When a Major Cyber Attack hits, how do we Communicate?

James Mullins, VP EMEA & APAC Sales, Mattermost

Cyber resilience is often measured by how quickly an organisation can recover its systems. But when a major cyber attack strikes, recovery starts much earlier than restoration. It starts with communication.

Today’s attackers understand that encrypting data is only part of the objective. Increasingly, they aim to disrupt an organisation’s ability to coordinate its response. Directory services are targeted. Collaboration platforms are disabled. Networks are isolated to contain the attack. Within minutes, organisations can find themselves unable to answer the most basic operational question: How do we communicate?

“If your main company network goes dark, your out-of-band communications should keep you in the light.”

This communications blackout is rarely accidental. It is a deliberate part of modern attack strategy. As defenders work to contain the breach, they often disconnect systems themselves to prevent further compromise.

The result is an operational environment where security teams, executives, legal counsel, communications teams and external partners are all trying to manage a rapidly evolving crisis without a trusted means of sharing information.

The Fog of Cyber War

Military leaders have long understood the concept of the “fog of war” – the uncertainty that exists when reliable information is unavailable. The same principle increasingly applies during a major cyber incident.

Under normal circumstances, leadership teams receive structured updates, assess the facts and make informed decisions. During a cyber attack, those information flows can disappear entirely. Without trusted communications, leaders struggle to establish what has happened, what systems remain operational, who is affected, or what actions should be prioritised.

The result is often one of two dangerous outcomes: rushed decisions based on incomplete information, or decision paralysis while waiting for certainty that may never come. Both work in the attacker’s favour.

Why Out-of-Band Communications Matter

This is why many organisations are now incorporating dedicated out-ofband communications into their cyber resilience strategies. An out-of-band capability operates independently of the primary corporate network. It is pre-configured, secure and available when core business systems have been taken offline or intentionally isolated.

Rather than scrambling to establish communications during a crisis, organisations can immediately coordinate incident response, share verified information, assign tasks and maintain executive oversight using a trusted platform that remains operational throughout the incident.

The objective is simple: ensure that the organisation can continue to make informed decisions when its primary communications infrastructure cannot.

Complaince Doesn’t Pause During an Attack

Maintaining communications is not simply an operational necessity. It is increasingly a regulatory requirement. Frameworks such as NIS2 expect organisations to notify regulators of significant incidents within strict reporting windows, often between 24 and 72 hours. Those obligations do not disappear because internal email, collaboration tools or corporate networks are unavailable.

Organisations must still establish the facts, coordinate response teams, document decisions and communicate with regulators, customers and partners. Without a secure communications capability, meeting those obligations becomes significantly more difficult.

The Consumer Messaging Trap

One of the most common mistakes organisations make during a cyber incident is turning to consumer messaging applications as an emergency alternative. While these platforms may restore basic communication, they can also introduce new risks.

Chain of custody can be lost. Regulatory obligations surrounding governance, record keeping and evidential integrity become much harder to demonstrate. In attempting to solve one problem, organisations may inadvertently create another.

Sensitive corporate information may be shared through unmanaged environments. Audit trails may be incomplete.

”The regulator doesn’t care if your email is down. They still expect you to report, communicate securely and remain compliant.”

Preparing Before the Crisis

Effective cyber resilience is about more than preventing attacks. It is about ensuring the organisation can continue to operate when prevention fails.

Planning for secure communications before an incident occurs allows organisations to coordinate response efforts, support leadership decision making, satisfy regulatory obligations and reduce the operational disruption caused by an attack.

In an environment where cyber incidents are increasingly viewed as a matter of when rather than if, the organisations that recover fastest will not necessarily be those with the strongest perimeter defences. They will be the organisations that can still communicate when everything else has gone quiet.

If you are reviewing your organisation’s cyber resilience or out-of-band communications strategy, visit mattermost.com to learn more or reach out to our team.

To listen to James Mullins interview with let’s talk cyber, click here.