Edward A. Flynn, the former Massachusetts public safety secretary, spoke to CSO shortly after he handled a media frenzy over reports that the FBI was seeking six foreign nationals in connection with a suspected plot to release a dirty bomb in Boston. Edward A. Flynn, the former Massachusetts public safety secretary, spoke to CSO in 2005, shortly after he handled a media frenzy over reports that the FBI was seeking six foreign nationals in connection with a suspected plot to release a dirty bomb in Boston. The tip to authorities later turned out to be a hoax. But as in real-time crisis situations facing many security executives, Flynn didn’t know that at first. Flynn shared these crisis communication tips, which you can pass along to executive colleagues and managers at your organization. Share accurate information. During a crisis, Flynn says, you first need to provide information to your colleagues and employees about what’s happening so that they can respond appropriately. This is a big deal even if it’s hard to do, with conflicting interests at play among government agencies, he adds. “Understandably, there’s stress between the federal concerns to protect an ongoing investigation and the state government who needs to convey information to the media.” Answer questions. After an organization releases information about an incident, Flynn says, expect questions. It’s important to respond quickly and to shape answers that reflect the tone you are trying to achieve—in this case, a calming presence. He adds: “If I’m answering your questions, I’ve found, it gives me room in tone and content to convey a more accurate, simple statement than any crafted message could do. And there’s always the old adage that you answer the question you wish you were asked.” Tell the truth. Flynn says that it’s important to establish your credibility before a crisis. Then, when an incident occurs, your boss and peers will know that they can come to you for accurate and reliable information. Also be aware of your superiors’ points of view. “Their concerns are not only security related. They have a constituency. There are other interests besides yours at stake.” Be prepared. Flynn says you need a communication plan that “requires that we work out in advance how we will communicate that message—who will deliver it to certain constituencies. If we have an industry that’s part of the critical infrastructure, what is your standard procedure to handle information when it comes into your domain? Into the public domain? How do you [speak] to your employees? These discussions need to take place in advance.” Get involved. As a government official, Flynn says he saw the importance of public- and private-sector information-sharing. “CSOs should get involved with local and state government,” Flynn says. “Get in touch with your state’s emergency management agency.” Related content news Chinese state actors behind espionage attacks on Southeast Asian government The distinct groups of activities formed three different clusters, each attributed to a specific APT group. By Shweta Sharma Sep 25, 2023 4 mins Advanced Persistent Threats Advanced Persistent Threats Cyberattacks feature How to pick the best endpoint detection and response solution EDR software has emerged as one of the preeminent tools in the CISO’s arsenal. Here’s what to look for and what to avoid when choosing EDR software. By Linda Rosencrance Sep 25, 2023 10 mins Intrusion Detection Software Security Monitoring Software Data and Information Security feature Top cybersecurity M&A deals for 2023 Fears of recession, rising interest rates, mass tech layoffs, and conservative spending trends are likely to make dealmakers cautious, but an ever-increasing need to defend against bigger and faster attacks will likely keep M&A activity steady in By CSO Staff Sep 22, 2023 24 mins Mergers and Acquisitions Data and Information Security IT Leadership brandpost Unmasking ransomware threat clusters: Why it matters to defenders Similar patterns of behavior among ransomware treat groups can help security teams better understand and prepare for attacks By Joan Goodchild Sep 21, 2023 3 mins Cybercrime Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe