FINANCIAL SERVICES · BANKING INSTITUTION CASE

“How do we respond to a cyberattack made public without deepening the loss of trust?”

Completed case for a European banking institution facing a confirmed cyberattack with customer data exposure.

5 scenarios
of communication tested in parallel
24 dynamic follow-ups
on unexpected friction points
48 hours
then
3 months
post-incident

THE CONTEXT

A confirmed technical breach: in a time window that closes in hours.

A European banking institution had suffered a successful cyberattack on a peripheral system containing analytical accounting data for several thousand business customers. The attack had been detected internally 36 hours after intrusion, with the confirmed exfiltration of a base of 22,000 customer profiles (name, company, outstanding balances, transaction history). The legal and cybersecurity departments had technically stabilized the incident within a further 12 hours.

The communication question remained. The incident fell under a legal obligation to notify the persons concerned and the competent authorities within 72 hours. The bank had to decide between several public communication scenarios: proactive communication ahead of the legal obligation, communication at the strict legal minimum, communication extended to the entire customer base even where unaffected, or communication differentiated by typology of affected customers.

The crisis leadership mobilized our system under a tight time constraint: 12 hours to inform a decision that would shape the reputational trajectory for several quarters.

THE INQUIRY

Four insights that steered the communication strategy.

Full transparency within 24 hours restores trust.

Our system projected that full transparency within the first 24 hours, communication beyond the legal obligation, precision about the exposed data, protection measures deployed, a commitment to fund a monitoring service for affected customers, restored trust by +28 pts compared with the wait-and-see silence scenario. The operational cost of that transparency was offset by the reduced risk of secondary media exposure in the following months.

Partial transparency is structurally worse than silence.

Counter-intuitively, a partial transparency scenario (minimal communication with limited precision about the data concerned) generates a more negative perception than total silence. Customers detect the omissions by cross-checking media information and read them as an implicit admission, while resenting the active opacity. Perception of management degrades by 42 pts in the partial transparency scenario, against 18 pts in the silence scenario, and gains 28 pts in the full transparency scenario.

The tolerated window is 48 hours: not 72.

Although the legal obligation extends to 72 hours, our system identified that the window of acceptability perceived by customers was 48 hours. Beyond it, each additional hour degrades the perceived competence of the institution by 3 to 4 points per day, regardless of the later content of the communication. The communication must land within that window, even if shorter, announcing a fuller follow-up communication to come.

Committing to visible protection measures matters more than apologies.

Our system tested several communication registers. A register centered on apologies generates 34% positive perception. A register centered on the protection measures deployed (reinforced monitoring of affected accounts, automatic reimbursement in case of attempted fraud, proactive human contact) generates 68% positive perception. Banking customers expect deeds more than words in security crises.

THE METHOD

How we built the inquiry in 8 hours.

Our system rebuilt a synthetic population of 480,000 retail and business customers of the institution, calibrated on the bank's proprietary segments and on public post-incident surveys from the European banking sector. The population was structured into 14 typologies crossing exposure to the incident, customer type, sensitivity to digital risk and seniority with the institution.

Our system interviewed 2,800 synthetic customers on the 5 tested communication scenarios, with dynamic follow-ups on the friction points identified in real time (communication register, timing, level of detail, protection commitments). The interviews ran across 800 parallel threads to compress the equivalent of three weeks of human work into under five minutes of computation, with full delivery to the crisis committee within 8 hours of mobilization.

THE DEPLOYMENT

What was decided, what happened.

The bank retained the full transparency scenario at 40 hours post-incident, with communication differentiated by typology of affected customers, a commitment to 12 months of reinforced monitoring for the 22,000 customers concerned, and proactive human contact within 48 hours of the public communication. The communication was carried by the chief executive in person, in a human and accountable register.

At 3 months, the measured loss of trust is −4 pts (against a projection of −18 pts under partial transparency and −24 pts under prolonged silence). The attrition rate among the 22,000 affected customers is 3.2% (against a sector projection of 14% under an opaque scenario). No lasting media movement emerged after the initial wave, and the institution received positive acknowledgment from the supervisory authority on the quality of its communication response.

TRUST RESTORED AT 3 MONTHS
+28 ptsvs the silence scenario projection
COST OF WAITING BEYOND 48H
+42%degradation per additional day
ATTRITION OF AFFECTED CUSTOMERS
3.2%vs sector projection of 14%
MEASURED LOSS OF TRUST
−4 ptsvs −24 pts under prolonged silence
INQUIRY DELIVERY TIME
8 hoursfrom mobilization to deliverable

THE LESSONS

Two principles transposable to cybersecurity crises.

Partial transparency is the worst scenario in a cyber crisis: worse than silence.

This case confirmed a structural dynamic of cybersecurity crises: partial transparency, often chosen out of legal caution, is perceived as more damaging than total silence or complete transparency. Customers detect the omissions and lose confidence in the institution's word, without the institution gaining the legal protection it sought. This principle implies a clear-cut choice between complete communication and wait-and-see silence, with no intermediate gray zone.

The window of acceptability in a cyber crisis is structurally shorter than the legal deadline.

The legal notification obligation (72 hours under the GDPR) is a ceiling, not a target. The windows of acceptability perceived by customers are structurally shorter (typically 48 hours). This gap must be built into the preparation of cyber crisis response plans, with teams trained to produce quality communications on compressed timelines.

A decision to make, a synthetic population that answers, an insight

GET STARTED

Preparing your cyber crisis response plan?

Cyber crisis response plans, upstream preparation, simulation exercises, calibration of crisis communications, share common mechanics with this case. A tight time constraint, the choice between transparency and opacity, a structurally short window of acceptability, the weight of deployed protection commitments. Every incident is singular, but the analytical and preparation levers are transposable.

The dynamic agents scope with you the parameters of a simulation adapted to your situation, ahead of the decision. From initial brief to first deliverable, allow 20 to 30 minutes, depending on the case's complexity and the breadth of the populations to model.