicate only once the exact extent of the incident has been established.
  2. 02MINIMISERCommunicate quickly, emphasizing that the incident is limited and under control.
  3. 03FACTUAL TRANSPARENCYState quickly what is known, what is not yet known, and what measures have already been taken.
  4. 04TRANSPARENCY + ACCOUNTABILITYAcknowledge the incident and explicitly take responsibility for protecting customers.
  5. 05TRANSPARENCY + PROTECTIONImmediately add concrete measures: monitoring of exposed accounts, proactive human contact, a dedicated channel.

“ Customers ”
do not react
with one voice.

SIMULATED POPULATION

The reconstructed population covers the institution's retail and business customers, combining actual exposure to the incident, type of banking relationship, intensity of digital use, sensitivity to data and tenure.

These dimensions, rather than an average opinion about cybersecurity, determine how the same sentence is received.

  • DIRECTLY EXPOSED CUSTOMERS

    their data falls within the scope of the incident

  • CUSTOMERS NOT AFFECTED BUT INFORMED

    learn about the incident through the media without knowing whether they are affected

  • BUSINESS CUSTOMERS

    financial exposure and responsibility toward their own customers

  • HEAVY APP USERS

    daily dependence on the bank's digital services

  • LOW-DIGITAL CUSTOMERS

    limited technical understanding, high dependence on an adviser

  • PEOPLE WHO HAVE PREVIOUSLY EXPERIENCED FRAUD

    memory of a previous incident, lower tolerance threshold

  • HIGH TRUST CAPITAL

    long-standing relationship, stable relationship with the institution

  • PRE-EXISTING DISTRUST

    distrust of financial institutions that predates the incident

  • HIGHLY SENSITIVE TO PERSONAL DATA

    high vigilance regarding data use and protection

These configurations reveal part of the population's heterogeneity. The simulation operates on synthetic individuals, not a handful of persona types.

Facade of a bank branch seen from the street on a gray day, with a few pedestrians on the wet pavement.
A few weeks later, the crisis is no longer playing out in an incident-response room. It plays out in each person's ordinary relationship with their bank.

REACTIONS

It was not the attack
that was being judged.
It was the response.

  1. 01

    SILENCE IS NOT NEUTRAL: IT IS INTERPRETED

    In the simulation, waiting does not suspend judgment; it shifts it. Every hour without an official statement leaves room for other narratives, and caution becomes readable as concealment.

  2. 02

    PARTIAL TRANSPARENCY IS READ AS OMISSION

    Fast but evasive communication reassures some customers and sharply worsens the position of others, who cross-check the available information. Perception deteriorates more than in the silence scenario.

  3. 03

    ACKNOWLEDGING WHAT IS NOT YET KNOWN INCREASES CREDIBILITY

    Counterintuitively, explicitly stating what remains unknown strengthens the credibility of the rest of the message. Acknowledged uncertainty is better tolerated than certainty that later proves false.

  4. 04

    ACTIONS CARRY MORE WEIGHT THAN REASSURING WORDS

    An apology-led message generates markedly lower support than one centered on protection measures actually put in place. Customers who were already distrustful respond only to evidence of action.

Imagine All The People does not simply ask a model to imagine how customers might react to a cyberattack. Several crisis responses are tested against a coherent, heterogeneous synthetic population to observe reactions, contradictions and differences between segments before the decision is made.

RESULT

Five responses,
assessed across four dimensions.

STRATEGYTRUSTREASSURANCERISK OF DISTRUSTROBUSTNESS OVER TIME
01Waitlowlowhighlow
02Minimizelowmoyennehighlow
03Factual transparencymoyennemoyennemediummoyenne
04Transparency + accountabilityhighmoyennemediummoyenne
05Transparency + protectionhighhighmediumhigh

Comparative reading based on simulated reactions. No response eliminates the risk: transparency combined with protection measures produces the most robust trajectory, but makes the initial severity clearer and commits the organization to verifiable actions over time.

THE MOST ROBUST

Speak quickly acknowledge uncertainty provide concrete protection

THE MOST FRAGILE

Wait downplay reassure without evidence

TAKEAWAY

Trust does not return
when the organization reassures.
It returns when the organization makes
its actions verifiable.

In the simulation, reassuring messages do not produce lasting trust: they create an expectation that the facts confirm or contradict a few days later. What holds over time are verifiable elements — what is known, what is not yet known, what is being put in place, and for whom.

Silence is not an absence of communication. It is already a message, and customers interpret it using other sources.

TO DO
Communicate quickly on established facts
TO OWN
State what remains unknown
TO PROVE
Verifiable protection measures
TO AVOID
Confuse reassurance with minimization

POSSIBLE FUTURES

The same crisis.
Three trajectories.

A

ATTENDRE

Communicate once the incident has been fully assessed

  • more complete and more reliable information
  • fewer subsequent corrections
  • a concealment narrative develops without the organization
  • the window of acceptability closes before the organization speaks

B

RASSURER

Speak quickly, present the incident as limited

  • reduced immediate anxiety for some customers
  • simple, controlled message
  • greater loss of trust if subsequent facts contradict the message
  • customers who were already distrustful harden their interpretation

C

SAY + ACT

Established facts, acknowledged uncertainty, immediate protection measures

  • credibility is built on verifiable elements
  • exposed customers have a concrete avenue for support
  • the initial severity is made clearer
  • heavy operational commitment that must be sustained over time

METHOD

Before recommending,
we tested reactions.

  1. DECISION
  2. POPULATION
  3. STRATEGIES
  4. DYNAMIC REACTIONS
  5. COMPARISON
  6. DECISION

This case differs from the previous ones because of its constraint: the decision could not be prepared in advance. The study was conducted under pressure, in parallel with the technical management of the incident, to inform a trade-off that had to be made that day.

A real case.
A confidential organization.

This case is based on a completed simulation. The institution is not named, and no element that could identify the incident or the client is published. The decision, the strategies tested and the findings are presented without revealing sensitive information.

Your next decision

Which decision do you want to explore?

Describe your need. We can point you to the right level of support.

What if you tested
your next decision?

State your decision. See the future it produces.

Explore the product