Skip to main content
Uncategorised

Building credibility, not chaos

By 16 April 2025No Comments

Cybersecurity breaches are inevitable. That means most cybersecurity companies advocate for an “assume breach” mindset these days. The message is that while having strong defences matter a lot, so does your response to an incident. Cyber resilience isn’t just about stopping an attack; it’s about how an organisation recovers from one. 

Despite that, whenever a high-profile breach makes headlines, we see a familiar pattern. Some cybersecurity companies swoop in, whether commenting in the media or on their own social media, suggesting that the breach is the fault of the organisation and wouldn’t have happened if the victim had chosen their products or services.  

This ‘ambulance-chasing’ approach may grab immediate attention, but it doesn’t build long-term credibility, nor should it have a place in a professional industry. 

Provide genuine expertise 

Quite rightly, most journalists covering a major breach will seek informed, credible voices and this is a good thing. The aim is to educate and inform. They need real experts who can offer meaningful insights, not opportunistic self-promotion.  

The same stands for comment on social media, people are looking to learn about the breach, not for other organisations pointing fingers with a complete lack of empathy. In the words of my grandmother – “there but for the grace of god”. Which of course, serves as a reminder that no one is immune to misfortune, so empathy should always guide our actions. 

If they choose to comment, cybersecurity companies must look outward and have something good to contribute. It needs to highlight broader trends and industry-wide lessons rather than focusing on the victim’s mistakes. 

Avoid appearing smug (we have not been breached) or suggesting a company “deserved it” (we could have stopped it).  A balanced, educational approach not only helps the conversation but also demonstrates the professionalism of the cyber security industry as a whole and strengthens media relationships.  

Most journalists prefer sources who provide reliable context over those who merely push an agenda. 

Build trust, not backlash 

Respect matters. Organisations hit by breaches are already under enormous pressure; public finger-pointing or sensationalising their misfortune isn’t just unethical—it can backfire, damaging your own reputation. Particularly now, it is widely accepted that no one can completely avoid a breach, even with the most robust defences. 

Trust isn’t built via opportunistic commentary on breaches. Your thought leadership needs to begin long before an incident occurs. Cybersecurity firms must proactively contribute to industry dialogue, advancing security standards through collaboration rather than sales pitches. 

So, when engaging with the press post-breach, the focus must be on improving cybersecurity for all—identifying industry issues, discussing solutions and encouraging a mindset where we have collective responsibility. After all, no company is immune—next time, it could be your customer. 

At PRPR, we help cybersecurity businesses craft thoughtful, ethical, and strategically valuable media engagement. Our approach ensures credibility, builds trust, and strengthens reputation—so when you do speak up, it is at the right time, about the right things.  

 

Find out how we can help you!

We’d love to discuss your marketing and communications requirements with you and we’re always happy to have a chat, so please get in touch.