# Discernible Inc > Communication experts for cybersecurity and privacy teams. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### Services URL: https://www.discernibleinc.com/services/ Last updated: 2026-08-26T20:50:55.000Z **Work With Us** Security and privacy teams are technically excellent. The gap isn't knowledge — it's the organizational skills needed to compete for resources, earn executive and cross-functional trust, and earn political capital that you can spend when you need it. That's what we help you develop. Discernible is a strategic advisory. We bring together former security and privacy leaders, organizational behavior specialists, and corporate anthropologists to work on the problems that sit at the intersection of technical expertise and organizational power. Our twenty years of pattern recognition across incident response, regulatory scrutiny, executive communication, and organizational change informs every engagement. --- ## **Organizational Engagements** We work with security and privacy organizations on the moments that require the most from your team. - **When you need to build credibility before you need it** — executive and board communication, narrative development, reputation management, and internal program positioning. - **When change requires buy-in** — new policy/control rollouts, framework adoption, certification launches, new tool deployments, and organizational restructuring. - **When an incident is possible or already underway** — incident response communication planning, readiness preparation, and customer communication strategy. - **When your team needs better communication infrastructure** — team communication rhythms, chief of staff support, cross-functional coordination, and bug bounty de-escalation. Our engagements are scoped to your moment, not a menu of deliverables. [Contact us to start the conversation.](https://calendly.com/melanie-discerniblecommunications/30min?ref=discernibleinc.com) --- ## **1:1 Coaching** For individual security and privacy leaders who need a focused partner. - **One-Time Consultation** *— $250* | A 45-minute session for leaders who need a second opinion on a specific challenge, decision, or communication approach. Includes pre-session context review and written follow-up within 48 hours. - **Executive Coaching** *— $3,000/month* | Weekly 45-minute sessions plus async support between calls. For leaders navigating complex, multi-month challenges — new roles, scaling teams, or stakeholder dynamics that won't resolve in a single conversation. Limited availability. Not sure where to start? A one-time consultation is a good first step. [Book an intro call.](https://calendly.com/melanie-discerniblecommunications/30min?ref=discernibleinc.com) ### Case Studies URL: https://www.discernibleinc.com/case-studies/ Last updated: 2026-07-01T00:43:40.000Z The organizational challenges security and privacy leaders face don't arrive in neat categories; they're tangled up in politics, timing, and institutional history that generic frameworks can't account for. Our case studies document the real work of how teams shifted their standing with executives, built communication capabilities that held up under pressure, and turned technical programs into recognized organizational assets. --- #### Incident Response Communications Planning A leading collaborative design platform proactively decided they wanted to be in the category of companies that were fully prepared to communicate effectively for a range of situations, with an end to end incident and response communications plan. **“I always admired Melanie’s ability to see through the clutter and diagnose the problem in a way that is very clear-eyed. When we needed to create something as no-nonsense as a process for how to respond to potential security incidents, we wanted to work with someone who was going to focus on the right path and give it to us straight – and that was Melanie.”* [Read more](https://www.discernibleinc.com/customer-case-study-incident-response-comms-plan/) #### Leveling Up Team Communications In his former role as the Chief Information Security Officer for Cisco Secure, Josh Yavor was responsible for a large, growing team. With a balance of established and newer leaders in this group, he understood that effective communication skills would be vital to ensure his direct reports were successful as they navigated significant organizational change. After evaluating numerous consultants, Yavor selected Discernible because of Melanie’s experience in security communications and her flexible approach. “I knew Melanie could be a partner in assessing each individual’s needs and doing that in a way that removed biases on my part,” Yavor said. “That and she is a security professional who knows how to uncover and prioritize areas of opportunity for development.” [Read more](https://www.discernibleinc.com/customer-case-study-cisco-secure/) #### Executive Communications for Security Leaders Specialized communications coaching from Discernible help CISOs navigate career transitions, strengthen reputation management skills, and build a stronger executive presence. “Working with Melanie at this point in my career journey was transformative. With years of professional leadership development and an undergraduate degree in Communications, I did not realize how much I would gain from this engagement.” — Amy Bogac, CISO, Baker Tilly [Read more](https://www.discernibleinc.com/customer-case-study-building-ciso-resilience-with-strategic-communications/) #### Increasing Community Engagement Discernible’s simple, yet powerful solution made a real difference. **“I had never seen this process operationalized before. Discernible was able to take the whole process and build a sequential workflow, all the way from ‘I’m thinking about speaking or blogging’ to actually doing it. It also ended up saving me and my team a lot of time, and for that, I’m incredibly thankful.”* E. Coleen Coolidge, former Twilio CISO [Read more](https://www.discernibleinc.com/customer-case-study-twilio/) #### Communication Training As the Vice-President of Software Assurance Practice at Trail of Bits, which secures some of the world's most targeted organizations and products, Nick Selby led a large, geographically distributed team of software engineers and security researchers who audit and strengthen the security of various products and networks for large private enterprise and government customers. And that requires a lot of communicating – in all directions: to the senior leaders of the company, to his peers across the organization and to his direct reports, and their teams. And, to audiences at industry events, to customers, and even to the press. “I noticed that Melanie has a rare ability to speak in headlines and get right to the point in a compelling way. I wanted to learn how to do that.” [Read more](https://www.discernibleinc.com/customer-case-study-trail-of-bits/) ### Weekly Incident Drills URL: https://www.discernibleinc.com/experience/ Last updated: 2026-07-05T17:00:49.000Z **The Discernible Experience** Most security professionals build technical instincts through years of hands-on work. Communication instincts don't develop the same way — unless you practice them intentionally. The Discernible Experience gives you weekly opportunities to practice the communication moments that separate technically strong practitioners from organizationally influential ones. Every Wednesday in our Slack community, small cohorts work through evolving real-world scenarios with genuine stakeholder complexity such as time pressure, incomplete information, competing priorities, and audiences who care about different things. This is not a tabletop exercise. Tabletops test your organization's processes. The Discernible Experience builds your individual communication capability. Once you learn to recognize the patterns, every stakeholder email, every executive update, and every cross-functional meeting becomes an opportunity to demonstrate your craft. Our scenarios rotate across more than a dozen incident types including ransomware, insider threats, supply chain compromises, privacy violations, and more — drawn from our 20 years of frontline security communication work. **Who It's For** Security or privacy professionals with at least one to two years of incident response experience who are great at the technical work and ready to close the gap on the organizational side. If you've ever struggled to get budget approved, explain program value to leadership, or turn technical wins into credibility, then this was built for you. **Plans** - *Debrief* — *$15/month* | Can't make our live sessions on Wednesdays? Get our weekly scenarios delivered directly to your inbox. - *Standard — $50/month* | Weekly scenarios via Slack plus access to the scenario library archive. - *Pro — $100/month* | Everything in Standard, plus custom scenario requests, live post-session discussions with Discernible CEO Melanie Ensign, and three guest passes per year. Individual subscriptions means you can join with or without the rest of your 9-5 team. [Choose your plan](https://www.discernibleinc.com/#/portal) ## ### Clients & Testimonials URL: https://www.discernibleinc.com/clients-testimonials/ Last updated: 2026-07-01T01:02:46.000Z **Who We Work With** Discernible works with security and privacy leaders at organizations where the stakes are high and the internal dynamics are complex — CISOs navigating board relationships, privacy officers managing regulatory pressure, and security teams working to build the organizational standing their programs deserve. Our clients come to us for communication capabilities that hold up when it matters most. --- ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/0813-defcon-logo.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/Cisco.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/Hack-Club-Logo.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/Match-Group-logo.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/Salesforce-logo.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/Security-Alliance.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/Twilio.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/yahoo_default_logo.webp) ![](https://storage.ghost.io/c/ae/fc/aefcd8de-a3c5-4631-8da8-b86ceabbc317/content/images/2026/06/Databricks-logo.png) --- “The barriers to achieving success are rarely technical. Most often they can be traced back to a lack of effective communication and partnerships with key stakeholders and customers. What’s worse is that many security programs fail to recognize this reality. Melanie \[Discernible CEO\] has deep experience developing the skill sets necessary to enable security teams to deliver successful outcomes for their customers and partners through the application of effective communication.” *\-Josh Yavor, former head of corporate security, Facebook* --- “I’m convinced there’s literally no one better in the world at Security and Privacy Communications than Melanie \[Discernible CEO\]. She’s guided startups and some of the world’s largest companies through endless headline-making events. But even better, you want her in your corner before you have an issue to help guide your teams and culture. She’ll help you get ahead of the curve with a distinct business advantage.” *\- Jamie Wallace, former director of cybersecurity, AT&T* --- “The lessons we learned at DEF CON from Melanie \[Discernible CEO\] are still with us today - her expertise is durable and not transactional. We have definitely leveled up from working with her.” *\-Jeff Moss (@TheDarkTangent), Founder & President, DEF CON* --- “Discernible’s expertise is the super power for any lawyer’s risk POV.” *\- Michelle Finneran Dennedy, former Chief Privacy Officer, Cisco & McAfee* ### Get in Touch URL: https://www.discernibleinc.com/contact/ Last updated: 2026-08-26T20:49:07.000Z If you're exploring whether Discernible is the right fit for your organization or your own leadership development, we'd love to hear from you. When you reach out, tell us a little about your role, your organization, and what you're working through. The more context you share, the more useful our first conversation will be. We typically respond to all inquiries within two business days. [Schedule an intro call](https://calendly.com/melanie-discerniblecommunications/30min?ref=discernibleinc.com) ### About URL: https://www.discernibleinc.com/about/ Last updated: 2026-08-06T01:55:31.000Z Most communications support for security and privacy teams arrives after something goes wrong. Melanie Ensign built Discernible to change that. Melanie spent two decades leading security and privacy communications inside some of the world's most scrutinized organizations, including Facebook, Uber, and AT&T. In every role, she fell in love with security teams that were technically excellent but organizationally invisible, and communications teams that were waiting for a crisis rather than helping prevent one. When she brought these disciplines together — improving how security teams communicated with leadership, with peers, and across functions — teams began building political capital, change management got easier, and public apologies became less necessary. She founded Discernible to make that kind of support available to more organizations by contracting with a network of specialists across executive leadership, organizational behavior, engineering, risk management, legal, and product development to ensure clients get the right mix of domain expertise and industry experience dedicated to their specific challenges. Previously, Melanie led communications for the world's largest hacker community DEF CON for 10 years. She is also an accomplished scuba diver and draws on the discipline of managing high-stakes, high-uncertainty situations (where preparation and clear communication are often the difference between a near-miss and a catastrophe) in her work with security and privacy leaders. ### Privacy Policy URL: https://www.discernibleinc.com/privacy/ Last updated: 2026-07-07T21:34:39.000Z *Last Updated: July 7, 2026* We believe the way we operate should reflect the work we do helping security and privacy professionals build influence and trust. That means no creepy tracking and no unnecessary data collection. This Privacy Notice describes our data collection and use practices on the following platforms: - Our website DiscernibleInc.com - Our newsletters and subscription services, if you sign up for them - Discernible Slack communities This Privacy Notice does not apply to our professional services, which are governed by the contract we sign with institutions for specific engagements. #### **What Do We Collect?** If you browse our website, we collect data through Ghost's native analytics to understand how visitors interact with our content. Specifically, we track: - web traffic and page views (cookie-free, first-party, powered by [Tinybird](https://ghost.org/integrations/tinybird?ref=discernibleinc.com)) - newsletter open rates - newsletter link clicks - member sources (the traffic sources and posts that drive subscriber growth) - outbound link activity to understand which external links are most useful to our audience. Ghost's web analytics do not use cookies or persistent browser storage to identify you across sessions. When you are logged in as a member, Ghost may record which posts you view to help us understand what content is most relevant. This data is never shared with third parties. Ghost's privacy policy is available on their website [here](https://ghost.org/privacy?ref=discernibleinc.com). If you buy a subscription from our website, our payment processor Stripe, will collect information needed to manage that transaction. Their privacy policy is available on their website [here](https://stripe.com/privacy?ref=discernibleinc.com). If you sign up for any of our Slack communities, we collect your name, email address, username, and any content or information you choose to disclose in the Slack community. Only share what you’re comfortable with because other community members may see it, too. Slack also has its own privacy policy available [here](https://slack.com/trust/privacy/privacy-policy?ref=discernibleinc.com). #### **How Do We Use It?** Discernible is a deliberately small business. We're not in the business of large-scale data analytics, marketing, or exploiting personal data. We use your information to: - Deliver our services and digital products/content - Process purchases - Send our newsletter and track engagement - Support activity in our Slack community #### **Who Do We Share Your Data With** We share or manage your data with the following services: - Ghost (website hosting, newsletter, and membership management) - Stripe (payment processing) - Slack (community and subscriber engagement) - Professional advisors, including legal and accounting, for compliance purposes If we receive a subpoena or similar order from law enforcement or the government, we may be required to share your data with them after working with our legal counsel to ensure the request is legal and adequately narrow. We may also share your data in connection with a sale, acquisition, or merger of Discernible with another business. #### **Sale or Sharing of Sensitive Personal Data** We don't collect sensitive personal data and will never sell your data to anyone. We recommend you avoid sharing sensitive personal data in our Slack communities. #### **Do Not Track** We do not implement Do Not Track or Global Privacy Control signals because our website analytics are intentionally designed to be privacy-protective. Ghost's native analytics are cookie-free and do not use persistent tracking across sessions or devices, which means there is nothing to opt out of in the traditional sense. #### **Children** We do not knowingly collect information from children under the age of 18\. You must be 18 to sign up for our Slack communities. If we have inadvertently collected the information of a child under the age of 18 and you would like to contact us to remove your data, please contact us at info \[at\] DiscernibleInc.com. #### **Your Rights** You can email us info \[at\] DiscernibleInc.com to: - Request to receive a copy of your data - Correct any incorrect data we have on you - Delete your data from our systems, subject to our legal retention requirements If you sign up for our newsletter, you can unsubscribe at any time by clicking the unsubscribe link at the bottom of the newsletter or emailing us. If you wish to leave the Slack community, please use the app's features to manage your information. You may also email us for assistance. We will not discriminate against you for exercising any of your rights. #### **Storage and Security** We store your data on our servers in the United States. We may access your information from anywhere in the world to provide the services you request. We implement data retention policies on our services to minimize the period of time we store your data. However, some of our third-party suppliers may retain your data longer than our internally managed systems. We are required to retain some data to comply with laws or protect ourselves in the event of litigation. As a small business, we select platforms and services that have industry-standard security in place. However, no security program or control is 100% foolproof. #### **Third-Party Links, Sites, and Services** Discernible uses various technologies to provide its services. The following companies have their own privacy notices that govern how they use data when you interact with them. - Ghost (website, newsletter, subscriptions, and analytics): [https://ghost.org/privacy](https://ghost.org/privacy?ref=discernibleinc.com) - Stripe (payment processing): [https://stripe.com/privacy](https://stripe.com/privacy?ref=discernibleinc.com) - Slack (for Discernible Experience drills and community): [https://slack.com/trust/privacy/privacy-policy](https://slack.com/trust/privacy/privacy-policy?ref=discernibleinc.com) - Google Workspace (email, cloud storage): [https://policies.google.com/privacy](https://policies.google.com/privacy?ref=discernibleinc.com) If you have any questions about how those platforms are using your information, please review their privacy notices for more information. From time to time, Discernible content, including newsletters and Slack communities, may contain links to third-party websites or apps. Discernible is not responsible for the content and data practices of those sites and pages that you may visit if you click on those links. #### **Updates** We may update this policy at any time and will notify you as required by law. #### **Contact Us** For any questions about this privacy notice, please contact us at: *Discernible Inc.* *info \[at\] DiscernibleInc.com* *1717 N Bayshore Drive, Suite 108-15* *Miami, FL 33132* ### How we use AI URL: https://www.discernibleinc.com/how-we-use-ai/ Last updated: 2026-08-13T17:58:11.000Z Discernible uses AI as a tool in parts of our process. This page explains where and how. **Experience scenarios** When we build scenarios for Discernible Experience, the constraints, learning objectives, and instructional design come from our own experience as well as publicly disclosed incidents. This is the part that determines whether a scenario will teach what we need it to. We use AI to help develop technical details within those constraints, things like plausible system behaviors, technical artifacts, or implementation specifics that need to be accurate but aren't themselves the point of the exercise. AI doesn't design what participants practice or why, but it does help us build out the technical architecture once we've decided what it should be. **Blog post** We write our own posts and use AI as an editor for catching typos, grammar mistakes, and inconsistencies. The ideas, positions, and sourcing are our own. **What stays human** - What a scenario is designed to teach and why - The frameworks, arguments, and positions in our writing - Client-specific strategy and recommendations - Anything that requires judgment about a specific organization's risk, politics, or context *Questions about how something specific was developed? You can ask us directly* [*here*](https://discernibleinc.com/contact?ref=discernibleinc.com)*.* ## Posts ### Discernible Debrief: 9.9.2026 URL: https://www.discernibleinc.com/discernible-debrief-9-9-2026/ Last updated: 2026-09-11T12:00:29.000Z A flagged risk, marked "addressed," never reached the board. Two years later, a lawsuit surfaced it. This scenario is about the aftermath. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: The Firewall that Wasn’t URL: https://www.discernibleinc.com/discernible-experience-the-firewall-that-wasnt/ Last updated: 2026-09-10T01:00:40.000Z A risk assessment flagged the gap two years before the breach. It never reached the board. This drill puts participants in the room after it resurfaces in a lawsuit. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Debrief: 9.2.26 URL: https://www.discernibleinc.com/discernible-debrief-9-2-26/ Last updated: 2026-09-04T13:00:47.000Z An open source RCE spreads across ten county systems with no single owner, and one under an active election freeze. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: A Patch Nobody Owns URL: https://www.discernibleinc.com/discernible-experience-a-patch-nobody-owns-2/ Last updated: 2026-09-03T17:31:57.000Z An open source RCE hits ten county systems overnight, one under an election freeze. Practice coordinating urgent patches with zero authority to compel action. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: A Patch Nobody Owns URL: https://www.discernibleinc.com/discernible-experience-a-patch-nobody-owns/ Last updated: 2026-09-03T01:04:09.000Z An open source RCE hits ten county systems overnight, one under an election freeze. Practice coordinating urgent patches with zero authority to compel action. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Issue 65: Why Compliance Alone Fails to Build Trust URL: https://www.discernibleinc.com/issue-65-why-compliance-alone-fails-to-build-trust/ Last updated: 2026-09-01T16:17:02.000Z Security and privacy teams often satisfy the format of communication without accomplishing its purpose. Here's why that makes it harder to earn trust. _This post is for subscribers only._ ### Discernible Debrief: 8.26.26 URL: https://www.discernibleinc.com/discernible-debrief-8-26-26/ Last updated: 2026-08-28T12:00:07.000Z A hardware wallet maker confirms active exploitation of a years-old firmware flaw. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Objectives Before Rhetoric URL: https://www.discernibleinc.com/objectives-before-rhetoric/ Last updated: 2026-08-27T16:06:05.000Z In our August newsletter, we introduced [Barbara O'Keefe's message-design logic theory](https://en.wikipedia.org/wiki/Message%5Fdesign%5Flogic?ref=discernibleinc.com). [Sign up for the Discernible newsletter here](https://www.discernibleinc.com/) if you missed it and want the full breakdown. This post picks up where that issue left off. O'Keefe's framework identifies three ways people conceptualize communication. 1. **Expressive logic** treats a message as a direct channel for stating thoughts. 2. **Conventional logic** treats communication as a rule-governed exchange, following etiquette, roles, and established scripts. 3. **Rhetorical logic** treats a message as a tool for negotiating a shared reality, one that can serve multiple objectives at once. Decades of research on this framework find that rhetorical messages get judged as more competent, particularly in situations where the objectives are in tension with each other. Security and privacy teams live inside all of these situations. For example, an incident update has to be accurate, timely, and reassuring, often to audiences who have conflicting interests in what "reassuring" even means, while a new security policy or tool rollout has to change behavior without making people feel surveilled or blamed. These are rhetorical problems by definition, but most practitioners never get to apply rhetorical logic because they haven'tyet defined what the communication is supposed to accomplish. I realize that even the term “rhetorical logic” might sound too academic for some people, so here’s the gist: the potential impact of your communications is directly tied to how well you understand what the message needs to do. If you haven't done that work, you default to expressive logic (i.e. say what's technically true and hope it lands) or conventional logic (i.e. follow a static template or playbook) because you don't have a handle on an objective to design around. This is one of the most common issues I see working with security teams. Many self-proclaimed “good communicators” are focused so much on tactical execution, they’re really surprised when someone’s reaction reflects just how far they missed the mark. I was working on incident response with a security team, whose historical post-mortem default was to report what happened, in the order it happened, because they didn’t have any other defined communication objectives beyond simply publishing a report. This approach made it very difficult for customers to consume the details with an accurate understanding of importance and priority. It also forced them to scroll through a lot of text to find what they needed. Once we decided the objective was actually to preserve the trust of enterprise customers while the investigation is ongoing, they wrote a completely different update, even though the underlying facts were the same. It was a completely different message design, not merely word-smithing. The team now knew what the communication needed to accomplish and that informed just not what they wrote, but how. The same gap shows up in policy rollouts. Teams that haven’t defined the communication objective beyond "explain the new policy" often produce an explanation. That’s better than saying nothing, but it’s not really enough. However, if you can be specific in your defined communication objectives, such as "get engineering leads to enforce this without escalating to us every time," the finish line moves to produce something built to change behavior, not just transfer information. To be clear, both documents can be factually correct, yet only one of them is designed to do something. The second piece of this that gets missed is that rhetoric was never about *your* word choice. It's about *their* interpretation. Most security practitioners still approach message design from the sender's perspective. They’ll ask what the most accurate word is or what the most technically correct phrasing is to find something that sounds right to them. But rhetorical logic doesn't work from the sender's preferences. It works from how the recipient will receive and interpret what you send them, given their existing beliefs, their incentives, and what they're already primed to assume. The same sentence can land as reassuring or alarming, as a status update or an admission of failure, depending on who's reading it and what they walked in believing. Choosing words based on what feels precise to you, rather than what the recipient will do with them, is expressive logic and puts a limit on how impactul your message can be. This is why objectives have to come first. You can’t design for a recipient's interpretation if you haven't decided what you need that interpretation to be. Objective setting is the thing that makes rhetorical logic possible. The next time your team sits down to draft an incident update or a policy announcement, skip the template for five minutes. Write down what you need the reader to believe, feel, or do differently once they've read it. That sentence is the most important thing you’ll write. --- **Here’s a simplified example to illustrate how different objectives drive different execution for something like an incident update:** **Incident Facts:** - unauthorized access to an internal admin tool was detected and contained within 6 hours. - No customer data was accessed. - The root cause was a misconfigured access control that has since been fixed. - Enterprise customers have been asking your account team for updates. **Version 1**: - **Objective:** report what happened (no defined communication goal beyond "keep people informed") - **Message**: *We detected unauthorized access to an internal admin tool on July 29\. Our security team identified the access within 6 hours and revoked the credentials involved. Our investigation found the access was caused by a misconfigured access control policy. We have since corrected the configuration. Our investigation determined that no customer data was accessed during this incident. Please let us know if you have any questions.* This version is accurate and the default output of most templates. That’s why it reads like one. It leads with the breach, buries the "no customer data" finding in the middle, and closes with a passive invitation for questions. **Version 2**: - **Objective**: preserve enterprise customer trust while the investigation is ongoing - **Message**: *On July 29, our monitoring flagged unauthorized access to an internal admin tool, which we contained in under 6 hours. Our investigation confirmed that no customer data was accessed and the root cause was a misconfigured access control. We've corrected it, and we're adding automated policy drift detection that flags any admin tool whose access controls deviate from our baseline IAM configuration within minutes. Happy to walk your security team through the full timeline if that's useful.* This version opens with the impact and containment, because those are things an enterprise customer actually needs to know first to make informed decisions. It then names a specific, verifiable fix instead of a vague promise to improve. And it closes with a proactive offer for more support, which gives the recipient something productive to do with any anxiety or discomfort they're feeling. ### Discernible Experience: The Drain URL: https://www.discernibleinc.com/discernible-experience-the-drain/ Last updated: 2026-08-26T17:54:59.000Z A hardware wallet maker confirms active exploitation of a years-old firmware flaw. Participants practice recommending action under real uncertainty. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Debrief: 8.19.26 URL: https://www.discernibleinc.com/discernible-debrief-8-19-26/ Last updated: 2026-08-21T12:00:37.000Z A vendor replied fast and minimized a real vulnerability. This scenario practices holding your ground with evidence instead of not ultimatums. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: The First Response URL: https://www.discernibleinc.com/discernible-experience-the-first-response/ Last updated: 2026-08-19T20:04:39.000Z A vendor replied fast while minimizing a real IP-leak vulnerability. Practice the disclosure decisions between staying engaged and walking away entirely. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Debrief: 8.12.26 URL: https://www.discernibleinc.com/discernible-debrief-8-12-26/ Last updated: 2026-08-14T12:00:41.000Z Inside this week's scenario: a security engineer finds a subtle firmware flaw days before release and has to escalate it quickly and honestly. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: The Fallback Path URL: https://www.discernibleinc.com/discernible-experience-the-fallback-path/ Last updated: 2026-08-12T21:36:48.000Z A firmware security engineer finds a subtle RNG flaw days before release. Practice escalating uncertain findings under deadline pressure. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Issue 64: Thought leadership vs punditry URL: https://www.discernibleinc.com/issue-64-thought-leadership-vs-punditry-why-power-and-status-arent-the-same-thing-when-it-comes-to-influence/ Last updated: 2026-08-03T16:08:03.000Z Why thought leadership often becomes punditry instead, and why power and status aren't the same thing when it comes to real influence. _This post is for subscribers only._ ### Why Your Content Strategy Isn't Building the Influence You Expected URL: https://www.discernibleinc.com/why-your-content-strategy-isnt-building-the-influence-you-expected/ Last updated: 2026-08-02T20:38:03.000Z Most security professionals who tell me they want to build influence through thought leadership are doing punditry instead. Unfortunately, the difference between those two things can make any content strategy feel like running on a treadmill because contrary to what people often assume, the problem isn’t effort or visibility. The issue is that they’re confusing punditry tactics for thought leadership, and not getting the results they expected. So, what’s the difference? ## Punditry tactics don't produce thought leadership results Thought leadership and punditry aren’t synonyms or even two sides of the same coin. They’re different strategies with different mechanics, different audiences, and thus, fundamentally different outcomes. Punditry’s primary goal is to generate attention. It’s reactive, timely, and, when done well, it’s optimized for the moment. When something happens such as a major incident, a regulatory announcement, or a high-profile industry debate, the pundits move fast. They get impressions, shares, and sometimes, a short spike in followers. Although that attention is real (meaning, we can measure it), it’s also shallow and temporary, because it’s not attached to anything original. It’s a hijacking of someone else’s moment. Conversely, the reason to invest in thought leadership is to build credibility. It’s slower and harder, but its value compounds over time because it’s attached to *your* ideas, *your* frameworks, and *your* track record of being right about things that matter to you and your industry. The practitioners and executives who read/listen/watch your work come back not because something happened in the news but because they trust that you have something worth hearing. When you use punditry tactics and expect thought leadership results, you get neither. Instead, you end up with a content hamster wheel that demands constant output to maintain even modest visibility, with no accumulated credibility to show for it. **Punditry Tactics** - Reacting to incidents or industry moments you have no direct knowledge of. - Summarizing what other respected voices said and adding light commentary. - Publishing takes timed to news cycles rather than to the maturity of your own thinking. - Framing opinions as analysis without acknowledging the limits of what you actually know. To be clear, none of this is inherently malicious. Most people doing it genuinely believe they’re contributing something and sometimes they truly are. Explanation and context have real value, especially for less technical audiences trying to make sense of a complex situation. But the explanation isn’t the same as the original thought nor is visibility the same as influence. In my experience, punditry tactics are a primary driver of what Bob Lord calls "[hacklore](https://www.hacklore.org/?ref=discernibleinc.com)" — the cybersecurity equivalent of urban legends, where confident but inaccurate advice gets repeated so often it takes on the appearance of established wisdom. When practitioners optimize for timely reactions over original analysis, they don't just fail to build their own credibility. They actively degrade the quality of information circulating in the industry. **Thought Leadership Tactics** - Publishing something before the industry has fully formed a consensus on it. - Naming a problem that practitioners recognize but haven’t seen articulated. - Sharing a framework you developed from your own work, including what failed before you got it right. - Taking a position that could be wrong and defending it with evidence and reasoning. The common thread here is originality. You are starting something rather than responding and that’s a fundamentally different posture from punditry, producing fundamentally different results. 💡 A ****thought leader** is an individual or firm recognized as a foremost authority in a specific field. As the term implies, a thought leader leads others in the thinking around a given topic. **(*[**Wikipedia*](https://en.wikipedia.org/wiki/Thought%5Fleader?ref=discernibleinc.com)**)* ## Talking head vs. being in the room Why does this distinction even matter? Well, as someone who spent the first half of my career working in corporate communication and public relations functions, I often think about the difference between the TV talking head and the person in the room where decisions are made. The talking head is visible, trying to get quoted or secure airtime while sounding authoritative. But they’re on the outside, narrating their best guess at what’s happening inside. In my experience, someone doing genuine thought leadership gets called before the story even exists – when a policy decision is still being shaped, an industry working group is forming, or the people who will eventually make a public statement are still figuring out what they think. That’s the critical difference punditry vs. thought leadership produces over time. It’s not about more or less visibility, but a fundamentally different kind of access. One can put you in front of an audience, while the other puts you in the room. For example, when Anthropic launched [Project Glasswing](https://www.anthropic.com/glasswing?ref=discernibleinc.com) (a restricted initiative giving select organizations access to Claude Mythos Preview, an unreleased frontier model with significant cybersecurity capabilities) access wasn't distributed by popularity contest or follower count. The organizations that got early access had invested in the right relationships over time, relationships built on demonstrated expertise, credibility, and trust. The loudest voices in the industry weren't necessarily the ones invited to be in the room, and many of them seemed surprised. ## Why the confusion is so persistent Primarily because punditry gets faster, easier-to-measure feedback than thought leadership does. Impressions, likes, and follower counts tick up quickly when you’re riding a news cycle while the rewards for thought leadership are slower and harder to attribute, e.g. a speaking invitation, a board-level introduction, a peer who puts your name forward for a new opportunity, or an invitation to a working group that never gets announced publicly. Those outcomes don’t show up in a dashboard, so many practitioners optimize for what they can immediately see and end up with a content strategy that keeps them visible but never actually builds the influence they need for future advancement. I have to note that there’s also a risk dynamic at play. Punditry is safer because commenting on someone else’s situation carries far less professional exposure than staking a position about your own work, your own field, or the direction the industry should be going. Original thought leadership requires owning something that could be wrong and that can be genuinely uncomfortable for people. In my work with clients, sometimes they’re worried about who might disagree with them regardless of whether they’re right or not. When that comes up, we take a step back and focus on the stakeholders that actually matter to them. If there are genuine concerns about how a specific audience will react, we adjust the content accordingly. But if the fear is really about trolls or pundits (AKA people who will react loudly regardless of what you say), I remind them that not everyone's opinion matters on everything. Credibility doesn't come from being unassailable, but from learning, changing your mind when evidence warrants it, and being willing to share that journey publicly. That's what makes someone a respected thought leader over time, not the mere absence of critics. ## The question to ask yourself If you’ve been publishing consistently and you’re not seeing the influence results you expected, the answer probably isn’t more content, but *different* content. In the last six months, how many things have you published that originated from your own experience or analysis? Something that would still exist and matter regardless of what happened in the news or industry rumor mills. If the honest answer is not many or none, you have a tactics problem. Thought leadership is a long game that requires original thinking, the willingness to be wrong in public, and the communication skills to make complex ideas land with the specific audiences that matter to you. It doesn’t reward you on the same timeline as punditry, but it builds something punditry never can: credibility that holds when the news cycle moves on. That’s what creates influence. ### Discernible Debrief: 7.29.26 URL: https://www.discernibleinc.com/discernible-debrief-7-29-26/ Last updated: 2026-07-31T13:00:51.000Z A vendor breach hits the news. Your company never used the vendor, but a customer wants proof within 24 hours. Practice defending a "not affected" position. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: The Wrong List URL: https://www.discernibleinc.com/discernible-experience-the-wrong-list/ Last updated: 2026-07-30T14:00:39.000Z A vendor breach hits the news. Your company never used the vendor — but a customer wants proof within 24 hours. Practice defending a "not affected" position. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Debrief: 07.22.26 URL: https://www.discernibleinc.com/discernible-debrief-07-22-26/ Last updated: 2026-07-24T12:39:13.000Z This week's scenario explores a public CVE + a live exploit + the difference between "affected" and "exposed." _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: Dependency Window URL: https://www.discernibleinc.com/discernible-experience-dependency-window/ Last updated: 2026-07-23T13:52:48.000Z A public CVE, a live exploit, and 14 services flagged as affected. Step into the role of Application Security Engineer and scope what's actually exposed. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Debrief: 07.15.26 URL: https://www.discernibleinc.com/discernible-debrief-inside-this-weeks-ir-scenario-2/ Last updated: 2026-07-18T02:29:46.000Z This week's IR scenario: communicating when an extortion group's public deadline outruns what your investigation has actually confirmed. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: The Leak Site URL: https://www.discernibleinc.com/discernible-experience-the-leak-site/ Last updated: 2026-07-16T20:55:35.000Z An extortion group's leak site claims breach before the investigation confirms scope. This IR tabletop scenario trains precise, defensible communication under deadline pressure. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Debrief: 07.09.26 URL: https://www.discernibleinc.com/discernible-debrief-07-09-26/ Last updated: 2026-07-18T02:33:45.000Z A model suspension, a federal review, and a rumor racing ahead of the facts. This week's Discernible Experience scenario looks at holding the line on precision when speculation moves faster than truth. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: The Access Window URL: https://www.discernibleinc.com/july-8-the-access-window/ Last updated: 2026-07-09T18:51:36.000Z A newsletter debrief summarizing the Access Window scenario and the communication principles it illustrates for Discernible Experience subscribers. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Experience: Quiet Hours URL: https://www.discernibleinc.com/discernible-experience-quiet-hours/ Last updated: 2026-07-18T02:20:13.000Z A newsletter debrief summarizing the Quiet Hours scenario and the communication principles it illustrates for Discernible Experience subscribers. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Discernible Debrief: 07.01.26 URL: https://www.discernibleinc.com/quiet-hours-last-weeks-discernible-experience-scenario/ Last updated: 2026-07-18T02:22:01.000Z When no law compels you to act, what you choose to do reveals what your values are actually worth. Our most recent scenario is about a public safety tech company navigating a privacy violation with no breach, no notification requirement, and no easy answers. _This post is for subscribers on the Discernible Debrief, Discernible Experience and Discernible Experience Pro tiers only._ ### Don't Let AI Write Your Public Post-Mortem URL: https://www.discernibleinc.com/dont-let-ai-write-your-public-post-mortem/ Last updated: 2026-07-09T19:52:33.000Z There's a version of this post where I tell you that AI-generated public post-mortems are fine as a starting point and you just need to edit carefully for an external audience. That's not this post. AI can be a genuinely useful tool for a subset of communication work, but incident post-mortems are one of the places where I see it consistently making things worse, and understanding why starts with knowing what a public post-mortem is supposed to do in the first place. A public post-mortem isn't merely a record-keeping exercise. It's a communication to people who were affected by something that went wrong at your organization — people who want to know what happened, what it means for them, and whether they can trust you going forward. That communication requires *human* judgment your AI doesn't have, built on context your AI shouldn't have. # The training data problem The most widely used AI learns from patterns in existing public documents and most public incident post-mortems are bad. They're written either by technical teams who included everything and organized it for themselves, or by legal teams optimizing for liability rather than clarity and credibility. In both cases, the person who was actually affected can't find what they need, and that’s the corpus AI is currently learning from. When you ask AI to write your post-mortem, you're asking it to write something that looks like the average of what other organizations have published before. **The average is not a standard worth emulating**. If your goal is to communicate well, to actually maintain trust with the people who matter the most to your organization, then you need to do better than the average, and you need to do something different from the patterns AI has learned to replicate. # Structure is a communication decision, not a formatting preference How you organize information signals what you think matters and influences how it’s processed by other people. Lead with the timeline, and you're telling your reader that the chronological sequence of your internal investigation is the most important thing for them to understand — and maybe it is, but if it’s not, then leading with customer impact and actions required, demonstrates that you understand what they actually need to know. The point is that the decision matters. But AI doesn't make this distinction. It defaults to narrative structure because narrative structure is what appears most often in its training data. The result is a flood of lukewarm post-mortems that read like incident diaries: first this happened, then this happened, then we did this, and here's what we learned. That structure might satisfy a technical audience at a Black Hat talk, but doesn't serve the customer trying to evaluate their potential exposure and what to do next. Strategic structure — the kind that's organized around what your audience needs rather than what happened to *you* — requires understanding your audience, their concerns, and what decisions they're trying to make with the information you're giving them. That's not a pattern AI can extract from poorly structured public reports. # Volume is not thoroughness AI writes *a lot* and there’s a specific failure mode I see frequently in AI-generated post-mortems, namely that they're comprehensive in a way that creates noise rather than clarity. The result looks thorough, but it functions as camouflage — the information your reader actually needs is buried somewhere in the middle of a document that took three minutes to generate and will take twenty to read, answering few (if any) of the questions they came to get answers for. Good incident communications does the opposite, making the most important information impossible to miss, and deprioritizing everything that doesn't help the reader understand what happened and what to do about it. The editing required to get there is substantive and requires judgment about what matters to *your* specific stakeholders — something AI genuinely isn't equipped to provide. # If You Have to Use AI Anyway Unfortuantely, not every organization has communications support for security, let alone incidents. So, if AI is genuinely your best available option, the prompt matters significantly. If you've read the [Template Trap](https://www.discernibleinc.com/the-template-trap/), you already know where this is going. A multi--step AI prompt with a fixed order is a more sophisticated Mad Libs. The blanks are just harder to see. So before you use what follows, I want to acknowledge that it’s a floor, not a ceiling. It's better than asking AI to "write an incident post-mortem" and accepting whatever comes out, but it’s not what good looks like. Good looks like a communicator who understands your customers, your organization's relationship with them, and what this specific incident means for that relationship — making deliberate decisions about structure, tone, and content based on the situation in front of them. No prompt replaces that judgment. --- With that said, here's a starting point if you need it: *You are helping write a public incident post-mortem for \[COMPANY NAME\]. Your goal is to communicate clearly and honestly with customers who were affected by this incident, and to provide clarity for those who weren't. Prioritize their needs, not our CYA.* *Use the following incident details:* *\[PASTE INCIDENT SUMMARY HERE — do not include specific technical details or system architecture information that could be exploited in future attacks\]* *\[CUSTOMER CONTEXT: Describe your primary customer in 2-3 sentences. Who are they? What do they use your product for? What's at stake for them when something goes wrong? Example: "Our customers are small business owners who use our platform to process payments. Downtime or data exposure directly affects their revenue and their relationship with their own customers."\]* *\[IMPACT CONTEXT: What is the realistic worst-case concern for an affected customer reading this? What decision are they trying to make?\]* 💡 **If you can't fill these in, you're not ready to publish yet — AI-assisted or otherwise.* *Before you write anything, make structural decisions based on what affected customers most urgently need to know. Do not default to chronological order. Do not lead with what happened to us — lead with what it means for them. Organize every section around a reader who is trying to make a decision, not a reader who is trying to understand our experience.* *As you structure and write, apply these principles:* *— *Lead with impact and action.* What happened to customers, and what do they need to do right now? If they don't need to do anything, say so explicitly. Don't make them read to the end to find out.* *— *Be specific about who was affected.* Vague language about "some users" or "certain accounts" makes everyone assume the worst. If you don't know yet, say \[PLACEHOLDER: affected population still being determined\] rather than hedging.* *— *Put the timeline last.* A chronological account of our investigation is useful context, not the point. It belongs at the end, after customers have everything they need.* *— *Use an active voice and own the actions.* "We failed to detect..." not "The incident went undetected..." Passive voice reads as evasion.* *— *Cut marketing language entirely.* Do not use "we take security seriously," "as soon as we became aware," "we sincerely apologize for any inconvenience," or any variation of these. Do not minimize the impact or use language that suggests affected customers are overreacting.* *— *Omit operationally sensitive details.* Do not include specifics about how the incident was executed, what systems were involved at a technical level, or what detection gaps existed. These details belong in internal documentation, not public communications.* *— *Use placeholders for unknowns.* Where information is still being determined, insert a \[PLACEHOLDER\] rather than omitting the section or writing around the gap with vague language.* *— *Write at a tenth-grade reading level.** --- The placeholder instruction deserves emphasis regardless of whether you're using AI or writing this yourself because the common temptation when information is incomplete is to omit a section or hedge around the gap. Both usually backfire, so using explicit placeholders forces you to confront what you actually know, identify what still needs to be determined, and make a deliberate decision about what to share and when. A post-mortem full of placeholders also tells you something important about how complete your understanding of the incident actually is before you publish anything publicly. The best post-mortems I've seen were written by people who understood what their customers needed to know and had the discipline to organize everything else around that. AI can help you get words on a page, but getting them right is still your job. ### A Wishlist Is Not a Recommendation URL: https://www.discernibleinc.com/a-wishlist-is-not-a-recommendation/ Last updated: 2026-07-11T18:30:56.000Z I’ve seen a troubling communication pattern among CISOs, most often appearing in post-incident briefings, budget requests, or board presentations after a near-miss. A lot of security leaders are walking into executive meetings with a list of things that need to happen. This list is accurate and the items on it are both real and usually critical, and then the decision-makers either approve a fraction of it. They deprioritizethe rest or maybe they're simply nodding along during the whole discussion but do nothing. Unfortunately, the most common reaction I see from CISOs is to blame the audience by saying they don't understand the risk, don't take security seriously, or are distracted by other priorities. Sometimes that's true, but more often than not, the problem is the list itself. A wishlist is a collection of things you want. A recommendation is an argument for what to do and why – in a specific order, with visible reasoning about what each choice will and won't solve. These are not the same thing, and conflating them is one of the most common communication failures I see in security leadership. ## **What does a wishlist look like?** The security wishlists I’ve seen in my engagements with CISOs tend to share a few characteristics. First, they are comprehensive and include everything that needs fixing, often organized by category or team. Also, they are roughly equivalent in urgency, claiming that everything is important, which means nothing is truly prioritized. And finally, they’re light on reasoning – the items are presented as conclusions rather than deliberate (or dare I say, *strategic*) choices. Instead of strategic recommendations, I see a lot of this in executive communications: - ***"We need MFA on all privileged accounts."*** Agreed. Why is that first and not third? What does first mean — first to fund, first to implement, first to present to the board? - ***"We need to improve our detection capabilities."*** Almost certainly true. Detection of what, specifically? Compared to what baseline? What would success look like in twelve months, and how would you know if you got there? - ***"We need to address our third-party risk program."*** Does a bear shit in the woods? For your organization, is that a people problem, a process problem, or a tooling problem? What's the smallest version of this that can move the needle? When every item on a list is stated with equal weight and vagueness, you have not made a recommendation. You’ve now essentially asked someone else to do the prioritization for you, and when they do, you probably won’t like the outcome. ## **Why this happens** The good news is that, based on my experience, I don’t believe the wishlist pattern is a laziness problem. It usually comes from one of three places: - **Completeness anxiety** – Security professionals are trained to identify risk comprehensively, so leaving something off the list feels like professional negligence. But completeness and prioritization are different disciplines, and defaulting to completeness in an executive communication context almost always lands poorly. Your job at that moment, in that room, is not to document every risk, but to give leadership what they need to make an informed decision without having to become security experts (if they all become security experts, they don’t need you). - **Fear of accountability** – A ranked list is a commitment, and if you say "this is our top priority and here’s why," you can be held to it. A flat list may feel like it’s distributing accountability across everything, preventing any single item from being judged against your reasoning. Despite the instinct for self-protection, this is a poor communication strategy because it teaches your leadership team that your security recommendations lack ownership, so you end up with less influence over the outcome, not more. - **Genuine uncertainty –** Sometimes the prioritization work hasn't been done yet, or it was harder than the enumeration work, and time ran out. But uncertainty can also come from an incomplete threat model, dependencies on other teams' roadmaps, budget constraints that haven't been finalized, or a technical environment that changed between the last assessment and today's meeting. The wishlist can be a symptom of neglect, but it can also reflect honest complexity. Either way, presenting it as a recommendation moves the prioritization burden to an audience less equipped to do it. ## **What does a recommendation require?** Generally speaking, a real recommendation includes a few universal elements. First, a good recommendation includes **a specific claim about what to do.** Not "improve detection," but "deploy behavioral monitoring on the management platform with alerting on anomalous credential usage and off-hours access." It needs to be specific enough that someone outside your team could determine whether it happened. Next, **visible reasoning**. Not only what, but *why*, and why in this order rather than some other order. The reasoning should connect directly to what actually happened. For example, "We're recommending this first because it has the most direct causal connection to the incident we just had," is a different argument than "we're recommending this first because it's the fastest to implement." Both can be valid, but neither is implicit. Recommendations also have **an honest account of limitations** including what this investment will reduce and what it won't eliminate. This is where a lot of security leaders lose their nerve because they're afraid that naming residual risk will undermine the case for the investment entirely, but it rarely does. What undermines the case is the appearance of overselling. Executives have been sold certainty before (we all have) and we’ve all watched those certainties fail. Naming residual risk explicitly makes a recommendation credible, not weak. Finally, you’ll know if you’re presenting a real recommendation if you have **a clear sense of what "done" looks like**. Without a definition of success, you’re presenting an open-ended commitment with no endpoint, which is simply a project without a scope. Boo. 👎 ## **If you only make the case after something breaks, you're already behind.** There is a version of this problem that I see show up specifically in post-incident contexts. Security organizations that operate primarily in reactive mode, meaning they wait to make the investment case after an incident, when they think leadership will finally be receptive, are not managing risk. They’re managing by crisis. A window for investment often opens after an incident, and a list is presented, but only a fraction is approved. Once the urgency fades, attention moves elsewhere, and a new quiet period begins, during which time, the risks that didn't make the approved list continue to accumulate. The next incident may or may not reopen the window. I’ve seen the “governing by crisis” approach consistently deliver two damaging things: 1) it makes everything feel like a crisis, and 2) it ensures that the work of building durable, proactive security programs never quite gets done. The improvements that get funded are only those visible in the rearview mirror of the last incident, not necessarily the ones that prevent the next one. Security leaders who successfully break this cycle are continuously prioritizing, so they can walk into a leadership conversation on any day, not just after something goes wrong, and clearly state the three things that matter most right now, in this order, and why. Their recommendations don’t depend on an incident being credible – they’re credible because the reasoning is visible and the prioritization is defensible. They no longer need a crisis to be heard. ### You’re Allowed to Ask for Help With This URL: https://www.discernibleinc.com/youre-allowed-to-ask-for-help-with-this/ Last updated: 2026-07-11T18:40:47.000Z At some point, something changed. Maybe it was a high-profile incident where your company put you out front to answer for decisions you didn’t make. Maybe it was after months of trying to rebuild trust with cross-functional peers who still associate you with your predecessor’s reputation. Sometimes it’s quieter than that, a conversation with yourself on a Sunday night where you honestly don’t know if you want to keep doing this job or feel overwhelmed, exhausted, or disconnected. Whatever the moment was, you probably still showed up, stayed composed, and said the right things to the right people. But you probably didn’t figure out what you’d need next or who you should ask. Over time, I’ve learned to recognize the shape of these conversations before they begin. For example, a CISO sitting across from me, three weeks after their company used them as the public face of a breach they didn’t cause, trying to figure out how to talk about what happened without sounding either defensive or broken. Or all the times people told me they don’t know if they want to keep doing this job. There’ve been new CISOs trying to repair relationships with every cross-functional peer their predecessor torched, carrying the weight of damage they didn’t create; and fearful statements like, “I think what they’re doing might be illegal, and I don’t know what to say to anyone.” I’ve had versions of all of these conversations. They require something different from the craft skills that got me into the room and they’re worth talking about directly. ## The unique difficulty of your role CISOs operate in a structural isolation that most people outside the function don’t fully appreciate. You’re accountable for outcomes you often don’t control, expected to be the steady presence in a crisis regardless of whether you caused it or warned it was coming, and you’re frequently the most technically credible person in a room full of people who are nonetheless empowered to override you. And when something goes wrong, you’re often the most convenient face to put on it. Being sacrificed as the public representative of an organizational failure is a distinct professional experience. It’s not the same as being held accountable for something you actually did; it involves being asked to absorb consequences on behalf of a system and then continue operating in that system as if nothing happened. The communications challenge on the other side of that experience, e.g., how you talk about your tenure, your decisions, your value, and your next move, is genuinely hard. It goes well beyond talking points and requires working through what you actually believe about what happened before you can credibly say anything about it to anyone else. Walking into a role and discovering that your predecessor burned every relationship you need to do your job is not a simple messaging problem, either. That’s a trust deficit you’re being asked to repay on someone else’s debt. The work of rebuilding those relationships is fundamentally a communications problem covering how you show up, what you acknowledge, what you don’t, how you sequence the conversations, and how you establish your own credibility without throwing someone else under the bus. Strategy and interpersonal efforts have to work together, and getting either one wrong makes the other one even harder. ## Naming what you’re experiencing matters There’s a reason a lot of CISOs in difficult transitions don’t ask for help clearly: the instinct is to frame everything as a strategic or operational problem, because that feels more solvable and more professional than saying “I’m not sure I trust my own judgment right now” or “I’m exhausted in a way that isn’t going away.” Recognizing these feelings can help you build trust with yourself and others, which is essential for effective support. But the framing you use to describe your situation determines the kind of help you’re able to receive, which means the first and most useful thing you can do is slow down before you hire anyone, brief anyone, or start working on your narrative. Ask what you’re actually trying to figure out. Is it what to say, or whether you believe it? Is it how to repair a relationship, or whether it’s worth repairing? Is it how to position your next role, or whether you want a next role that looks like this one? Those questions change the work. And they’re the ones worth answering before anything else. ## What good communications help looks like It doesn’t start with messaging. It starts with someone asking you the questions above and taking the answers seriously. From there, the work looks different depending on where you are. If you’re coming out of a situation where you were put in front of regulators or policymakers to answer for something systemic, the goal is language for a complicated professional history that is honest without being self-destructive. Instead, it’s accurate, credible, and constructed in a way that preserves your ability to do the next thing. If you’re inheriting a damaged environment, it’s about sequencing the relationship repair conversations, knowing what to acknowledge versus what to leave alone, and building credibility without making the underlying situation worse. If you’re trying to figure out what you actually want to say about your career going forward — on stage, in interviews, and the rooms that matter — it’s about finding what you’ve genuinely learned rather than what you think sounds best. And if the question underneath everything else is whether you want to keep doing this job, that deserves a real answer before you invest in any narrative work at all. The narrative you build should be in service of something you actually want. ## A specific note on whistleblowing If you’re sitting with information about illegal or seriously unethical practices at your organization and trying to figure out what to say and to whom, the communications dimension is real, but it comes later. Before you work on how to say it, you need to understand your legal protections, your exposure, and your options. Talk to an attorney before you talk to anyone else. The communications strategy follows once you know what you’re actually trying to accomplish and what the realistic outcomes are. Trying to message your way through a situation you don’t yet have legal clarity on is how people make it worse. ## The ask you’re probably not making Most CISOs in difficult situations put their team first. Not always effectively, but consistently, meaning the effort, energy, and political capital they do have go toward fighting for resources, pushing back on unreasonable timelines, and making the case for their programs. Their own situation gets whatever is left over (if anything). If you’re in one of the situations this post describes, the most useful thing you can do right now is resist the instinct to reframe it as something more manageable than it is. Name it accurately — to yourself first, and then to whoever you bring in to help. The quality of the help you get will follow directly from the honesty of that conversation. ### 📬 Mailbag: We know people don't believe us when we say security is our top priority. How can we be more authentic in our communications? URL: https://www.discernibleinc.com/mailbag-we-know-people-dont-believe-us-when-we-say-security-is-our-top-priority-how-can-we-be-more-authentic-in-our-communications/ Last updated: 2026-07-11T18:47:24.000Z *Mailbag questions are submitted by our readers. Submit your own question for our team at discernibleinc.com/contact.* --- The real answer to this question is that if you're asking how to be more authentic during a high-stakes event, you're already too late. Authenticity is the cumulative result of consistent communication patterns your customers have observed over time. I hear this question a lot when working with clients on product vulnerabilities, privacy policy changes, and incident disclosures. I’ve seen organizations actually telling the truth about their security commitments, but customers interpret their communications as damage control or corporate spin. It’s typical for companies in this situation to obsess over specific word choices as if the right combination of language will suddenly make customers trust them. The problem is that many organizations only talk to customers about security when they have to. This means customers have no baseline for evaluating whether your communication is genuine. They have nothing to measure against, no established pattern to reference, no track record to inform their judgment. You've asked them to assume you’re being authentic despite providing no prior evidence to support it. This is the same strategy problem I've written about before, effective security communication requires building relationships and credibility before you need them. ## **The Problem** Is your organization silent about security during normal operations, then suddenly ask customers to trust them during the worst possible moment? This approach fundamentally ignores how authenticity works. Recent research on corporate social advocacy provides a framework that explains why this strategy fails. Specifically, [Dr. Ejae Lee's study on perceived authenticity](https://doi.org/10.1080/1062726X.2024.2437775?ref=discernibleinc.com) identifies four distinct dimensions that shape audiences' perceptions of organizational communication as genuine or performative: **truthfulness**, **persistence**, **commitment**, and **congruence**. I’ll go into the details of each one in a bit, but before I do, I need to tell you that **every single dimension requires a communication track record**. [Lee's research](https://instituteforpr.org/how-the-four-dimensions-of-authentic-advocacy-build-trust/?ref=discernibleinc.com) explains that perceived authenticity operates as a trust heuristic, meaning it’s a mental shortcut audiences use to evaluate the credibility of a communication quickly. But heuristics require historical data, and when customers lack that data, they default to skepticism. The same is true for your organization’s other publics, including employees, regulators, and partners. The organizations that are seen as authentic during security incidents are those that have been communicating regularly about security all along, treating security communication as ongoing stakeholder engagement. Now, let’s walk through each dimension and why it requires proactive communication. ## **1\. Truthfulness: You Can't Be Consistent Without a Pattern** Truthfulness is about whether your current message aligns with your established identity (not the identity your brand team carefully curated, but the one referenced behind your back*).* Customers evaluate this by asking: "Is this consistent with how this company normally talks to us about security?" If you've never talked to customers about security before, they have no reference point. Whatever you’re trying to communicate now exists in a vacuum. Customers read it and think, “*Do they really care about security and transparency, or are they only saying this because they got caught?”* Without prior communication to reference, customers assume the latter. When you announce mandatory MFA for customer accounts but have never previously explained your security philosophy, customers interpret it as reactive compliance rather than proactive protection. They lack the context to understand whether this reflects your values, so they’re skeptical of your motivations. Even though you’re now making a meaningful improvement to security, it points out what you could have been doing all along, but didn’t. *(Remember the 2010s when every tech company thought announcing MFA within a breach notification would help them appear proactive? lol. Just do it now.)* The goal when [framing security decisions](https://www.discernibleinc.com/why-effective-security-communication-starts-with-strategy-not-translations/) is to implement good security *and* communicate those choices in a way that demonstrates your values before incidents force the conversation. Organizations that score high on truthfulness have established these communication patterns with things like: - **Regular security updates** to customers about improvements, architecture changes, and threat landscape responses – not because anything went wrong, but because you're proactively building transparency and because if you were a customer, you’d want to know too. - **Consistent communication voice** across normal operations and incidents, because you've practiced that voice in low-stakes contexts and it’s now familiar to your stakeholders. - **Documented security values** that customers have seen demonstrated repeatedly through your ongoing communication. When these organizations experience incidents, customers can compare these notifications to the company’s typical security updates. Yep – same level of technical detail, same direct language, and same protective focus. The consistency builds credibility. Without a proactive, voluntary pattern, you're asking customers to trust that your crisis communication reflects your "real" values, even though you’ve given them no evidence of what those values look like in normal operations. It comes across as performative and inauthentic. ## **2\. Persistence: One Statement Doesn't Demonstrate Commitment** Persistence reflects whether you maintain your position in the face of pushback, criticism, or consequences. This dimension evaluates whether you care enough to keep stakeholders updated throughout an incident or to disappear after the initial disclosure, because no single communication can evaluate persistence. Persistence is demonstrated over time through repeated follow-through, and for most organizations, the goal is not to make incidents a common occurrence, so you need to create more touchpoints. When you say, “your security is important to us,” customers immediately question whether you’ve ever demonstrated that before. Without a track record of prioritizing security, your promise lacks credibility. Customers assume you'll fold once the news cycle moves on. Organizations that score high on persistence have demonstrated consistent follow-through long before any incident. In my experience, this means: - **Established update cadences** for security communications that customers can rely on, e.g., monthly security newsletters, quarterly transparency reports, and regular product security updates. Patch Tuesday is a long-standing example. - **Evidence of following through,** even when inconvenient, such as publishing vulnerability disclosures on schedule, acknowledging security improvements that may not be externally visible, and updating customers about how you protect them even when they’re not thinking about it. - **Track record of transparency** during uncomfortable moments, explaining service disruptions, acknowledging when you got something wrong, and explaining the fix. When you've consistently demonstrated persistence during normal operations, customers are more likely to believe in the commitments you make in response to an incident. They've watched you maintain communication and transparency when it wasn't legally required. This is why our consulting work starts with preparation and a foundation of proactive communication rather than crisis response statements. We’re intentionally not smoke-jumpers. We help clients establish incident communication protocols before they're needed, including pre-negotiating with legal what constitutes acceptable ongoing disclosure, identifying who owns strategic decisions and execution, and creating communication principles that maintain consistency even when the team is overwhelmed. We all know that trust isn’t built through mandatory notices. ## **3\. Commitment: Protective Intent Requires Demonstrated Priorities** Commitment captures whether customers believe you're motivated by genuine concern for them rather than legal liability. This dimension specifically evaluates, "Are they doing this to protect us, or to protect themselves?" Customers judge your commitment by observing your priorities over time (is anyone in your company tracking that?). What do you invest in when not legally required? What do you communicate about when nobody's forcing you? For example: - **Organization A** has never communicated with customers about security investments, threat response, or protective measures. They issue a breach notification that claims: "The security of customer data is our highest priority." - **Organization B** regularly communicates about security architecture improvements, vulnerability reports from external researchers, and proactive threat defense – all without an incident. When both organizations face incidents, Organization B's claim that security is a priority gains credibility because customers have observed them investing in and communicating about security, even when there was no crisis forcing them to do so. Organization A's identical claim reads as defensive positioning. Organizations that score high on commitment make their protective intent visible long before any incident. Without this, any claim about caring for customer security sounds like crisis CYA, and customers will assume you're motivated exclusively by liability, since they've never seen you prioritize their protection when you weren't legally required to. ## **4\. Congruence: Your Actions Must Visibly Match Your Words Over Time** Congruence is the alignment between what you tell people and what they can observe you actually doing. This dimension evaluates whether your security investments and behaviors align with what you claim to prioritize, and whether you communicate about security work during normal operations. If you don't, customers have no visibility into whether your actions match your stated values. Let’s say you mention in a breach notification that you’re “making significant security investments to prevent this from happening again" (oof!). Obviously, customers will be asking, "Like what? And how will we know you actually did it?" Six months later, customers see... nothing. No post-mortem report, no technical engineering discussions, and no visible security improvements in the product. Not even any updates on what changed. From the customer's perspective, you made a promise and disappeared. They have no way to evaluate whether you followed through. Even if you made substantial security investments, the lack of communication means customers can't observe the congruence between your promise and your actions. [Turning points that determine your organization's reputation](https://www.discernibleinc.com/risk-communications-recognizing-turning-points-and-managing-decisions/) go beyond public incidents and include all of the decisions about whether to communicate about the work you're doing to prevent them. Building a reputation for congruence means making your security work visible to customers on an ongoing basis, such as: - **Sharing what you're actually doing** on security. This doesn’t have to be a formal report; just regular updates on security improvements you've shipped, how you handled incidents (even minor ones), and what you're investing in and why. - **Visible follow-through** on commitments, and don’t make commitments if you’re not able/willing to monitor and report on your progress. - **Public documentation** of security improvements that customers can reference, including updated security pages, architecture blog posts, and changelog entries for security patches. We regularly work with clients preparing post-incident reports, and there’s often a familiar tension between legal wanting minimal detail and customers wanting meaningful transparency. The organizations that maintain congruence are those that have established those boundaries in advance, often through ongoing communication that builds norms about what level of technical detail is considered both safe and credible. But even more fundamentally, these organizations have established the habit of communicating about security work during normal operations. When incident response requires visible follow-through, they already have the communication channels, approval processes, and stakeholder relationships in place to demonstrate congruence. ## **What This Means for Your Organization** The next breach notification, privacy policy change, or vulnerability disclosure you face will be evaluated against the communication pattern you've established with customers. If that pattern is silence punctuated by legal requirements, customers will read your crisis communication through that trust-eroding lens. If you want customers to perceive your security communications as authentic, you need to build the infrastructure that makes authenticity possible: - Establish regular security communication cadence with customers before incidents require it. - Demonstrate persistence by following through on commitments during normal operations. - Make protective intent visible by voluntarily communicating about security investments and decisions. - Let customers observe congruence between your words and actions. Communication patterns established during normal operations set your authenticity baseline, so when serious incidents do occur, customers have already seen your proven track record. This mirrors [the same principle behind positive incident framing](https://www.discernibleinc.com/what-could-go-right/), building strategic communication capabilities before you need them, so you have options when the stakes are highest. ### The Threshold Moves With Practice URL: https://www.discernibleinc.com/the-threshold-moves-with-practice/ Last updated: 2026-07-11T18:48:31.000Z Years ago, my therapist recommended I read John Ratey's book [*Spark*](https://www.amazon.com/Spark-Revolutionary-Science-Exercise-Brain/dp/0316113514?ref=discernibleinc.com) because it explains the impact of consistent physical challenge on the brain and at a time when I was far more invested in my mental health than my fitness, that framing was the thing that finally made exercise feel worth doing. Ratey explains how low-level stress, applied consistently, raises the threshold at which your body mounts a full stress response. The field of science is called neurophysiology and includes the biology and chemistry behind how neurons fire, how the brain processes signals, and how those processes produce behavior, thought, and physical response. Ratey draws on this to explain how exercise changes brain chemistry, not just body composition. In a nutshell, he points out how **regular moderate stress makes our neurons more resilient to acute stress, shifting the trigger point.** What used to put you in fight-or-flight-or-freeze can eventually become manageable background noise. Ratey's focus is the relationship between exercise and the brain (my therapist knew she could strengthen my commitment to exercise if I understood it was an investment in caring for my brain), but the core principle extends even further and it’s something I think about often in my professional and personal life. I've been a scuba diver for years. When I started, the cognitive load of every dive was enormous — buoyancy, air consumption, depth, buddy checks, current, time, navigation, etc. Each variable demanded active attention and panic was one equipment malfunction away from becoming a real threat. That's not the case anymore. Consistent training didn't merely teach me what to do when something goes wrong underwater, it also moved those responses lower in my brain. The tasks that used to require deliberate thought, like clearing a flooded mask, responding to a free-flowing regulator, managing a controlled ascent when something goes sideways, now happen with less cognitive overhead. Essentially, my nervous system has been recalibrated and the threshold for what registers as a genuine emergency is higher because I've trained at the uncomfortable edge repeatedly enough that the edge itself moved. This is not the same thing as knowing the right procedure intellectually. You can memorize every dive table and emergency protocol and still freeze the first time visibility drops to zero and you can't tell which direction is up. Knowledge lives in your prefrontal cortex, but our trained responses live somewhere older and faster — and the goal of repetition is to move our knowledge to that same place. Cavern diving added another layer to this for me. [Stratis Kas, author of Close Calls](https://stratiskas.com/testimonialscc-2/?ref=discernibleinc.com), (an anthology of technical diving incidents) describes what it feels like to become disoriented in a cave, writing that unlike a car accident, where fear arrives and passes in seconds, getting lost in a cave means sustained, prolonged uncertainty. You process the fear, and then you reprocess it, over and over, while still needing to function. That specific experience of managing yourself across an extended incident rather than a single acute moment profoundly changes something in a diver. I've had moments in cavern dives where I had to stay methodical through conditions that had no quick resolution. It’s a different kind of training than drilling a single emergency response because what I'm really practicing is not coming apart over an extended period of time while scared and under pressure. I’ve observed the same logic in effective incident response. Most security teams practice incidents the way I used to do dive checklists as a newly-certified diver: reviewing the steps, confirming they know the procedure, and filing out reports. That's not nothing, but it's also not the same as training the nervous system. And it especially doesn't prepare you for the reality Kas describes and that many of us have learned throughout our careers in security — that serious incidents aren't over quickly. In fact, they can play out over weeks, months, and sometimes years. This kind of stress isn't a spike. It’s a sustained condition in which we have to operate, regulating our emotions and maintaining discipline in our strategy. With consistent, regular practice, you can recalibrate the stress threshold so that you enter your next prolonged event from a different starting point. The cave is still the cave, but you're not burning through your cognitive reserves in the first hour just managing the fact that it's happening**. Low-level, repeated stress exposure builds a nervous system that doesn't treat the hard thing as a complete surprise.** The Discernible Experience is built on exactly that premise. Weekly, hour-long sessions with a small group of security peers gives our subscribers the low-level stress exposure that shifts the threshold. When you're in a room where an incident scenario is unfolding in real time and you have to communicate decisions to a skeptical stakeholder (let’s be honest, it’s usually a lawyer), draft a customer notification under pressure, or coordinate messaging across sales, social media, and regulators simultaneously — that's the stimulus. But it’s no longer a catastrophic crisis stimulus. Instead, it’s a manageable, repeatable, uncomfortable-enough-to-matter stimulus. Do that enough times and your stress threshold for the real thing moves and the cognitive load drops. The tasks that used to consume enormous mental bandwidth, e.g. what do we say, to whom, in what order, with what level of detail, etc., start to run on a lower channel, leaving you with more capacity for high-judgement decision-making because the basic mechanics are no longer eating up your working memory. I also want to note an important reframe that would help a lot of organizations right now – **the goal isn't just to survive the big incidents, but to use the smaller ones to our advantage.** Every minor security event your organization responds to is a training stimulus, if you treat it that way. The team that debrefs a low-severity phishing response with the same rigor as a disruptive ransomware event is building the same kind of recalibration I got from cavern diving because we grow more not from the catastrophic moment, but from the accumulated reps at the uncomfortable edge. Ultimately, the big incidents become less consequential because the small ones already moved the threshold. There's something else worth explicitly naming here because it's where most security communication programs stop too short. Ratey’s principle applies not just to incident response, but to proactive security communication in general. Security leaders who communicate regularly with their boards, peers, and cross functional teams (and not only during crises) are doing the equivalent of consistent low-level training for these relationships. They're building a nervous system, organizationally speaking, that doesn't spike when a hard conversation needs to happen, meaning the company’s relationship with customers or regulators isn't a crisis communication relationship and your relationship with the CEO doesn't depend on a breach to activate it. Voluntary, routine security communication is how you raise the organizational stress threshold before you need it. By the time a serious incident hits, the channels exist, the trust is established, and the cognitive load of "how do I explain this to people who don't share my mental model" is lower because you've done the reps. That's the architecture of truly effective security communication programs. It’s not about a communication plan that only activates during incidents. It’s a communication practice that makes incidents less catastrophic when they arrive. Ratey's point, at its core, is that the brain is trainable in ways we tend to underestimate and challenge, applied consistently and at the right level, makes us more capable, not just more knowledgeable. That's as true underwater and in a cave as it is in the quarterly board meeting where a CISO explains risk tolerance to people whose job is not to know how CVEs are issued. The whole reason for building the practice before you need it is that practice moves the threshold. ### Embracing Morbid Curiosity: What Horror Fans Can Teach Us About Incident Response URL: https://www.discernibleinc.com/embracing-morbid-curiosity-what-horror-fans-can-teach-us-about-incident-response/ Last updated: 2026-07-11T21:59:15.000Z When psychologist [Coltan Scrivner](https://www.coltanscrivner.com/?ref=discernibleinc.com) surveyed people during the early months of the COVID-19 pandemic, he discovered that horror movie fans showed greater psychological resilience and less distress than their peers who avoided scary content. Even more intriguing, people who regularly watched "prepper" genres like zombie apocalypse and pandemic films reported feeling more prepared for the crisis unfolding around them. This finding was interesting to me and I wondered if there’s anything we can learn from this research to better understand how to build resilience in incident response teams. ## **Understanding Morbid Curiosity** Scrivner defines morbid curiosity as an interest in information about danger or threats. As he's quick to point out, "morbid" refers to the content itself (things that could lead to harm), not that curiosity itself is unhealthy. In fact, his research suggests that morbid curiosity serves an adaptive function, helping us learn about dangers without experiencing them firsthand. From an evolutionary perspective, animals that are curious about predators (from a safe distance) have a better chance of survival than the one that remains blissfully ignorant until the threat is immediate. Humans take this a step further through our capacity for storytelling and fictional simulations, where we can learn about threats through narratives, practicing our responses long before we face real risk. In their[ 2021 study published in *Personality and Individual Differences*](https://www.sciencedirect.com/science/article/pii/S0191886920305882?ref=discernibleinc.com), Scrivner and his colleagues found that engagement with frightening fictional experiences acts as a kind of simulation that allows us to gather information and model possible scenarios in a safe environment. During the pandemic, this translated into measurable benefits as horror fans experienced less psychological distress, and fans of apocalyptic genres reported being better prepared for the disruptions that followed. ## **The Incident Response Parallel** As I thought about this more in the context of incident response preparedness, I noted a few parallels. Just as horror fans practice emotional regulation by repeatedly exposing themselves to controlled fear, incident response professionals can build psychological resilience through regular drill scenarios. Each tabletop exercise or simulated incident is an opportunity to experience the stress, uncertainty, and pressure of a real incident without the actual business impact, data loss, or career consequences. In my work, this extends beyond technical skills or even practicing procedures and refining playbooks because the psychological dimension is just as important. Scrivner's research suggests that the kind of drills Discernible runs for our subscribers every week can help them build emotional regulation under pressure and mental libraries of threat scenarios. Frequent exposure to simulated stimuli helps build resistance to a fight-flight-or-freeze response because you’re learning how to keep your analytical brain engaged even when adrenaline is flowing. Each Discernible Experience adds to your repository of "what could go wrong" patterns. Like horror fans who've internalized countless variations of danger, security professionals who drill regularly develop richer mental models of how attacks unfold, where things typically break down, and what unexpected complications might emerge. To help security teams build genuine resilience, we need to understand how people learn from controlled exposure to danger. Scrivner's research emphasizes that horror works because it provides a "safe space" to experience danger. The horror fan knows they can walk out of the theater, and participants in our drills know the debrief is coming in an hour. This psychological safety is crucial because without it, the experience becomes genuinely traumatic rather than training. We added an additional layer of safety to Discernible Experience by having participants practice with industry peers rather than their own teams. You're not performing in front of your boss or colleagues who might judge your decisions. This removes the career risk that often makes internal tabletops feel high-stakes. You can ask "dumb" questions, make mistakes, try unconventional approaches, and admit uncertainty without worrying about how it looks on your next performance review. The psychological safety to experiment supports genuine learning. But within that safe container, unpredictability matters. Horror movies are scary because you don't know exactly what's coming next. Similarly, the most valuable drills maintain some element of surprise. If participants can predict every twist, they're following a script, not practicing real-time decision-making. This tension between safety and unpredictability shaped the core design decisions of Discernible Experience. Critically, weekly drills prevent the "cramming" problem common to many tabletops, which occur so infrequently that they become high-stakes events people dread. The pressure is often so intense that it interferes with learning and retention. Weekly simulations normalize the experience as part of how your team operates, not a special occasion to be anxious about. ## **Different Every Time** The second key insight from Scrivner's research is that variety matters. Most horror fans don't watch the same movie over and over. They seek out different subgenres, different types of scares, and different threats. This variety prevents desensitization while building a broader repertoire of responses. Similarly, if we practiced the same incident scenario every week, we’d end up memorizing a script rather than building genuine adaptability. We design each Discernible Experience to be different: - **Different incident types:** The communication demands of a ransomware attack differ from those of an insider threat or a supply chain compromise. Each incident type creates different stakeholder concerns, different information gaps, different pressures on what to say and when. - **Different stakeholder dynamics:** Sometimes you’re managing upward to executives who want immediate answers you don’t have. Other times you’re fielding questions from customers, or coordinating messages across legal, PR, and engineering teams with competing priorities. - **Different states of information:** Some drills put you in the fog of early incident response, when you know something is wrong but not what or how bad it is. Others place you mid-incident when you understand the problem but are still containing it. Still others focus on post-incident communication when you know what happened but must decide what to disclose. - **Different communication channels:** One week, you’re drafting internal status updates and the next you’re preparing talking points for a customer call. Then you’re crafting a post mortem or responding to board member questions. This variety prevents the experience from becoming rote while ensuring participants build communication skills that transfer across incident types, ultimately developing the judgment to know what information matters to which audiences, how to communicate clearly under uncertainty, and how to maintain credibility when the situation is still evolving. ## **The Right Amount of Challenge** Finally, Scrivner's framework suggests there's an optimal level of exposure to frightening content. Too little and you don't build resilience; too much and you risk desensitization or even trauma. We found that sweet spot in the combination of short and frequent sessions. One hour of high-intensity simulation is enough to activate stress responses and force real decision-making, but not so much that people burn out. Weekly repetition builds resilience through consistent practice, but the variety prevents desensitization. If drills become rote or predictable, you've lost the beneficial tension and folks go through the motions without genuinely engaging. If they're so intense that people dread them, you've crossed into harmful stress. One-hour weekly drills, different every time, keep people in that productive middle ground where they're challenged enough to grow but safe enough to experiment and learn. ## **Putting It Into Practice** If you're designing an incident response program, consider these questions through the lens of Scrivner's morbid curiosity research: 1. Does your team have enough exposure to simulated threats to build resilience, or are drills so infrequent that each one feels novel and overwhelming? 2. Are your drills predictable enough that people feel safe, but unpredictable enough that they're still practicing real-time decision-making? 3. Do you track psychological outcomes alongside technical performance? Are people building confidence or developing anxiety? 4. Are you creating opportunities for "morbid curiosity,” meaning letting team members explore new ideas in safe environments? The goal isn't to turn your security team into horror fans (though if they already are, that might be a promising sign). The goal is to borrow what works from how humans have always prepared for danger, through controlled exposure, storytelling, and practice that feels real enough to matter but safe enough to learn from. Horror movies won't teach you how to respond to every attack, but the psychology of why horror fans thrived during a pandemic might teach us how to build security teams that can face any incident with resilience, capability, and maybe even a little bit of that morbidly curious excitement about seeing what happens next. --- **Want to build your team's incident communication resilience?* Learn more about* [*Discernible Experience*](http://discernibleinc.com/experience?ref=discernibleinc.com) *— our weekly drills designed around the psychology of how people actually learn from controlled exposure to crisis scenarios. Or* [*contact us*](http://discernibleinc.com/contact?ref=discernibleinc.com) *to discuss how we can help your team build the communication capabilities and psychological readiness you need before the next incident hits.* ### The Privacy Professional's Influence Starter Kit URL: https://www.discernibleinc.com/the-privacy-professionals-influence-starter-kit/ Last updated: 2026-07-11T22:09:59.000Z ## **Nobody Gave You a Playbook. Here's Where to Start.** In a recent LinkedIn Live conversation, privacy law scholar Daniel Solove made an observation that stuck with me: there's no industry-provided playbook for how privacy professionals figure out how to influence the business or what skills they need to elevate the profession beyond a compliance cost center. (Check out Dan’s YouTube recording [here](https://www.youtube.com/watch?v=njMFfr2euxw&ref=discernibleinc.com).) He's right. And the gap is costly. Privacy professionals spend years developing deep expertise in data protection law, regulatory frameworks, and risk assessment. What they often don't develop in time (because no one tells them they need to) are the communication skills required to turn that expertise into business decisions, behavior change, and resource allocation. The result is technically brilliant people who struggle to get their organizations to actually do anything with what they know. I’m writing this post as a starter kit – a curated collection of concepts and resources to help privacy professionals begin developing the organizational influence skills that their technical training missed. Consider it a first step toward closing a gap the industry has left open for too long. ## **Why This Matters for Privacy Professionals Specifically** Privacy teams occupy a uniquely difficult organizational position, operating in the space of risk prevention and regulatory compliance, areas where success is often invisible, and failure is compounding. That makes the job's political dimension especially challenging. You may have an ironclad legal analysis and know exactly what needs to change. Still, if you can't build support across product, engineering, and executive leadership (and if you haven't cultivated those relationships before you need them), then your expertise will sit collecting dust while the organization charges ahead. The skills that close this gap are strategic communication capabilities, including how to frame arguments for different audiences, build coalitions across functions, negotiate when interests diverge, and move an organization toward a decision it's resistant to making. The good news is that these are learnable skills, and there’s already a rich body of academic and professional literature that has been growing for decades. Privacy professionals just haven't been pointed toward it – until now. ## **The Three Capabilities You Should Develop First** Before I share my favorite resources, it helps to understand what you're building toward. Based on what I see in my work with privacy executives and their teams, I recommend starting with the following areas because they yield the highest leverage if you want more organizational influence: - **Communication as strategy, not translation.** Most privacy professionals approach business communication like translators, translating regulatory language into "plain English." This misses the point. Effective organizational communication goes well beyond simplifying concepts (and sometimes you shouldn’t) to understanding what a specific audience needs to believe or understand to take a specific action, and then constructing the argument that gets them there. This is a fundamentally different skill set than merely translating legalese, and it starts with clarity about outcomes before you ever think about words. - **Negotiation and influence without authority.** Privacy professionals rarely have direct authority over the decisions they care most about. They need to influence product roadmaps they don't control, competitive positions they didn't set, and engineering priorities they can't mandate. The academic literature on negotiation and principled persuasion is rich and directly applicable here, especially frameworks that help you understand stakeholders’ true interests beneath their stated positions, identify trade-offs, and find paths to success when your explicit leverage is limited. - **Coalition-building as infrastructure.** Individual relationships with sympathetic colleagues aren't the same as a coalition. A coalition is a network of stakeholders who understand your perspective, who have reason to support your goals, and who you've cultivated *before* you need them. Privacy professionals who operate independently or reactively (reaching out when they have a problem) consistently underperform those who invest in reliable relationships as a standing practice. This is [corporate anthropology](https://discernibleinc.com/blog/boost-your-teams-influence-with-corporate-anthropology-3-steps?rq=anthropology&ref=discernibleinc.com) in practice. ## **Where to Start** What follows is a curated (not exhaustive) starting point to introduce you to ideas that don't typically appear in privacy training programs and to provide practical frameworks you can apply immediately. ### **Books** Start with two books that work well in sequence: - ***Getting to Yes*** by Roger Fisher and William Ury remains the foundational text on principled negotiation and on separating positions from interests to find agreements that actually hold. It's short, clear, and directly applicable to the internal negotiations privacy professionals face constantly. - Once you've read it, pick up ***Why Should the Boss Listen to You?*** by James Lukaszewski, a crisis management veteran who writes specifically about how technical and staff professionals can earn and keep the attention of senior leaders. His framework for becoming indispensable to decision-makers is more directly relevant to the privacy professional's situation than almost anything else I’ve seen so far in the leadership communication genre. ### **Podcasts** - [**If/Then**](https://www.gsb.stanford.edu/insights/if-then-podcast?ref=discernibleinc.com) from Stanford Graduate School of Business applies behavioral science and organizational research to practical business questions. It's the kind of show that helps you understand *why* people and organizations behave the way they do — which is foundational to influencing them. - [**HBR IdeaCast**](https://hbr.org/podcasts/ideacast?ref=discernibleinc.com) and the broader HBR podcast network cover leadership, communication, and organizational dynamics in accessible, research-grounded formats. The HBR On Leadership series, in particular, is worth working through. - [**Hidden Brain**](https://www.hiddenbrain.org/?ref=discernibleinc.com) with Shankar Vedantam is essential listening for anyone trying to understand human behavior and organizational dynamics. Three episodes are especially relevant:[ ](https://hiddenbrain.org/podcast/we-need-to-talk/?ref=discernibleinc.com) - [We Need to Talk](https://hiddenbrain.org/podcast/we-need-to-talk/?ref=discernibleinc.com), in which behavioral scientist Alison Wood Brooks breaks down the science of conversation and why most of us are worse at it than we think - [Do Less](https://hiddenbrain.org/podcast/do-less/?ref=discernibleinc.com), on why we systematically overlook subtraction as a strategy — a directly applicable insight for privacy professionals who need to make the case for streamlined, rather than additive, data practices. - [I'm Right, You're Wrong](https://www.npr.org/2017/12/25/572162132/enter-title?ref=discernibleinc.com), which examines why data alone rarely changes minds and what actually does - [**Ologies with Alie Ward**](https://www.alieward.com/ologies?ref=discernibleinc.com) takes a rigorous but accessible approach to explaining how experts in obscure fields actually think. The episode[ Andragogology](https://podcasts.apple.com/us/podcast/ologies-with-alie-ward/id1278815517?i=1000659568048&ref=discernibleinc.com) (the science of how adults learn) is particularly useful for privacy professionals trying to shift ingrained organizational behaviors. ### **Articles and Academic Resources** The research literature on organizational influence and communication is rich and surprisingly readable when you know where to look. Here are a few pieces worth your time: - [The Secret to Building Resilience](https://hbr.org/2021/01/the-secret-to-building-resilience?ref=discernibleinc.com) (HBR, Cross, Dillon & Greenberg, 2021) reframes resilience as a relational asset rather than an individual trait; a mindset shift with direct implications for how privacy professionals should think about investing in relationships before they need them. If you want to go deeper into the research literature, these studies offer insight into organizational influence, communication effectiveness, and the psychology of persuasion: - Research from the[ Strategic Management Journal](https://sms.onlinelibrary.wiley.com/doi/epdf/10.1002/smj.274?ref=discernibleinc.com) on competitive dynamics - Work from[ Human Communication Research](https://academic.oup.com/hcr/article-abstract/49/4/383/7194689?redirectedFrom=fulltext&ref=discernibleinc.com) on how messages land - Two studies from the[ Journal of Organizational Behavior](https://onlinelibrary.wiley.com/doi/full/10.1002/job.2738?ref=discernibleinc.com) (and[ here](https://onlinelibrary.wiley.com/share/DA7QU2ZZVW4J3ZRSQBQS?target=10.1002/job.2628&ref=discernibleinc.com)) on workplace influence and behavior If you want to see these ideas applied directly to privacy work, our own post [Privacy Needs a Better Story](https://www.discernibleinc.com/privacy-needs-a-better-story/) walks through how framing theory and the Ladder of Inference apply to the specific challenge of positioning privacy as business value rather than compliance overhead. It's a useful bridge between the communication theory literature and the day-to-day reality of making the case internally. ### **The Discernible Perspectives Newsletter** All of the resources above have appeared in previous issues of our monthly [newsletter](https://www.discernibleinc.com/), which covers the current privacy and security communications landscape, communication theory applied to real-world situations, the latest in communications research, and a recommended podcast episode each month. If you want a steady stream of relevant reading without having to find it yourself, subscribing to this newsletter is the most efficient path. ## **A Note on What to Do Next** Reading about influence and actually developing organizational credibility are different things. The resources above will give you conceptual frameworks and language for what you're observing in your own organization. Still, the real work happens in practice, trying a different framing in your next cross-functional meeting, mapping stakeholder interests before your next budget ask, building one influential relationship this quarter that you don't currently have. Thinking strategically about relationships, timing, and organizational dynamicsis is how professionals with limited formal authority secure outcomes. Privacy professionals who resist this framing tend to find themselves technically right and organizationally irrelevant, while the ones who embrace it are building the kind of sustained influence that moves organizations. --- *This post is part of Discernible's ongoing work helping security and privacy professionals build the communication capabilities and organizational influence they need to do their jobs effectively. If you're working through these challenges with your team,* [*we'd love to talk*](http://discernibleinc.com/contact?ref=discernibleinc.com)*.* ### Why Are CISOs Afraid of Power? URL: https://www.discernibleinc.com/why-are-cisos-afraid-of-power/ Last updated: 2026-06-25T20:47:28.000Z I've worked with security leaders for two decades, and I keep seeing the same troubling pattern. Many CISOs complain constantly about their lack of influence. They're frustrated that executives don't prioritize security investments, that other departments resist their initiatives, and that they're brought into strategic decisions too late or not at all. But I’ve seen many of these same CISOs actively avoiding the very activities that would give them the power they claim to want. Political capital isn't bestowed by technical competence alone (everyone sitting around the table is a technical expert in their respective domain). It requires deliberate relationship-building, strategic coalition formation, and a willingness to engage in organizational dynamics that many security professionals find distasteful. The CISO role is inherently political, yet too many security leaders approach it as a purely technical challenge. Here are a few ways I've seen CISOs sabotage their own influence. ## **Self-Isolating** A lot of CISOs (especially less-experienced ones) tend to hunker down in their security bunkers, emerging only to deliver bad news or demand compliance with a new policy rollout. I see this self-isolation manifesting most often as minimal cross-departmental engagement, communication limited to security incidents or policy changes, and an "us versus them" mentality that positions security as separate from (and often opposed to) the rest of the business. Over the past 5 years, we’ve run dozens of message-testing focus groups, and the #1 keyword that turns off security buyers is “collaboration” because it implies group work with people who don’t report to you. That’s a problem. The most effective CISOs I work with understand something their peers miss. You don't need to convert people to a new religion to get them into the church. A potluck works just fine, and the results are the same. Stop waiting for other departments to come to you with the "right" level of passion or commitment to security. Instead, meet them where they are. Attend their team meetings. Understand their objectives and constraints. Find ways to make security an invaluable champion of their goals rather than an obstacle or distraction. You'll never achieve your security objectives alone. You need allies across the organization who understand that your success is tied to theirs, even if they never become a true believer in the security religion – you don’t need their soul, only their cooperation (or in some cases, to simply stay out of the way). These relationships require consistent and authentic interpersonal interactions that demonstrates you care about their success as much as you care about your own. It’s not an awareness campaign; it’s just not. ## **Mistaking Correctness for Effectiveness** I've watched too many CISOs operate under the dangerous misconception that being technically correct will ultimately win the day, assuming that if they present the right data, the perfect risk assessment, or the most compelling maturity statistics, executives will naturally prioritize security investments. This is a fantasy, folks. The CISO role is fundamentally political. Your job is to make security an invaluable business asset. And before anyone clutches their pearls, there are more lucrative career paths in security if you want to prioritize being right over being effective. But if you want a job where technical correctness is the primary currency, don’t become a CISO. I honestly wish our industry would elevate the profile of these alternative roles just as much as we’ve idolized the CISO path. It might be the right choice for some, but not for everyone, and we need to talk more about other ambitions you can pursue in this field. However, if you do choose the CISO path, you're choosing a role where influence matters more than being right, and you need to be skilled at reading the room and choosing your battles wisely. Not every security risk requires a full-court press with the executive team. Learn to distinguish between genuine business-critical risks and issues that you can manage through tactical solutions or accept as residual risk at the appropriate level of the organization (with the appropriate business lead documenting that acceptance, not you). Stop talking about attack vectors and start talking about customer trust, operational resilience, and competitive advantage. The C-suite is not impressed by your security architecture. They care about whether you're protecting the assets that matter to the business model. And here's something I tell every CISO I coach — if the only time executives hear from you is during an incident or when you’re asked to report at a regularly-scheduled meeting, you're already losing. Effective CISOs consistently create value for their peers, establishing themselves as trusted advisors long before they need to ask for anything or get coerced into singing for their supper. To be clear, I’m not advocating that anyone abandon their principles or accept unreasonable risk – but I am encouraging you to recognize that organizational change requires persuasion, trust, and strategic thinking, not only technical competence. It’s not an accident that the security leaders who build substantial political capital are the ones willing to engage in the messy, interpersonal work of organizational influence. That’s the job. ## **Not Understanding Executives** Here's a question I ask that routinely exposes the gap between CISOs' stated desires and their actual behavior. When was the last time you talked to the security teams at companies where your board members currently work or previously worked? If you're like most CISOs I see complaining on social media, the answer is "never." And yet these same security leaders will spend hours complaining that their board doesn't understand security, doesn't prioritize it appropriately, and can't grasp the risks the organization faces. This is willful ignorance masquerading as victimhood. Your board members have extensive business experience, and they've seen security programs succeed and fail across multiple organizations. And they've formed opinions about security based on those experiences. If you want to influence them, you need to understand where they're coming from. What security incidents have they witnessed firsthand? What security leaders have impressed them, and what behaviors or approaches earned their respect? What security investments have they seen succeed, and which ones became budget black holes with little measurable impact? This information is often available if you ask for it. Reach out to security leaders at your board members' other portfolio companies or previous organizations. Asking peer security professionals about their experiences working with shared board members is a no-brainer, and most security leaders I work with are willing to have these conversations because they understand the value of shared intelligence. Beyond board members, take time to understand your executive peers as individuals with their own objectives, constraints, and career aspirations. Nobody is obstinately refusing to fund security because they hate you (unless you deserve it), but remember that they’re managing dozens of competing investment priorities with limited capital. When you understand the context in which your executives operate, you can frame security initiatives to align with their objectives rather than compete with them, anticipate their concerns, and address them proactively. The goal is to identify opportunities where security investments genuinely enable business outcomes rather than just reduce risk (unless you want to continue to be treated as a cost center). ## **Hoarding Influence Instead of Multiplying It** The most significant missed opportunity I see is CISOs failing to build political capital through their teams. Many security leaders operate as solo practitioners when it comes to organizational influence and while they might be working on their own executive relationships, they're leaving their teams completely unprepared to build credibility and trust across the organization. If you empower every member of your security team to earn influence in their daily interactions, you multiply your political capital across dozens of relationships simultaneously. Instead of one CISO trying to convince executives that security matters, you have an entire team of security professionals building trust with engineering, product, operations, marketing, and finance every single day. Yet how many CISOs are actually training their teams in stakeholder communication? How many are coaching their security engineers on how to negotiate security outcomes into product roadmaps? How many are giving their team members the tools and support to become trusted advisors rather than rule enforcers? The answer, for most organizations, before we start working together, is effectively none. Instead, security teams are trained exclusively on domain expertise, leaving them unprepared for the interpersonal and communication challenges that determine whether their recommendations are actually implemented. Then CISOs wonder why their teams are seen as obstacles rather than enablers, why security initiatives face resistance, and why they can't scale their influence beyond their own direct interactions. Leading a movement means training your team on communication and influence skills that work in their respective context. It also means creating opportunities for your team to build relationships. Don't be the sole point of contact between security and other departments. Instead, connect your team members with peers across the organization, and encourage them to attend cross-functional meetings, contribute to projects outside security, and establish themselves as partners to critical business functions. If you're isolated, your team will be isolated. If you position security as separate from the business, they will too. If you only engage with other departments during crises, that's the pattern your team will replicate. And finally, leading a movement means giving your team permission to prioritize relationships. If your team believes its job is solely to find problems and report them, it'll optimize for that, often at the expense of the trust and credibility needed to actually fix those issues. Make it clear that building effective working relationships is part of their job, not a distraction from it. And by this I mean, include it in your performance reviews because the most expensive engineers are those who can’t form productive relationships that influence outcomes (and remember, there is no single neurotypical way to do this; you have to find what works best for your team). When you build a security team where every member actively earns influence through their daily work, you create organizational change that no individual CISO could accomplish alone, repositioning security from a department people tolerate into a function people actively seek out to partner with. This is the kind of distributed political capital that survives leadership transitions, budget cuts, and organizational restructuring. Most importantly, you create a movement rather than a mandate. And movements are far more powerful than any individual authority. ## **Choosing Influence** Political capital doesn’t accumulate by accident, but through deliberate effort to build relationships, demonstrate value, and engage with organizational dynamics. The choice facing many of today’s CISOs is straightforward – either continue operating as a technical expert who complains about a lack of influence, or embrace the political nature of the role and actively build the power necessary to drive meaningful security outcomes. If you want influence, if you want the organizational authority to make substantial investments and drive real cultural change, you need to be willing to engage in the coalition-building, strategic positioning, and executive relationship management that creates political capital. And then you need to multiply that influence by empowering your entire team to do the same. Or you can remain technically correct and organizationally powerless. It's your choice. ### 3 Counterproductive Communication Patterns Holding Back Security Researchers URL: https://www.discernibleinc.com/3-counterproductive-communication-patterns-holding-back-security-researchers/ Last updated: 2026-07-11T18:52:11.000Z I want security researchers to be able to disclose more of their bug bounty findings because greater transparency from companies is essential for advancing our collective security knowledge and practices – and because so many of these individuals have become dear friends over the span of my career. So, I want to address something with the new generation of reachers – some of your communication choices work against the very trust you need to make transparency possible. The public spotlight of responsible disclosure often falls on companies that mishandle vulnerability reports or treat researchers poorly, and while those stories certainly exist ([I've written extensively in previous posts](https://www.discernibleinc.com/tag/bug-bounty/) about how companies can communicate more effectively with researchers), another element of this formula deserves attention. Namely, the communication challenges that security researchers themselves bring to the table (and sometimes insist on amplifying). After years of working with bug bounty programs and independent security researchers across web2 and web3, I've seen a pattern of communication practices that repeatedly undermine otherwise productive interactions. Even the most talented researchers can sabotage their own efforts through ineffective communication. Here are three of the most common communication mistakes I see researchers make during the vulnerability disclosure process. I'll also walk through how addressing these issues can lead to better outcomes for everyone. ## **1\. Misaligned Expectations About Urgency and Impact** A common source of friction in disclosure communications is misaligned expectations about a vulnerability’s severity and subsequent resolution timeline. Some researchers submit reports with the implicit assumption that their discovery should be treated as a “drop-everything” emergency, using alarming or threatening language to push for immediate fixes without considering other factors that might inform a company's risk decisions. When a company then triages the issue according to its established risk matrix (perhaps assigning it medium priority rather than critical), researchers often feel dismissed or undervalued. When this disconnect happens, it’s often because a researcher failed to: - Understand how companies evaluate risk in the context of their specific business and threat model - Recognize that engineering, infra, and product teams often have competing priorities and release cycles - Provide clear and objective evidence of their report’s impact rather than only theoretical worst-case scenarios I routinely hear from bug bounty teams that the worst reports scream "CRITICAL VULNERABILITY!!!" but fail to show meaningful impact or include reproduction steps. This kind of report creates tension and skepticism rather than collaboration because it leads with alarm rather than specifics, making the security team's job even harder. Uncertainty breeds resentment, not urgency, so even if you’re right, you’ve just decreased your chances of success. My advice is to provide clear evidence of what the vulnerability does in their environment, walk through reproduction steps, and show the impact in terms that someone can act on. Your objective should be to help them understand where this fits in their risk landscape so they can prioritize appropriately, which is how you convince engineering teams to schedule fixes. ## **2\. Failing to Understand Audience and Process** Many researchers don't realize that their reports go through multiple hands, each with different technical expertise and responsibilities. The initial triage team often has a broad but not deep understanding of all systems, and they're primarily focused on two questions: "Is this a legitimate security issue?" and "Where should this report be routed next?" Common researcher mistakes include: - Assuming everyone reading the report has identical technical context - Being either too technical without a summary or too vague without specifics - Sending lengthy, unedited videos that meander around the point A bug bounty manager once told me, "I've seen researchers send 20-page reports with no clear indication of what the vulnerability actually is, or a two-sentence report with no reproduction steps. Both extremes make it incredibly difficult for us to evaluate the finding properly." Spoiler: Things that are hard to evaluate usually don't get prioritized. Structure your reports with a human workflow in mind because your initial report needs to help the triage team understand where to route it, while subsequent communications may go to engineers with deeper knowledge. Your communication should help frontline folks communicate accurately to the next person in the workflow, recognizing the actual level of decision-making authority at each step, and adapt your communication style accordingly as the report progresses through the internal team. Spoiler: IC engineers aren't responsible for negative headlines in the press, and rarely does it impact their own performance reviews. They're not the audience for this overused, often ignorant threat by researchers (most organizations can safely weather a single, isolated news cycle as a bump in the road). ## **3\. Letting Emotions Damage Professional Relationships** The bug bounty ecosystem can be emotionally charged. Researchers invest significant time and energy into their findings, and when they perceive a company as dismissive or unresponsive, frustration naturally follows. However, letting those emotions dictate your communication creates significant problems, including: - Using threatening or extortionate language - Publicly venting frustrations before allowing internal processes to finish - Deliberately overstating risk - Adopting a combative tone These approaches signal to companies that a researcher may not be acting in good faith, which ironically leads to even slower response times and more conservative assessments. Companies talk to each other about problematic researchers just as researchers talk about problematic companies – and when organizations receive an angry or threatening report, it’s not uncommon for teams to loop in the lawyers, which immediately slows everything down. Security teams want to work with researchers who see themselves as partners in security, not adversaries trying to extort or blackmail them. Responsible disclosure is a professional relationship that might span years, not a one-time transaction. Position yourself on the same side of the table as the company's security team because you're both working to solve the same problem. Frame your communications around shared goals such as protecting users and advancing the field's collective knowledge. Stop telling yourself that your vulnerability alone could destroy their brand, because if they’ve hired me, it won’t. Try communicating with something like this: "I discovered an issue that we should address together to protect your users. Here's what I found and how we can work together to resolve it effectively." Be patient but persistent, maintaining courteous communication even when frustrated. If you believe your report is being mishandled, explain your reasoning clearly and ask for clarification rather than escalating to threats or public disclosure. Remember that bug bounty teams are staffed by security professionals who generally want to do the right thing – treat them accordingly (hell, they're probably equally annoyed as you are about the process/politics that allowed this issue to happen in the first place). When you demonstrate that you're collaborating toward a mutual goal rather than extracting value from an adversary, you lay the foundation for the trust that enables companies to be more transparent about vulnerabilities, ultimately benefiting the entire security community. If you say this is your goal, but your behavior demonstrates otherwise, it's really hard to believe you. ## **The Communications Science Behind These Challenges** The challenges described above aren't unique to security research - they're amplified manifestations of well-documented phenomena in communications scholarship. Understanding the academic research behind these issues can help researchers approach disclosure more effectively. **Media Richness Theory and Bug Bounty Communications** Media Richness Theory, pioneered by Richard Daft and Robert Lengel in the 1980s, explains that different communication channels vary in their ability to convey complex information. Text-based bug reports represent a "lean" medium that lacks facial expressions, tone of voice, and immediate feedback - all elements that help prevent misunderstandings. Research shows that lean media is particularly problematic when: - The subject matter is complex or ambiguous - Parties don't share established relationships - There are potential conflicts of interest All three conditions are typically present in bug bounty scenarios. This explains why misunderstandings about severity, impact, and intent are so common - the communication medium itself predisposes these interactions to confusion. **Cross-Cultural and Language Barriers** Bug bounty programs operate globally, connecting researchers and companies across cultural and linguistic boundaries. Communications research by Geert Hofstede and others demonstrates that cultural differences significantly impact how people interpret messages, particularly around: - Power distance (attitudes toward authority and hierarchy) - Directness vs. indirectness in communication - Tolerance for ambiguity and uncertainty - Time orientation (long-term vs. short-term thinking) When a researcher from a culture that values direct communication interacts with a program managed by people from a culture that prioritizes harmony and indirect communication, misunderstandings are virtually inevitable without conscious adaptation. **Asynchronous vs. Synchronous Communication** Most bug bounty communications happen asynchronously, with significant time delays between messages. Research by McGrath and Hollingshead shows that asynchronous communication creates unique challenges: - It extends the feedback cycle, allowing misunderstandings to compound - It reduces context awareness between parties - It makes relationship-building more difficult - It can exacerbate attribution biases (assuming negative intent) These factors help explain why frustration often builds over time in bug bounty interactions, particularly when reports remain unresolved for extended periods. ## **Building Better Security Partnerships for Greater Transparency** My ultimate goal in highlighting these communication issues is to promote more transparency in security. Companies should disclose more vulnerability reports publicly, sharing information that helps the entire security community learn and improve. But this kind of transparency requires trust, and that gets undermined when communications go poorly on either side of the relationship. To be clear: this post focuses on researcher communication patterns, but companies bear equal responsibility for effective bug bounty communications. I've written extensively about how organizations can improve their side of this equation, including[ setting clear expectations](https://www.discernibleinc.com/powerful-expectations-effective-communications-for-bug-bounty-programs/),[ understanding metacommunication dynamics](https://www.discernibleinc.com/metacommunication-and-bug-bounty-programs/), and[ breaking down communication barriers](https://www.discernibleinc.com/breaking-down-barriers-insights-from-our-recent-bug-bounty-communications-scenario/) that prevent productive researcher relationships. Both parties need to improve for this ecosystem to reach its full potential. When researchers approach disclosures in ways that create adversarial relationships, legal concerns, or public relations anxieties, companies naturally become more hesitant to share information openly. Each negative interaction reinforces the corporate instinct to minimize disclosure rather than embrace it. Successful bug bounty relationships aren't just about finding vulnerabilities – they're about establishing productive, long-term collaborations between researchers and companies. The most effective researchers understand this dynamic and communicate in ways that facilitate trust rather than undermine it. Before submitting your next bug report, consider how your communication approach might be perceived. Are you presenting yourself as a professional security partner, or as someone the company should view with caution? The difference often determines not just the bounty amount, but whether your findings make a meaningful security impact at all – and whether they eventually become part of the shared knowledge that advances our field. By avoiding these common communication pitfalls, researchers can significantly improve their effectiveness and build the trust necessary for greater transparency across the industry. After all, both parties share the same ultimate goal: making systems more secure for users through both fixes and knowledge sharing. ### Why Security Communication Feels So Hard (And What to Do About It) URL: https://www.discernibleinc.com/why-security-communication-feels-so-hard-and-what-to-do-about-it/ Last updated: 2026-06-26T20:46:16.000Z Security and privacy professionals spend a lot of time and energy converting threat models into ROI calculations, privacy risks into brand value metrics, and architectural decisions into shipping velocity. Yet critical nuances still get lost, and important concerns remain deprioritized. Most advice tells you to improve your translation skills – swapping out technical terms for business jargon. But effective communication is actually about understanding the structural dynamics that make these conversions necessary in the first place, and using that understanding strategically. # Muted Group Theory Muted group theory originated in anthropology through Edwin Ardener's work in the 1970s, studying how certain groups become structurally silenced within a culture. Feminist scholar Cheris Kramarae later developed the theory to explain women's communication disadvantages in patriarchal societies. Still, the framework's principles can be applied to any group forced to operate within a dominant group's language system. Regardless of which group is dominant, **when you don't control the language, you have to work harder to be heard.** According to the theory, dominant groups create the vocabulary, the acceptable topics, and the expectations for what counts as valid arguments. Everyone else must adjust. Understanding this dynamic is an important communication skill – one that fundamentally changes how effective you can be as an advisor. Businesses naturally develop vocabularies around core functions such as growth, operations, and finance because their focus centers on market opportunity, competitive advantage, revenue growth, operational efficiency, and return on investment. As security and privacy professionals, we often operate in a different conceptual space, centered on protection, resilience, adversarial thinking, systemic vulnerability, and user rights. Neither language is inherently better than the other, but security and privacy are specialized advisory functions that must constantly bridge into existing business frameworks. And that bridging work – the effort to align and set shared objectives – falls almost entirely on security professionals. Recognizing this pattern is the first step in an effective communication strategy. # How the Asymmetry Actually Breaks Communication The translation problem isn't just about vocabulary; it's about what gets lost when someone forces you to express security concerns in terms that weren't designed to hold them. Consider what happens when a security team identifies a critical authentication vulnerability. It’s an urgent systemic risk that could compromise an entire platform, affecting all users simultaneously. The severity comes from the scope of potential impact and the adversarial probability since attackers actively and relentlessly scan for exactly these weaknesses. When you translate this into business language, it might look something like: "We need to spend $200K and delay the next feature launch by X weeks to implement MFA." The urgency disappears. It's now one cost-benefit calculation among many, competing with marketing campaigns and product improvements that have clear revenue projections attached. What broke down? The security assessment operates in a threat model framework, i.e., likelihood of exploitation, blast radius, and adversarial motivation. The business decision operates within an opportunity-cost framework, i.e., known costs vs. projected returns, and the trade-offs between certain delays and potential incidents. Far beyond different vocabularies, these are different epistemologies about what constitutes a sound decision. Security evaluates what adversaries might do given their capabilities and opportunity. The business evaluates what the organization should do, given its available resources and competing priorities. The same vulnerability looks different through each lens. When you're in the muted position, you're not only translating words to convey meaning in another context, but also compressing your entire reasoning framework into someone else's decision architecture. And in that compression, the structural logic that makes something "critical" often gets flattened into a simple cost. This is why the standard advice for security professionals to just get better at translating security concepts into business terms isn't enough. Bilingualism will make you more effective, but understanding and working with the organization's structural limitations is where the real wins are. Rather than simply working harder to convert security concepts into business terms, effective communicators recognize this asymmetry and use it strategically. # Communication Strategies Here are two high-leverage communication strategies to consider once you understand the structural dynamic: **1\. Reframe timing, not just content** – Instead of arguing harder that the vulnerability is critical or converting it to a simple cost-benefit (losing the nuance of criticality), you can reframe the decision timeframe itself. "We can implement this in Q2 for $200K, or we can wait until we're responding to an active incident, which historically costs organizations in our sector $2-4M in emergency response, customer notification, regulatory response, and platform recovery – plus the opportunity cost of every product and engineering team stopping their work to address it. The question isn't whether to implement MFA, but whether we want to choose our timing or have it chosen for us." This works because it translates the adversarial probability (which doesn't compute in business frameworks) into the business-native concept of paying now versus paying more later. Rather than fighting the dominant language system, identify where your framework has natural leverage inside of it. **2\. Build decision-making infrastructure before you need it** – Muted groups become less muted when they establish their concerns as legitimate inputs before crises force the conversation. This means proactively creating spaces where security reasoning is expected and valued. A popular asset we’ve created for clients at Discernible is a lightweight "security decision log" to track the security issues they flagged, the business's decisions (including who owns the risk), and what actually happened. Not as a gotcha document, but as organizational learning. When you can say, "In the last eight quarters, we recommended new controls 6 times before an incident and 3 times after an incident. Here's what each path cost," you're no longer arguing from a muted position. You've created a track record that speaks business language while preserving security logic. Understanding muted group theory fundamentally changes which outcomes you can achieve and allows you to deploy your energy more strategically. Instead of endlessly refining your board deck, you might focus on changing what kinds of questions the board asks. Instead of arguing harder in each product security review, you might work to establish security reviews as a standard phase with different decision criteria. Most importantly, you stop seeing business stakeholders as obstacles to overcome and start seeing them as partners who face the same structural constraints in how organizations make decisions. Your role exists to help the business pursue its goals, which requires communicating about risks in ways that align with how decision-makers actually make decisions. Understanding the asymmetry helps you do that more effectively while maintaining the integrity of what you're trying to communicate. Muted group theory won't solve every communication challenge security professionals face. Still, it offers something more valuable than another framework for "translating technical to business" because it explains why that translation is so difficult and what strategic options become available when you understand the underlying dynamic. ### Calling Technology Magic is Bad Communication URL: https://www.discernibleinc.com/calling-technology-magic-is-bad-communication/ Last updated: 2026-07-11T22:12:40.000Z *A conversation about transparency, accountability, and breaking free from a playbook of deceit.* The audience is supposed to know they're being tricked – that's what makes stage magic entertaining rather than fraudulent. We *want* to believe the impossible, but we know, somewhere in our rational minds, that it's a performance. A deliberate deception we've consented to. But what happens when an industry wraps itself in the language of magic without that crucial element of consent? When does a “seamless user journey” become a smoke screen rather than a feature? When is opacity treated as innovation rather than obstruction? This is an unfortunate truth at the heart of [Lisa LeVasseur’s](https://www.linkedin.com/in/lisalevasseur/?ref=discernibleinc.com) recent presentation at the Enigma track of the 2025 USENIX Security Conference (seriously, it’s so good – you have to check it out on [YouTube](https://youtu.be/15hg1qD1FQ8?ref=discernibleinc.com)!). Her talk argues that framing technology as "magic" isn't just lazy marketing but an active catalyst in our declining ability to build and communicate about safe digital products. And as someone who spends their days trying to extract truth from technical systems to share it through honest stakeholder communications, I felt seen. ## **The Pattern We Keep Repeating 🤢** Lisa traces a direct line from [Edward Bernays](https://en.wikipedia.org/wiki/Edward%5FBernays?ref=discernibleinc.com) (whose obituary claimed he was “the father of public relations” and who convinced America that smoking was a form of liberation through the tobacco industry's 50-year deception campaign) to the digital products we use today. Bernays weaponized his uncle Sigmund Freud's insights about human psychology to manipulate people’s behavior at scale, creating a blueprint for decades of preventable deaths. Using Bernays’ manipulative techniques, the tobacco industry didn't just deny that their products caused harm; they systematically blamed consumers, discredited unfavorable science while funding favorable (often questionable) research, used complexity and opacity as shields against accountability, and delayed transparency and measurement for decades. If this sounds eerily familiar, you’re not alone. Because, as Lisa points out, we’re following the same playbook today with digital products. I reached out to Lisa, the Executive Director at [Internet Safety Labs](https://internetsafetylabs.org/?ref=discernibleinc.com), to explore these ideas further, particularly their implications for security and privacy communications. --- # Q&A with Lisa LeVasseur **Q: In your talk, you note that software introduces a second “actor” in product safety because the product itself can behave autonomously. How should this change the way we think about consent and user control?** **A:** I think we need to start by acknowledging that consent as a part of the product safety “toolkit” was only introduced with the advent of digital products, and I’d like to suggest that it’s been a failed experiment. Before digital products, earlier products relied on labels (ingredients, information, and warnings) and product design safety standards; consent was not part of the bargain when we bought a vehicle, for example. We mainly experienced consent in a medical or research setting. It came, of course, from notice and choice in privacy regulation; so we took digital product safety guidance from privacy regulation, not from product safety norms. Consent has never been fit for purpose for digital products. For instance, it categorically fails to satisfy the “informed” requirement for viable consent. From an autonomous action perspective, consent seems like a reasonable approach—we seek consent as humans, for our human behaviors. Where it fails is that software behavior is complicated and getting more complex. As consumers, we don’t have time to familiarize ourselves with all the potentially risky behaviors that may (or may not) be described in the privacy policy and terms of service. Moreover, software can be so complex that even the manufacturer can’t predict its behavior. Finally, we don’t have a consensus on the hazards and risks of digital products, let alone how to communicate them in a digestible manner. For the user control part of the question, the manufacturer controls whatever kinds of control the user is allowed over the product. The manufacturer is the ultimate puppet master of both the software and the user of the digital product. And obviously, as software behavior gets more complicated and less predictable, can a manufacturer promise any kind of user control? And if they could or did, how would users know that the controls they toggled were actually changing the behavior of the digital product? **Q: You draw parallels between the tobacco industry’s playbook and current digital product practices. What are some of the most egregious contemporary examples you’ve seen of this playbook in action? Are there any examples of companies doing things right?** **A:** What I’m about to describe is somewhat novel to digital products, but it’s part of the original social engineering (i.e., narrative creation and control) first codified by the tobacco industry. I think the fact that we don’t call them digital products is one of the greatest cons of the industrial age. We call it “technology” or “high tech”, or we call them “services”; we equate the use of digital products with going somewhere—being in a digital world. We see this propagated by language such as “online safety”, which furthers the gaslighting agenda that safety is the consumer’s responsibility when it comes to digital products. And now, of course, we talk about “AI,” which is really a bunch of software techniques. By not calling these things products, the industry casts a kind of spell that this is completely new territory, and we have, in fact, dissociated these industries from everything we’ve learned about product safety and product liability. I’ve been in software since the late 80s, and in my career (embedded and application software), product safety was never mentioned. The benefit for industry is that framing this as completely novel implies that all new governance is needed, most of which, by the way, ignores product safety regulations and best practices. Creating new regulations is a delay tactic while extractive digital products become further entrenched in our lives at every level. As for the “DIY safety” narrative that has quite successfully permeated the world—if you look at the myriad online safety initiatives—it’s the predominant framing. Industry has indeed convinced us that it’s our job to keep safe while using digital products. In fact, maybe that’s the greatest con of the industrial age: the products’ behavior is unpredictable, poorly documented, exceedingly complex, and yet somehow it’s our responsibility to keep safe while using them. **Q: The “technology is magic” framing seems particularly powerful in the AI space right now, with “black box” models often treated as fundamentally unexplainable. How does your framework apply to AI product safety and communication?** **A:** This is a good question (they’re all good questions). Yes, the “AI” industries are embracing the obfuscation tactic of the product safety resistance playbook, even though it feels like infrastructure—almost like electricity. AI is a collection of commercially packaged software capabilities/techniques—a collection of digital products. What we refer to as AI is often LLM and ML-powered synthetic text and media “extrusion machines” \[[as Emily Bender and Alex Hanna have deemed them](https://thecon.ai/?ref=discernibleinc.com)\]. These synthetic text/media extruders are 3rd-party productized components integrated into a bunch of other digital products. In this way, the synthetic text extruder is yet another 3rd party software component, and thus, we’re entitled to know (1) does the extruder include any additional downstream 3rd party components \[or data processors in the GDPR vernacular\], who are they, and what do they do? (2) What happens with my personal information? Who uses it and for what purposes? (3) How can I control my personal information? **Q: You mention that empirical measurement is crucial, but can take decades to establish. Which measurements should the digital product industry standardize now? What would a nutrition label for digital products actually look like?** **A:** We need to harmonize on the kinds of hazards and harms we’re exposed to when using digital products. At ISL, we’ve been working on ingredient and information labels in earnest for several years, and launched our first version in 2023\. We have exciting new changes to the label launching next year, including deceptive patterns. I’ll describe the envisioned new sections more in the next question. **Q: In your talk, you showed a taxonomy of digital product harms that goes well beyond privacy or security as we typically define them. Can you walk us through why this broader framing matters—and what harms we’re missing when we focus narrowly on data protection?** **A:** It goes back to the idea that software imbues digital products with seemingly autonomous behavior. Things that behave are capable of harm. Humans behave; we are capable of harm. Note that harm can be independent of intent. As humans, we can harm others without intending to. But we’ve arrived at social agreements regarding what interpersonal behavior is acceptable and what isn’t. I suggest that we do the same with digital products. These are the broad behaviors of digital products that can be hazardous to consumers—note that each one of these risks is amplified by so-called “AI” methods: 1. You mentioned the exposure of personal information. This is a major safety concern, and there are two avenues of risk: by design (privacy) and by attack (security). 2. User manipulation: we can and are manipulated in multiple ways in our use of digital products, ranging from advertising manipulation to deliberately addictive user interfaces. This year, we catalogued around 150 such manipulative patterns in our work. Baked-in manipulation generally aims to get the human user of a digital product to behave in a way that serves the manufacturer’s needs, usually to part people from their money, time, or data (which is another form of currency).Text extruders (chatbots) have turned this family of hazards into serious harm in the form of “suicide coaching”. The cigarette industry knew full well \[through their own research\] that children aged 13-18 were the most susceptible to becoming addicted to smoking, and they strove to capture them before they outgrew the tendency. I’m not a neuroscientist, but I believe teens' (and younger children's) brains need special care. 3. Interpersonal risks: platforms that enable person-to-person communication can present serious risks to children, such as grooming, exposure to CSAM, etc. 4. Algorithmic decision-making: Digital products constantly make algorithmic decisions. The risk is when these decisions treat people unfairly. A related variant of algorithmic decision-making is predictive technology: technology that makes predictions about a human based on a reductive set of digitized data. Bender and Hanna discuss troubling technology that purports to identify a criminal by looking at a person’s face. We also see this in edtech platforms that predict a student’s likelihood of success or risk disciplinary action, sometimes directly connected to law enforcement. These are all examples of the kinds of design-based hazards and harms built into digital products. But there is also the category of Cybercrime, where digital products are weaponized by people to commit crimes, like cyberbullying, for example. Over time, we’re going to see greater accountability from digital product manufacturers to build in guardrails that provide reasonable protection against the weaponization of digital products by cybercriminals. **Q: You ended with a call to action: engineers have the power to build safer digital products, and we can create a digital product safety playbook together. What would be in that playbook? Where do we start?** **A:** I’m going to start with an unpopular, but I think existentially vital suggestion: That we need to prohibit the exchange of personal information for valuable consideration of any kind. Just prohibit it. Take away the incentive entirely. There’s a reason we don’t allow an open market for human organs: it’s profane. It dangerously devalues human organs. Also, having any market for personal information will turn privacy into something available only to the wealthy. Don’t sell personal data. Are you including behavioral digital advertising \[accessing real-time bidding\] in your product? You’re selling personal data. Is your marketing organization buying customer data? (hint: they are) You’re selling personal data. Okay, other easier things: 1. Call them digital products. 2. Stop hoarding personal information just because you can. Cory Doctorow, soothsayer for the digital age, [told us in 2008](http://theguardian.com/technology/2008/jan/15/data.security?ref=discernibleinc.com) that we should treat personal information like plutonium. And we still don’t do it. Push back and fight the urge to collect data. Odds are very high that you don’t need gender information for your product. 3. Start with transparency. Manufacturers need to do it as a compliance matter in documenting processing activities. Make it a standard part of the development process. Document all data processors. I look forward to the day when Software Bills of Material (SBOMs) are standard practice for all apps, all digital products. I also greatly look forward to machine-readable Records of Processing Activities (ROPAs) generated by all digital products, recording all processing of each data element about me that a data controller or data processor collects, uses, or shares. The software supply chain management process needs significant revision. It’s too easy to integrate 3rd-party software components without an adequate understanding of downstream data processing activities or appropriate binding agreements. 4. Abuse and misuse Cases: Hone creative thinking to generate abuse and misuse cases along with traditional use cases. How could this product be deliberately weaponized to cause harm? We need more awareness and training about the ways technology is used for personal surveillance in cases of intimate partner violence or hostile child custody arrangements. What are the ways that the product might be harmful if accidentally misused? --- ## **My Final Thoughts** My work as a communications advisor would be so much easier if businesses and engineers understood these concepts and committed to product safety from the start. But "easier" isn't the point. The point is building products that don't require late-stage archaeological expeditions to uncover the truth, products that don't treat transparency as a liability, and products designed with the understanding that technology isn't magic, but responsibility. The spell is broken when you understand the trick — and maybe that’s what all these companies are afraid of. --- **Support the work:* Internet Safety Labs is establishing critical product safety standards for digital products.* [*Support their research*](https://internetsafetylabs.org/donate/?ref=discernibleinc.com)*.* **Get support:* If you need help communicating product safety risks to leadership,* [*contact us*](https://discernibleinc.com/contact?ref=discernibleinc.com) *to discuss how we can help.* **Stay informed:** [*Subscribe to our newsletter*](https://discernibleinc.com/?ref=discernibleinc.com) *for more frameworks on security and privacy communications.* ### Messaging != Communication URL: https://www.discernibleinc.com/messaging-communication/ Last updated: 2026-07-11T22:26:52.000Z Messaging and communication aren't interchangeable terms. Messaging is content, including all your carefully chosen words, the narratives you present, and the talking points you prepare. Messaging answers the basic questions of: What information needs to be conveyed? How should we frame this technical concept? What language will resonate with this audience? Good messaging is clear, accurate, and audience-appropriate – and frames security investments in business terms. These are valuable skills, and most security professionals work hard to develop them. But messaging alone changes nothing. ## **The Why Matters** **Communication is strategy:** the deliberate effort to create shared understanding to drive specific outcomes. It answers questions like: What do we need people to believe, feel, or do differently? What's preventing that change right now? How do we proactively address those barriers? Effective communication starts with the end in mind, meaning the action you need someone to take. Then we work backwards through every layer of resistance standing in the way. Communication encompasses: - Understanding your CFO's current belief that “benchmarked” security from five years ago still applies - Identifying that the Head of Product views security requirements as obstacles to velocity - Recognizing that your CEO's skepticism stems from a previous CISO who oversold solutions - Mapping the specific experiences, assumptions, and conclusions preventing stakeholders from taking the action you're requesting In essence, messaging is what you say, whereas communication is the entire strategic effort to change what someone thinks, feels, or does. I see the confusion between messaging and messaging-as-communication showing up everywhere in security work, often with measurable consequences for organizational outcomes. ### **The Template Trap** Organizations frequently approach incident response by perfecting their disclosure templates. They spend hours workshopping notification language to ensure legal compliance. The generic, one-size-fits-all template is often viewed as a scalable work of art (especially by outside counsel 🙄). Then an incident happens, they deploy the template, and stakeholders react with confusion, anger, or silence. The message might have been *legally* perfect, but the communication failed. Why? Because effective communication recognizes that everything that impacts how people perceive and interpret your words, including their current emotional state, specific relationship with your organization, previous experiences with security, and what they need to believe about your response before they can trust you again. A template can't account for these variables because templates are messaging tools, not communication strategies. As we discussed in our previous post, [The Template Trap](https://www.discernibleinc.com/the-template-trap/), the organizations that handle incidents well build communication infrastructure that prepares them to adapt their messaging to whatever circumstances they actually face. ### **The Translation Fallacy** Many security leaders believe their communication challenge is translation, i.e., converting "multi-factor authentication" into "extra login steps" or "zero-day vulnerability" into "unknown security weakness." They're solving the wrong problem. As we’ve discussed [before](https://www.discernibleinc.com/why-effective-security-communication-starts-with-strategy-not-translations/), the underlying issue isn't that executives don't understand technical concepts unless you dumb things down (which is very condescending, by the way). Effective communication requires understanding what motivates your CFO, the constraints your Head of Operations faces, and the experiences that have shaped your CEO's skepticism about security investments. Then you craft messaging that addresses those specific barriers while pursuing the particular outcome you need. ## **Graduating from Messaging to Communication** So how do security professionals make this shift? Treat persuasion as the goal. Effective security communication is persuasion, not translation. Find out what motivates your audience and address what stands in your way. Messaging is just one tool in that larger strategic effort. 1. **Start with outcomes, not information.** Before crafting any message, ask: What specific action do I need someone to take? What needs to be true for them to take that action? What's preventing it right now? 2. **Map the resistance.** Use frameworks like the [Ladder of Inference](https://www.discernibleinc.com/beyond-translation-how-cisos-lead-when-the-c-suite-cant-decide/) to identify the beliefs, conclusions, assumptions, and experiences preventing stakeholders from taking the action you need. A good communication strategy addresses these barriers rather than merely present information. 3. **Build infrastructure, not templates.** Instead of perfecting a slew of templates, build the stakeholder relationships, internal credibility, and decision-making frameworks that let you communicate effectively regardless of what circumstances you face. As we explored in [What Could Go Right](https://www.discernibleinc.com/what-could-go-right/), preparation means creating capabilities and preserving choice, not scripting responses. 4. **Measure communication outcomes, not just message deployment.** Focus on whether beliefs changed, behaviors shifted, or decisions moved in your direction to ensure your strategy achieves real security improvements. Security teams that understand this distinction fundamentally change their role within the organization. They earn influence, credibility, and political capital that they can leverage when needed. Clear, accurate, well-framed messages are essential, but they're tools in service of communication, not substitutes for it. The security teams that master this distinction get to realize the outcomes their messages were supposed to create in the first place. ### Why Your Incident Response Should Be Unique URL: https://www.discernibleinc.com/why-your-incident-response-should-be-unique/ Last updated: 2026-07-11T22:31:35.000Z *The best incident response emerges from honest conversations about who you are, not from templates that assume all companies are the same.* A few weeks ago, we ran a new [Discernible Experience](http://discernibleinc.com/experience?ref=discernibleinc.com) on open-source supply chain incidents with teams in our subscriber community. We based it on real npm compromises from the past few months. We asked participants to analyze what went wrong with a hypothetical company’s communication and how it could build better communications infrastructure to prevent similar mistakes in the future. **We didn't give anyone templates to fill out.** Instead, we asked them to map who owns which channels, identify which relationships need building, and sketch decision frameworks that align with how this company actually works. Here's what surprised us: Even though we gave everyone the same fictional company to work with, three different teams produced three wildly different – and all completely valid – approaches to fixing its incident communications. Why? Because they interpreted the company's culture, values, and priorities differently. Let me show you why that matters. ## **The Same Company, Three Different Interpretations** Everyone was working with DevFlow Technologies, an imaginary developer tools company powered by open source npm packages, serving enterprise customers and a community of 450,000+ developers. The company had just failed spectacularly at communicating about a supply chain compromise, including a 6-hour disclosure delay, a vague and unhelpful advisory, the wrong communication channels, the exclusion of volunteer maintainers, and angry customers. The imaginary company profile included key details to help participants imagine themselves in the position of the Security Communications Lead: - 850 employees - $240M revenue - “Trusted developer platform known for ease of use and security” - Company values like “Developer Trust First” and “Security as a Feature” - Serving both the open source community and enterprise customers - Mix of volunteer maintainers and internal teams We also gave them the same hypothetical feedback from key internal stakeholders to illustrate where communications broke down: **CISO:** “We treated this like an internal enterprise incident where we control information flow, but open source is fundamentally public. We can't control what the community discovers or discusses. We needed a decision framework that accepts this reality and optimizes for trust and usefulness, not information control. The 6-hour delay was trying to achieve certainty that was impossible in this context.” **Director of Open Source:** “Open source community norms are: acknowledge fast, update frequently, be transparent about uncertainty, and show your work. We did the opposite: delayed acknowledgment, infrequent updates, hid uncertainty, and provided conclusions without analysis. We needed a decision framework based on open source norms, not enterprise security norms. We also should have treated maintainers as insider partners, not external parties.” **VP of Engineering:** “My engineers were in an impossible position. They're active open source community members who saw friends and colleagues affected by our packages, but they had no guidance about what they could say. Some stayed silent and looked unresponsive; others shared information they probably shouldn't have. We needed clear, fast guidelines so they could be helpful within boundaries.” **VP of Customer Success:** “Enterprise customers have contracts with security provisions, and we violated those by not proactively notifying them before public disclosure. They expect premium service and insider information, not learning from Hacker News. We needed to be integrated into incident response from minute one with authority to contact customers immediately, even if that means disclosing before a full public announcement.” **General Counsel:** “I understand I slowed things down with legal review, but every public statement creates legal exposure. That said, I now realize that in open source incidents, delayed communication creates reputational and business risks that outweigh the incremental legal risk reduction. We also need a better understanding of what legal risks are actually material versus theoretical in open source contexts.” **VP of Product/Developer Relations:** “We should have been monitoring community discussions and engaging in real-time, but we weren't integrated into incident response. By the time we realized misinformation was spreading, we didn't have approved messaging to correct it. We needed authority to engage with the community using pre-approved guidance, not wait for corporate communications clearance on every response.” But despite having identical facts and context, when participants outlined what DevFlow should build before the next incident, their answers looked completely different because they brought different mental models about how companies like this actually work – here’s what we observed: ## **Version 1: The Security-Focused Startup Interpretation** **How this team saw DevFlow:** Reading the same company profile, this team interpreted DevFlow as operating more like a security-focused startup. They saw the “850 employees” and thought “mid-size, still growing, needs to move fast.” They read “Developer Trust First” and concluded speed and transparency were competitive advantages. **Their incident communication approach:** - When mapping channel ownership, they wrote things like: “Developer Relations team needs admin access NOW. Currently, only the CISO has it, and they were in back-to-back meetings during the incident.” - For decision authority: “Security Communications Lead has authority to publish initial acknowledgment within 1 hour. Can escalate to CISO if needed, but the default is to disclose fast.” - Their legal framework: “Schedule meeting to define what categories of technical info are pre-approved... We can't afford lengthy legal reviews on every communication.” **What their interpretation reveals:** - Several participants on this team have worked at startups or fast-moving companies where speed is a competitive advantage and bureaucracy is the enemy. When they saw DevFlow's values emphasizing “Developer Trust” and “Security as a Feature,” they interpreted that as “we need to move fast and be transparent to maintain trust.” - Their infrastructure recommendations reflect startup realities: lean processes, clear empowerment, and minimal gatekeeping. ## **Version 2: The Enterprise Developer Tools Interpretation** **How this team saw DevFlow:** Reading the same profile, this team saw “12,500+ companies” and “$240M revenue” and interpreted DevFlow as a maturing enterprise company with significant operational complexity. They read “trusted developer platform” and thought about contractual SLAs and customer expectations. **Their incident communication approach:** - When mapping channel ownership, they identified sophisticated needs such as “Need API integration with internal security tools for auto-publish capability” and “Need TweetDeck configured with security incident lists.” *(Note: TweetDeck is now called “X Pro”)* - They created a three-tier customer system: “T1 customers (50) get immediate calls; T2 (200) get priority email; T3 get standard email.” - Their coordination: “War room: Physical room + Zoom + #incident-war-room Slack for first 8 hours” with “90-minute sync cycles: Assess → Decide → Communicate → Monitor.” **What their interpretation reveals:** - This team has experience at larger companies where processes enable scale, and complexity requires structure. When they saw DevFlow had 12,500+ customers, they immediately thought about segmentation, SLAs, and different customer tiers with different expectations. - Their infrastructure recommendations reflect enterprise realities: formal processes, clear SLAs, sophisticated systems that require resources to build and maintain. ## **Version 3: The Open Source-Native Interpretation** **How this team saw DevFlow:** Reading the same profile, this team saw “community of 450,000+ developers” and interpreted DevFlow as fundamentally a community-first company that happens to have an enterprise business, not the other way around. They read “Developer Trust First” and thought about authentic community relationships. **Their incident communication approach:** - Primary communication channels: “Discord (12K members, highly engaged)... CRITICAL: This is the primary channel for initial disclosure to our community.” - Employee communication: “Engineers and maintainers are empowered to engage authentically. Security Comms Lead provides core facts and technical accuracy, but individuals can use their own voice. We trust our people.” - Decision authority: “Open Source team lead makes call, can disclose within 30 min without waiting for legal review... This is OUR community - we get to make this call.” - Pre-incident agreements: “Company-wide acknowledgment that OSS = different rules... Document that this is our strategy and we accept the trade-offs.” **What their interpretation reveals:** - Individuals on this team worked at open source-native companies or were deeply involved in OSS communities. When they saw DevFlow's emphasis on developer trust and community, they interpreted the enterprise business as secondary to community relationships. - Their infrastructure recommendations reflect OSS realities: radical transparency, individual empowerment, trust over control, and community channels over corporate communications. ## **Why Three Different Answers All Make Sense** All three interpretations are defensible given the company's profile. DevFlow could legitimately operate as: - A security-focused startup that moves fast and competes on transparency - An enterprise developer tools company that balances community and customer obligations - An open source-native company that prioritizes community relationships above all The first team had seen startups fail because they moved too slowly and were too corporate. They brought that mental model to DevFlow. The second team has seen companies struggle with complexity and customer segmentation. They brought that mental model to DevFlow. The third team saw companies damage community trust by being too corporate. They brought that mental model to DevFlow. **None of them is wrong.** They're just seeing different versions of what DevFlow could be – and the difference in values, priorities, and aspirations led each team to adopt a different approach to incident communications. ## **This Is Why Templates Fail** Templates try to paper over these differences by giving everyone the same script: - Step 1: Notify legal - Step 2: Assess scope - Step 3: Draft disclosure - Step 4: Notify customers But these steps assume everyone agrees on things like: - How long should a legal review take, and how far beyond “legal advice” is this feedback helpful - What “assess scope” means operationally - Who drafts and who approves disclosures, especially when disclosures to different stakeholders require different information - Whether customers get notified before or after public disclosure In reality, the startup-minded person thinks legal review should take no more than 15 minutes. The enterprise-minded person thinks it needs 2 hours. The OSS-minded person typically thinks legal shouldn't have veto power at all. A template doesn't resolve this tension. It hides it until you're in the middle of an incident, when people are fighting over “step 2.” ## **What You Actually Need: Shared Values & Identity** After running this Discernible Experience, the most valuable outcome wasn't the specific infrastructure people identified. It was the realization that their day-to-day organizations probably have the same unspoken disagreements about: - Who are we as a company? - What do we optimize for? - What are we willing to accept? Templates can’t answer these questions because they're strategic choices about organizational values and identity. --- *Join* [*Discernible Experiences*](http://discernbileinc.com/experiece?ref=discernibleinc.com)*, where we talk about the messy reality of coordinating incident response across people with different backgrounds, assumptions, and ideas about how companies should work.* ### The Template Trap URL: https://www.discernibleinc.com/the-template-trap/ Last updated: 2026-07-11T22:33:27.000Z You can’t adequately demonstrate empathy and competency when your communications look like form letters. The details matter. The context matters. The specific circumstances of this particular incident, affecting these particular people, at this particular moment in time – all of it matters. And none of it can be captured in a template written six months ago by people who had no idea what would actually go wrong. The appeal of templates is obvious. They promise that during the chaos of an incident, you'll have something ready to go. Just fill in the blanks, get quick approval, and hit send. Fast, efficient, predictable. But this approach fundamentally misunderstands what incident communication needs to accomplish. You're not merely transmitting information – you're preserving trust, demonstrating competence, and maintaining relationships during a moment of vulnerability. None of these objectives can be achieved through standardized messaging that could apply to any incident at any company. When stakeholders receive templated communications, they can tell. The generic language, the obvious placeholders, the carefully hedged statements that avoid saying anything specific – all of it signals that you're going through the motions rather than actually engaging with the reality of what happened. It communicates that this incident isn't important enough to warrant special attention, or, worse, that you don't understand it well enough to discuss it specifically. ## **What Actually Prepares You for Incidents** If templates aren't the answer, what is? The truth is harder but far more effective: infrastructure, relationships, and pre-negotiated decision frameworks. These are the things that actually enable rapid, effective, authentic incident communications. They're more difficult to build than templates, and they require ongoing investment rather than a one-time document creation. But they're what separates organizations that handle incidents well from those that don't. ### **1\. Build Relationships Before You Need Them** Effective incident response requires pre-established relationships. You cannot cold-call volunteer maintainers, community members, regulatory contacts, or media representatives during an incident and expect effective coordination. These relationships need continuous ownership and cultivation. This means: - Identifying who you might need to coordinate with during various incident types. - Establishing regular touchpoints before incidents occur. - Understanding their communication preferences, decision-making processes, and constraints. - Building mutual trust and credibility through ongoing, non-incident interactions. When an incident hits, you need to be able to reach someone who already knows you, understands your organization, and has context for why you're reaching out. That person should already trust that when you say something is urgent, it actually is. It’s exponentially harder to build that in the middle of a fire – and with some folks it’s downright impossible. ### **2\. Establish Channel Access and Infrastructure** Channel access and infrastructure must be in place before incidents occur. Requesting GitHub security advisory permissions, setting up email distribution systems, configuring Discord moderator roles, or getting approval for social media access during an incident wastes critical time when every minute counts. This infrastructure includes: - Pre-approved access to all channels where you might need to communicate. - Technical setup for email campaigns, blog posts, or social media announcements. - Tested systems for reaching different stakeholder groups quickly. - Backup communication methods if primary channels fail. The difference between communicating in the first hour versus the first six hours of an incident often comes down to whether this infrastructure was in place. Templates don't solve this problem – proper preparation does. ### **3\. Map Decision Authority in Advance** Decision authority must be clear and mapped in advance. Six-hour debates about what information to disclose happen when nobody knows who has the authority to decide. These delays don't occur because people are indecisive, but because the organization never clarified who gets to make which calls. Before any incident, you need to be crystal clear on: - Who can authorize different categories of disclosures. - What types of incidents require executive involvement versus team-level decisions. - How to escalate when the mapped decision-maker is unavailable. - What boundaries exist around legal, compliance, and business risk. The point is to eliminate organizational confusion that paralyzes response efforts. When the decision-maker is clear, even difficult decisions can move quickly. And if you’re like me and don’t think litigation should drive every business decision, then you need to negotiate that in advance during quieter, less emotional times. ### **4\. Know Where Your Stakeholders Actually Communicate** Different stakeholder groups consume information through various channels, and your carefully crafted corporate communications are worthless if they never reach the people who need them. Customers, partners, employees, regulators, media, and community members all have different communication preferences and habits. You need to meet each group where they actually are, not where it's convenient for you to communicate with them. This means: - Understanding which channels each stakeholder group actually monitors and trusts. - Having established a presence and credibility in those spaces before incidents. - Knowing the norms and expectations for communication in each channel. - Recognizing that different audiences require different approaches and even different information. For customers, this might mean an email, in-app notifications, or your status page. For technical users, it could be GitHub, community forums, or Discord. For partners, it might be dedicated Slack channels or direct contact with the account manager. For employees, it might include internal chat platforms or all-hands meetings. For media and investors, it might be your corporate blog or social media. For regulators, it often requires direct, formal communication through established reporting channels specified by law. A beautifully written statement posted only to your corporate blog is far less valuable than targeted communications delivered through the channels your specific stakeholders actually use – even if those communications are less polished. And keep in mind that some people will see your message across channels, so even if different, they should never contradict each other. Effective incident communications is about strategic coordination just as much as word-smithing. ### **5\. Pre-Negotiate Legal and Compliance Boundaries** Speed requires pre-negotiated values and priorities, not case-by-case debate. Ninety-minute legal reviews happen when boundaries are unclear. When you're arguing about whether you can disclose specific technical details while the clock is ticking, you're too late. Instead, establish ahead of time: - Which company values matter more than litigation risk (if any). Lawsuits are coming no matter what — the question is what kind of company do you want to be when you face them? - Categories of information that are generally acceptable to disclose. - What requires additional legal review, and what doesn't, and what the acceptable SLA will be for these reviews. - How to handle edge cases that don't fit neat categories. - What the escalation path looks like when quick decisions are needed. This doesn't mean eliminating legal review – it means making that review faster and more focused by doing the foundational work in advance. ### **6\. Assign Explicit Ownership for Monitoring and Engagement** Monitoring and engagement require dedicated ownership. If nobody is explicitly responsible for monitoring Hacker News, Reddit, Twitter/X, and other community channels during incidents, it won't happen. And when it doesn't, you miss critical community intelligence on how your incident is being perceived and discussed. This ownership includes: - Designated people to monitor specific channels during incidents. - Clear escalation procedures for concerning developments. - Authority to engage directly or pull in additional support. - Tools and access to track conversations across multiple platforms. The alternative is discovering three days later that a significant misunderstanding has taken root in your community, or that someone else has filled your communication vacuum with inaccurate information. ## **Moving Beyond the Mad Libs Mentality** The goal isn't to simply communicate faster but to **communicate more effectively**. Sometimes that means speed, accuracy, or empathy. But it always means demonstrating that you understand what happened and care about the people affected. You can't demonstrate understanding and care through fill-in-the-blank templates. You can only do it through communications that are genuinely responsive to the specific situation you're facing. And the only way to create those communications quickly during an incident is to have built the infrastructure, relationships, and frameworks that make rapid, authentic response possible. Stop preparing templates. Start building infrastructure. The next time your team sits down to "improve incident readiness," resist the urge to waste cycles creating communication templates. Instead, ask: - Who do we need relationships with before incidents occur, and who owns those relationships? - What channels and infrastructure must be in place now to enable fast communication later? - Have we clearly mapped decision authority so people won't waste hours debating who can approve what? (Anlikelyt likey, whose approval outweighs someone else’s?) - Do we know where our communities actually communicate, and do we have an established presence there? - Have we pre-negotiated frameworks with legal so reviews can move quickly and deliver helpful outcomes? - Have we assigned explicit ownership for monitoring and engagement during incidents? Answer these questions well, and you'll be infinitely better prepared than any template could ever make you. ### CISO as Super-Facilitator: Elevating Board and C-Suite Security Leadership URL: https://www.discernibleinc.com/ciso-as-super-facilitator-elevating-board-and-c-suite-security-leadership/ Last updated: 2026-07-11T22:35:02.000Z In Harvard Business Review's September 2025 article[ "Every Team Needs a Super-Facilitator,"](https://hbr.org/2025/09/every-team-needs-a-super-facilitator?ref=discernibleinc.com) Stanford psychologist Jamil Zaki introduces a compelling concept through the lens of NBA star Chris Paul. Individual scoring records don't define Paul's remarkable career, but by what's become known as the "Chris Paul effect" – four times he's joined a new team, and each time that team posted its best record ever within two years. No other NBA player has had that kind of impact. Zaki calls Paul a "super-facilitator" – someone who integrates diverse expertise, promotes equitable contributions, and cultivates trust to generate collective intelligence. He's not just a star player, says Zaki; he's a star-maker. For CISOs, this framing illuminates a valuable but often misunderstood (or ignored!) opportunity to elevate the security leadership capabilities of senior executives and board members. The job isn't really to dazzle the board with your technical expertise, but to transform them into sophisticated security decision-makers. ## **Reframing the C-Suite and Board as Your Team** Most CISOs think of executives and board members as our audience, our approvers, our budget gatekeepers. We prepare for board meetings as if we're presenting to external stakeholders, simplifying and translating, hoping they'll understand enough to say yes. But what if we reframed this relationship entirely? What if the senior leadership team isn't your audience – they're your team? This reframe follows the same communications principle we've discussed [before](https://www.discernibleinc.com/what-could-go-right/), asking "what could go right" instead of "what could go wrong," opening up possibilities that deficit-based thinking obscures. According to Zaki, Chris Paul doesn't treat his teammates as people he performs for. He treats them as collaborators whose performance he's responsible for elevating. When Paul joins a team, he's not thinking "how do I impress these players?" He's thinking, "How do I make these players better?" The super-facilitator CISO asks the same question about executives and board members: How do I make this leadership team better at security governance? Not simply better at understanding my security program, but genuinely better at leading security strategy for the organization. ## **The Star Player CISO vs. The Star-Maker CISO** The distinction matters enormously in executive-level communications because how we communicate doesn’t just reflect our identity; it creates it. We’ve discussed this before in our post about [Constitutive Theory](https://www.discernibleinc.com/your-teams-communication-isnt-just-what-you-say-its-who-you-are-understanding-constitutive-theory/). **The star player CISO** communicates to demonstrate competence: - "Our threat landscape looks like this." - "We're addressing it this way." - "These metrics show we're doing well (or not)." - "We need this to continue succeeding." This CISO is the expert, and everyone else is the non-expert. The implicit message: "Trust me, I've got this." **The star-maker CISO** communicates to develop capability: - "This threat landscape connects directly to each of your strategic priorities." - "You're uniquely positioned to influence these outcomes." - "Your governance decisions shaped our current security posture." - "We need your specific expertise to make better security trade-offs." This CISO is the facilitator, and everyone else is a contributor. The implicit message: "We've got this – together." The difference isn't rhetorical. In practice, one approach isolates security as a specialist function, while the other integrates security into strategic leadership. I think this is what many people envision when they talk about “[shared responsibility](https://www.discernibleinc.com/the-myth-of-shared-responsibility/),” but then they continue communicating in the opposite direction. ## **Attunement: Understanding What Executives Really Need** In his article, Zaki identifies attunement (using perception and empathy to understand what the team needs) as the first super-facilitator capability. For CISOs, this means recognizing that executives and board members don't need simpler security explanations. They need security framed in terms of the complex decisions they're already making. The CFO doesn't need cyber risk explained in kindergarten terms. They need to understand within the same framework they use for financial, market, and operational risk. They need to see how security investments complement and protect other capital allocation decisions. The CEO doesn't need lectures about phishing, but they do need insight into how security (or its absence) affects customer trust, competitive positioning, and deal velocity. Board members don't need the acronyms for certification explained. What they need is to understand how security governance connects to their fiduciary duties, strategic oversight, and risk committee responsibilities. Attunement in the context of a CISO means investing time in understanding: - What keeps each executive up at night (and it's not vulnerability management – it's quarterly targets, competitive threats, talent retention, etc.)? - How does each board member think about their governance role? - What questions do they wish they knew how to ask about security? - Where do they feel most uncertain or vulnerable in security discussions? - What would make them feel genuinely confident in security oversight, not just reassured? This requires humility. You might be the security expert, but they're the experts in business strategy, financial stewardship, market dynamics, and governance. Attunement means recognizing that your job isn't to make them security experts, but to help them apply their current expertise to security decisions. ## **Communication: Making Board Members Security Leaders** Super-facilitators, Zaki explains, mentor others and express genuine belief in their colleagues' capabilities. This is a radical (& exciting!) reframe for CISO-board relationships. Most CISOs would never describe their interactions with board members as mentoring them. That likely sounds presumptuous to most people, but it’s exactly what super-facilitation requires – believing that executives and board members can develop genuine security leadership capability and helping them do it. This doesn't mean teaching board members about industry frameworks. It means: - **Developing their security judgment**: When presenting a security investment decision, don't just recommend an answer. Walk them through your decision framework. "Here's how I weighed the residual risk against the operational impact. What factors am I underweighting from your perspective?" - **Building their security intuition**: Share how you think about security trade-offs, not just your conclusions. "My instinct here was to prioritize detection over prevention because of our cloud architecture. Does that intuition align with the business direction you're seeing?" - **Strengthening their security dialogue**: Provide them with language and frameworks that empower them to engage more effectively. Not security jargon – I mean, actually strategic vocabulary. "You might think of our security posture as having three horizons: immediate operational resilience, medium-term capability building, and long-term architecture transformation." - **Expressing belief in their capability**: When board members ask sharp questions, call it out: "That question gets at exactly the tension we're managing." When they challenge your thinking, embrace it: "That's the perspective I was missing – you're right that the customer trust implications change the calculus." The message you're sending is: "You belong in this conversation. Your judgment matters here. You can lead security oversight, not just receive security reports." Over time, this transforms board dynamics. Security stops being the mysterious technical briefing that everyone tolerates. It becomes a strategic dialogue that executives and board members actively drive. ## **The Courage to Facilitate, Not Just Perform** This approach requires courage. It's vulnerable to treat your board as your team rather than your evaluators. It's risky to shift from demonstrating competence to developing it in others. What if they don't rise to it? What if you look less impressive when you're not the only one talking? But consider what Chris Paul risks every time he passes to a teammate in a crucial moment. He's trusting them to make the shot when he could take it himself. He's creating space for them to be the hero when he could be. This is the bet super-facilitators make — that the collective capability they build will outperform individual heroics, meaning that a team of security-literate executives makes better decisions than one brilliant CISO. The evidence supports this bet. Paul's teams consistently over-perform. Organizations with security-sophisticated boards and executive teams consistently outperform in both security outcomes and business results. The traditional CISO success narrative is about personal mastery, i.e., the expert who keeps the organization secure through superior technical knowledge, vigilant monitoring, and heroic incident response. The super-facilitator CISO success narrative is about leadership multiplication with a facilitator who elevates executive and board security capability so that strategic decisions, governance oversight, and organizational culture become the security program. Communication becomes a superpower, not persuading executives to approve your security program, but developing their capacity to lead organizational security strategy, which ultimately gives you a lot more influence over the outcomes. Executives and board members should leave security conversations feeling more capable, more confident, and with more ownership of security results. That's super-facilitator work. This is your team. Make them better at the game. ### When Ransomware Groups Target Executives: Lessons from Our Latest IR Scenario URL: https://www.discernibleinc.com/when-ransomware-groups-target-executives-lessons-from-our-latest-ir-scenario/ Last updated: 2026-07-11T22:36:09.000Z *This post is inspired by the debrief discussions following our most recent* [*security communications scenario*](http://discernbileinc.com/experience?ref=discernibleinc.com)*, "Operation Harassment: When Ransomware Groups Target Your Executives," which was based on the recent Salesloft/Drift ransomware incident. Our weekly experiences give security teams hands-on practice with realistic scenarios, and the conversations afterward often reveal insights that extend far beyond the simulation.* --- The Salesloft ransomware incident revealed something many security teams aren’t prepared for – modern extortion campaigns that don’t stop at encrypting systems or threatening to publish data. Sometimes they target executives personally, harassing families, posting home addresses, filing fake professional complaints, and flooding personal phones with threatening calls. In the case of the recent Salesloft incident, personal contact information was doxxed by the criminals on Telegram with a financial incentive for everyday people to pick up a pitchfork. Our Discernible Experience last week asked participants to practice three critical communication skills that most incident response training overlooks entirely: - Advising executives to provide specific rather than vague breach notifications - Facilitating threat intelligence sharing with industry competitors - Supporting leaders who are being personally targeted The discussions that followed the exercise surfaced four insights that every business leader should understand. ## **Vague Disclosures Won’t Protect You** The most heated debates in the incident debrief centered on a common scenario – legal counsel recommends intentionally vague incident disclosure language to "minimize liability exposure," leaving affected customers to fill in the blanks with incomplete information. Participants wrestled with advising executives to override legal guidance and provide detailed information about what data was accessed, when, and what customers should do about it. The discomfort was palpable since many security professionals have never been asked to push back on legal recommendations, even when those recommendations clearly harm customer trust and brand value. The counterintuitive reality is that specific disclosure often *reduces* legal risk rather than increasing it. Courts and regulators look more favorably on companies that demonstrate good faith and competency by providing clear, actionable information. Vague notifications create the perception that you either don't understand the incident's scope or you're hiding something, and neither of those protects you in litigation or regulatory proceedings. Discovery is a b\*tch. Also, during our debrief, a few participants focused on one key argument: "Customers who can't determine what data was affected will assume the worst and make decisions based on fear rather than facts. Vague language accelerates the very outcome we're trying to prevent – customer defection and loss of trust." The communication skill being practiced here isn't just "write better notifications or disclosures." It's learning how to advocate for customer-serving transparency when organizational incentives (legal risks, executive egos) push toward opacity. The best security attorneys I’ve ever worked with understand that specificity is actually a risk management strategy, not a liability. ## **Industry Coordination Strengthens Incident Intelligence** When attacks target an entire industry sector systematically (as we saw with sales engagement platforms), companies can respond independently with limited visibility of the threat actor's full campaign, or coordinate with peers (and often competitors) to share threat intelligence and understand the complete attack pattern. Most executives' first instinct is to avoid coordination. "Why would we help our competitors?" was a common response heard by our experience participants. The competitive concern is understandable, but this logic misses the business advantage of information sharing. When you're dealing with a threat actor conducting a systematic campaign across multiple companies, your individual incident data represents only a fraction of what’s going on. You see what happened to *you*, but not what the attacker tried at other companies, which techniques worked or failed elsewhere, or what the attacker's broader objectives might be. Participants practiced articulating reasons for executives to participate in industry coordination, including: - **Better threat intelligence:** Other companies have IOCs (indicators of compromise) and TTPs (tactics, techniques, procedures) that can help you validate whether your investigation is complete. If three other platforms were compromised through a specific third-party integration, that's intelligence you can use immediately. - **Faster response:** Your peers may have already spent days or weeks investigating the same threat actor. Sharing their findings can significantly compress your response timeline and help you avoid investigative dead ends that they’ve already explored. - **Enhanced defense:** Understanding the attacker's full campaign helps you identify which of your defenses worked, which failed, and what the attacker is likely to try next. This is vastly more valuable than working from your isolated vantage point, looking at a single incident. - **Customer protection:** When the same attacker is targeting multiple platforms your customers use, coordinated intelligence sharing helps you provide better guidance about what customers should actually do to protect themselves across their entire tech stack. The legal and competitive concerns about information sharing are addressable through proper structure. Industry ISACs (Information Sharing and Analysis Centers) provide legal protections for shared threat intelligence. The key is separating threat intelligence coordination (sharing IOCs, TTPs, and technical mitigations) from business coordination (which would raise antitrust concerns) – and this is where legal counsel can provide unique value. Security teams sharing "this threat actor used these specific techniques and here's what worked to detect/stop them" is fundamentally different from business teams discussing pricing or customer terms. Still, they need legal guidance on how to do it correctly. Several participants noted that the biggest barrier they’ve experienced isn’t legal risk, but cultural constraints. Many security teams operate in organizations where coordination with competitors feels unnatural or even wrong. The communication skill being practiced here is helping executives understand that refusing to coordinate means operating with incomplete threat intelligence. You're making defense decisions based on partial information about an adversary who has a complete map of the entire campaign. When participants reframed the question from "Are we helping competitors?" to "Are we getting the complete picture we need to make the best decision for the business," the executive decision often shifted. ## **Executive Harassment Requires Acknowledging Human Limits** The most difficult discussions in our scenario centered on the third phase of our incident – a coordinated harassment campaign against executives and their families. Participants role-played scenarios where CEOs were receiving threatening calls, their home addresses were posted online, fake allegations were being filed with professional licensing boards, and family members were being targeted on social media. The criminal's message was explicit: "Pay up or the harassment intensifies. Your family will suffer." Traditional incident response training rarely addresses this scenario, and many participants admitted they had no framework for thinking about it. Our simulation asked participants to develop communication strategies for supporting executives facing this level of harassment, including guidance on when and how to respond publicly, what to communicate internally, and how to balance executive safety with business continuity. Multiple participants expressed understanding of why some executives choose to pay, "not because it's right, but because it's human." This acknowledgment matters. The most effective incident response strategies recognize that executives under sustained personal harassment cannot be expected to make optimal decisions without significant support structures. During our scenario, participants practiced helping executives think through their options while under extreme personal pressure. This required: - **Immediate and substantial support infrastructure.** Participants developed plans that included executive protection consultations, social media security assistance, legal documentation, mental health resources, administrative support for screening communications, and family safety resources. The goal was to ensure executives had the support needed to make clear decisions rather than decisions driven by exhaustion and fear. - **Frameworks for public response.** Participants created guidance for when executives should respond publicly to harassment versus when silence is strategic. - **Internal communication strategies.** Participants also developed talking points for what executives should tell their teams, board members, and close business partners about the harassment campaign without creating panic or appearing to buckle under pressure. Several participants noted that this kind of communication planning underscores the importance of preparing before incidents occur. Organizations need to have discussed these scenarios with boards and executive teams *before* someone is targeted, because trying to establish these frameworks during an active harassment campaign is exponentially harder. The experience didn’t ask participants to advocate for a particular decision about paying the ransom. Instead, we focused on how to help executives maintain decision-making capacity and organizational stability when they're experiencing a severe personal attack, something that requires both practical support and thoughtful communication strategies. ## ***Helpful* Transparency Protects You** The overarching theme across each phase of our scenario was the tension between helpful transparency (which serves customers and strengthens security) and caution (which legal and PR teams often recommend). The irony is that the self-protective instinct to be vague, handle it alone, and minimize public discussion often creates the very outcomes organizations are trying to avoid. The "Streisand Effect." The communication skill underlying every task in this experience was learning to help executives understand that transparency is a risk management strategy, not just a values statement. This requires being able to articulate specific mechanisms through which transparency reduces risk, such as: - Specific, helpful disclosure demonstrates good faith and due diligence in legal and regulatory contexts - Industry coordination provides more complete threat intelligence needed for effective defense and business decisions - Honest acknowledgment of challenges builds stakeholder confidence in your organization’s capabilities and judgment ## **Practice & Preparation Mean More Opportunities** What makes these communication challenges so difficult is that they often require persuading executives to act against their immediate instincts during high-stress situations. "Be more transparent when lawyers advise caution," "coordinate with competitors during an emergency," and "support executives facing personal harassment while maintaining operations," are typically not intuitive responses. This is why we design experiences that practice these specific communication challenges. The participants who performed best in our scenario were those who could clearly articulate the customer perspective, provide specific evidence for their recommendations, acknowledge the legitimate concerns of legal and business stakeholders, and maintain their position under pressure. These are learnable skills, but they require practice. ### Beyond Translation: How CISOs Lead When the C-Suite Can’t Decide URL: https://www.discernibleinc.com/beyond-translation-how-cisos-lead-when-the-c-suite-cant-decide/ Last updated: 2026-07-11T22:28:35.000Z Last week, I was updating my list of resources for a communication and influence workshop with several dozen CISOs. I wanted participants to have solid articles and frameworks they could reference after the session. In doing so, I came across this HBR article: "[Managing Your Team When the C-Suite Isn't Providing Strategic Direction](https://hbr.org/2025/09/managing-your-team-when-the-c-suite-isnt-providing-strategic-direction?ref=discernibleinc.com)" by Jenny Fernandez and Kathryn Landis. It wasn't written for security leaders, but it nailed something I see CISOs struggle with constantly. The article tackles the familiar problem of what to do when senior leadership keeps stalling on key decisions. When accountability rolls downhill while direction fails to flow down from above? When you're stuck managing both confusion and a restless team? This isn't just about organizational dysfunction (although, my god, the blog posts I could write about company-wide dysfunction caused by indecisive executives) – it's about the fundamental challenge CISOs face: leading strategically while influencing upward in an environment where security is rarely the top priority. ## **Four Strategies That Actually Work** Fernandez and Landis propose four strategies for leading when the C-suite can't (or won't) make decisions. What makes them powerful for CISOs is that they're rooted in communication theory, not management platitudes. ### **1\. Reframe Requests and Proposals as Low-Risk** Prospect theory is your best friend here. Daniel Kahneman and Amos Tversky's work demonstrated that people are roughly twice as motivated to avoid losses than to pursue equivalent gains. This loss aversion shapes how executives evaluate risk. **For CISOs**: Stop leading with what could go wrong. We've trained ourselves to think in terms of threats, vulnerabilities, and worst-case scenarios. But when you frame every security initiative as preventing catastrophic loss, you trigger the psychological response that makes executives hesitate. They become risk-averse about making any decision, including the one you're proposing. Reframe your proposals to emphasize how they preserve existing goals while minimizing disruption. Present them as incremental improvements that protect existing business operations rather than major transformations that could destabilize current systems. **In practice:** Rather than saying, "Without zero-trust architecture, we're vulnerable to lateral movement attacks that could compromise our entire network," try "This zero-trust implementation protects our current operations by preventing small incidents from becoming company-wide disruptions. It's essentially an insurance policy for the infrastructure investments we've already made." ### **2\. Quantify the Cost of Inaction** While reframing reduces perceived risk, you still need to create urgency. This is where framing effects come into play – the strategic use of loss framing when the goal is to motivate action rather than shape a specific choice. The research is clear that when you're trying to move someone from inaction to action (rather than choosing between two options), loss frames can be more effective than gain frames. But here's the difference – you're not framing a specific solution as a loss. You're framing inaction as the risky choice. **For CISO**s: Create concrete, data-driven scenarios that illustrate the costs of continued inaction. Not theoretical breach scenarios, but operational inefficiencies, competitive disadvantages, or regulatory exposures that are already happening. **In practice:** "Our current authentication system is generating 47 password reset tickets per week, consuming approximately 12 hours of IT support time. That's $31,000 annually in support costs alone, before we factor in the productivity loss from employees locked out of systems. Three of our competitors implemented MFA last quarter and are now highlighting it in their SOC 2 reports to our shared customers." ### **3\. Keep Your Team Moving and Motivated** This strategy draws on upward communication theory, which emphasizes that effective leadership isn't just about managing up. It's also about creating communication channels that flow in both directions while maintaining team momentum despite organizational ambiguity. Research on upward communication shows that teams perform better when they understand why decisions are delayed and how their work contributes to the larger strategy, even when that strategy is still forming. **For CISOs**: Your security team doesn't need to know every political battle you're fighting, but they do need to understand the landscape. Share what you can about organizational priorities, competing initiatives, and timeline realities. This transparency builds trust and helps your team make better local decisions while you work on securing company-level buy-in. **In practice:** Create regular forums like team meetings, Slack channels, or written updates where you share not just decisions but the context around them. When a security initiative stalls, explain whether it's a budget issue, a competing priority, a stakeholder alignment challenge, or an uncertainty about business impact. This helps your team understand that delays aren't failures, but part of organizational reality. ### **4\. Build Your Influence Up and Across** This connects directly to what we explored in our previous post on "[Why Effective Security Communication Starts with Strategy, Not Translations](https://www.discernibleinc.com/why-effective-security-communication-starts-with-strategy-not-translations/)." The HBR article emphasizes building coalitions with peers and finding ways to influence upward strategically – what we call "climbing the Ladder of Inference” – by understanding that influence requires meeting people where they are and systematically addressing each level of resistance. **For CISOs**: You can't influence C-suite direction if you only interact with executives during budget season or after incidents. You need ongoing relationships with peer leaders (CFO, CTO, COO, GC, CMO) who can help you understand competing priorities and find opportunities for alignment. **In practice:** - Schedule informal check-ins with peer executives to understand their current challenges - Look for ways your security initiatives can solve their problems (the CFO's audit concerns, the CTO's technical debt, the COO's operational inefficiencies) - Share information that helps them succeed, even when it's not directly about security - Build a coalition around shared problems rather than security-specific solutions ## **Why This Matters More Than "Translation"** These strategies are different from the usual "translate security concepts into business language" advice. They're about strategic influence, not vocabulary substitution. The problem isn't that executives don't understand what "endpoint detection and response" means. The problem is they don't know why they should prioritize your EDR recommendation over the fifteen other initiatives competing for the same budget and attention. These four strategies – reframing risk, quantifying inaction, maintaining team momentum, and building coalitions – give you a systematic approach to creating strategic direction rather than waiting for it to appear from above. ## **The Bigger Picture** Fernandez and Landis' key insight: when the C-suite isn't providing strategic direction, senior leaders must step up to flip ambiguity into clarity and keep the organization moving forward. For CISOs, this isn't an occasional challenge. It's a daily reality. Security rarely drives business strategy; it enables and protects it. You're almost always operating in an environment where security isn't the top priority and strategic direction from senior leadership is ambiguous at best. The CISOs who succeed aren't the ones who wait for perfect clarity or complain about a lack of executive support. They're the ones who master these influence strategies: - They reframe security investments as risk mitigation for existing business operations. - They quantify the cost of continuing current practices in terms that executives already care about. - They keep their teams focused and motivated despite organizational uncertainty. - They build peer relationships that create pathways for influence and alignment. ## **Moving Forward** As you prepare for your next executive presentation or strategy session, remember that your job isn't to translate security priorities into business language. Your job is to lead strategically while influencing systematically. That means: - Understanding how your proposals are framed from your audience's perspective (prospect theory) - Making the cost of inaction more salient than the risk of action (strategic loss framing) - Building communication channels that keep your team effective, even when organizational clarity is lacking (upward communication) - Creating coalitions that amplify your influence and align security with business priorities (systematic influence) I first learned these principles as a graduate student in communications at Boston University. They're not just communication tactics—they're leadership strategies grounded in decades of research on how people actually make decisions in the midst of uncertainty. And isn't that exactly where CISOs operate every day? --- ## **Further Reading** If you want to dive deeper into the communication theories that underpin these strategies: **Prospect Theory & Framing Effects:** - Kahneman, D., & Tversky, A. (1979). "Prospect Theory: An Analysis of Decision Under Risk." Econometrica, 47(2), 263-291. - Tversky, A., & Kahneman, D. (1981). "The Framing of Decisions and the Psychology of Choice." Science, 211(4481), 453-458. - Kahneman, D., & Tversky, A. (1984). "Choices, Values, and Frames." American Psychologist, 39(4), 341-350. **Upward Communication Theory:** - Klauss, R., & Bass, B.M. (1982). "Interpersonal Communication in Organizations." Academic Press. - Study on upward communication and organizational effectiveness:[ EBSCO Research Starters on Upward Communication](https://www.ebsco.com/research-starters/business-and-management/upward-communication?ref=discernibleinc.com) ### How to Market Privacy Without Falling Into the Privacy Washing Trap URL: https://www.discernibleinc.com/how-to-market-privacy-without-falling-into-the-privacy-washing-trap/ Last updated: 2026-07-11T22:36:47.000Z *A practical guide for marketing and PR professionals who want to build genuine trust* --- You've probably seen this everywhere: "Your privacy is important to us." A phrase so ubiquitous it's practically meaningless. And that's exactly the problem. A recent article from Privacy Guides titled ["Red and Green Privacy Flags"](https://www.privacyguides.org/articles/2025/09/03/red-and-green-privacy-flags/?ref=discernibleinc.com) breaks down how consumers are getting better at spotting "privacy washing" — the practice of misleadingly, or fraudulently, presenting a product, service, or organization as being trustworthy for data privacy, when in fact it isn't. As marketers, we need to understand these signals not just to avoid them, but to build genuinely trustworthy privacy communications. Here's how to navigate this landscape without accidentally undermining your brand's credibility. ## **The Problem: Everyone Says the Same Thing** Buzzwords like "military-grade encryption", "privacy-enhancing", and the reassuring classic "we never sell your data" (but we will share it willingly) get thrown around like candies falling off a privacy-preserving-piñata. But here's the thing — your audience is getting smarter. They know how to spot the red flags. Here’s what savvy consumers look for (the **red** flags you want to avoid): ### **1\. Conflict of Interest Red Flags** A conflict of interest is one of the biggest red flags to look out for, and it comes in many forms, including sponsorships, affiliate links, parent companies, donations, employment, personal relationships, etc. **For your marketing**: Be transparent about partnerships and data-sharing arrangements. If you're partnering with a data broker for attribution, don't hide it in paragraph 47 of your privacy policy. ### **2\. The "Forced Cooperation" Spin** Spinning regulatory investigations or audits into something that sounds favorable to the corporation is a form of privacy washing. Most organizations would not be "working with" the privacy regulator if they hadn't been forced to in the first place. **For your marketing**: Don't try to spin regulatory compliance as a form of voluntary leadership. Instead, focus on what you're doing beyond the minimum requirements. ### **3\. Vague, Meaningless Language** When your copy could apply to literally any company, you're not building trust — you're contributing to the noise. Instead of: "We take your privacy seriously." Try: "We delete your browsing data after 24 hours and never sell it to third parties" (with specifics about your actual practices). ## **The Opportunity is Building Real Trust** The good news? There are **red** (and **green**) flags we can look for to help us. Understanding what builds trust gives you a competitive advantage. Here are some **green** flags that build credibility: #### **1\. Community Consensus** If your tool or product is repeatedly recommended by multiple experts (not websites or influencers, but real domain experts), then this can be a **green** flag that the community generally trusts the tool or service. **Pro Tip**: Seek endorsements from seasoned privacy experts, not just influencers. Feature testimonials from verified professionals who actually understand your technical implementation. Their feedback is a gift. #### **2\. Transparency in Action** Show, don't tell. If your app doesn't require account creation, lead with that. If you delete user data after specific timeframes, make it prominent. **Pro Tip:** Lead with privacy features in your product messaging, not just in the fine print. If your chat app doesn't store message history on servers, make that a headline feature. If you auto-delete user activity after 30 days, put it on your homepage. Create comparison pages that show what you *don't* do compared to competitors. Turn your privacy practices into competitive advantages that sales and marketing can actually discuss, rather than legal disclaimers hidden in fine print. #### **3\. Proactive Communication** Address the elephant in the room. If your business model requires collecting certain data, explain why and how you protect it. **Pro Tip:** When introducing a new feature that requires data collection, announce it with a blog post or email that clearly explains the trade-off. For example: "Our new fraud detection system analyzes purchase patterns, which means we'll retain transaction data for 90 days instead of 30\. Here's why we think this protects you, and here's how to opt out if you prefer not to participate." Don't wait for users to discover changes in a privacy policy update. If you’re fearful of them finding out what you’re doing, that’s a huge **red** flag that you’re violating user trust. ## **Practical Steps for Improvement** #### **1\. Audit Your Current Messaging** Go through your website, ads, and privacy policy. Count how many times you use generic privacy phrases without backing them up with specifics. That's your starting point. If this sounds overwhelming, you're not alone – we do this for busy clients all the time and help them set up tracking mechanisms to flag when updates are needed. The key is starting somewhere, even if it's just your homepage and main landing pages. #### **2\. Get Specific About Your Practices** Work with your legal and product teams to identify concrete privacy practices you can highlight, such as: - Data retention periods - Third-party integrations (or lack thereof 🤩) - User control options - Technical safeguards #### **3\. Test Your Claims** Use a search engine to look for related news using keywords such as the company's name with "data breach", "fined", or "privacy". Do this exercise on your own company. What comes up? Address any concerns proactively. Then ask your favorite AI agent. Rinse and repeat regularly. #### **4\. Focus on User Benefits** Instead of talking about how much you care, focus on what users get: - "Download all your data in one click." - "Your messages are encrypted, so even we can't read them." - "No tracking pixels in our emails." ## **The Long Game: Building Genuine Privacy Leadership** Privacy isn't just a term on your SEO bingo card — it's a genuine differentiator. The companies that will win long-term are those that build privacy into their business model from the ground up, not those that try to marketing-speak (or worse, LeGaL sPeAk!) their way around poor practices. The companies that will win long-term are those that build privacy into their business model from the ground up, not those that try to marketing-speak their way around poor practices. Questions to ask your team: - If an independent expert (or regulator! 😰) were to audit our actual practices (not just our policies), what would they find? - What would we need to change to make our privacy marketing completely truthful? - How can we give users more control, not just more reassurance? Privacy washing isn't just ethically questionable — it's a business risk as consumers get savvier at spotting it. The opportunity lies in being one of the companies that actually delivers on privacy promises. Your marketing will be more effective, your legal team will sleep better, and your customers will actually trust you. In a world full of empty "your privacy is important to us" statements, genuine privacy practices are truly a competitive advantage. ### The CISO's Guide to Making the Business Case: How Security Investments Drive Brand Performance URL: https://www.discernibleinc.com/the-cisos-guide-to-making-the-business-case-how-security-investments-drive-brand-performance/ Last updated: 2026-07-11T22:37:59.000Z Findings from the [2025 Edelman Trust Barometer](https://www.edelman.com/trust/2025/trust-barometer/special-report-brands?ref=discernibleinc.com), released earlier this year, offer several insights for CISOs seeking to elevate their program’s position from a cost center to a brand differentiator with direct impacts on revenue, customer loyalty, and market valuation. ## **Repeat After Me: “Security = Brand Equity”** ### **Trust is Currency** According to the Edelman report,brand trust (68%) now significantly exceeds institutional trust (55%), a 13-point gap that represents unprecedented consumer confidence in corporate responsibility compared to government or civic organizations (depressing but true). This elevated trust in brands creates both opportunity and risk for your company. **What this means for your CEO:** - Security incidents now damage brand equity, not just IT systems - Competitive advantage increasingly depends on consumer trust - Cybersecurity investments protect and enhance market valuation ### **Trust Directly Drives Purchase Decisions** According to the report, trust ranks equally with cost and quality as a purchase consideration (84%). This elevates cybersecurity from operational necessity to revenue driver because: - Security investments protect revenue streams - Proactive security creates competitive differentiation - Trust-based purchasing decisions favor security-forward brands ### **Security Contributes to Brand Emotional Value** Edelman reports that68% of consumers want brands to "make them feel good" by providing feelings of safety, confidence, and calm. Turns out, security can directly contribute to three of the top five brand emotional needs cited in the report’s findings: 1. Safety and confidence (68% demand) 2. Optimism for the future (62% demand) 3. Education and guidance (59% demand) ## **Your Assignment: Build the Business Case** Making security a business priority isn’t an exercise in repackaging technical metrics. It demands that you gather concrete evidence from your own organization, uncovering the actual business relationships that prove security's strategic value. It’s not easy and it’s a lot of work, but that’s the job. This isn't a one-time project either. Building a compelling business case requires establishing ongoing measurement systems that connect security activities to business outcomes. You're essentially building a new reporting infrastructure that runs parallel to your technical security metrics. Here's some groundwork you need to do: **1\. Map Security to Customer Behavior** Don't assume the connection. You must prove it with data: - Pull customer satisfaction scores and overlay them against your security incident timeline. Look for correlations. - Analyze customer churn rates before and after security communications or incidents. - Survey your customer base: How much does security factor into their purchasing decisions? Their renewal decisions? - Compare Net Promoter Scores across different customer segments to determine whether security-aware customers score higher. **2\. Quantify Your Revenue Exposure** Help your leadership understand what's actually at risk: - Calculate revenue-at-risk for systems without adequate security controls. - Document deals won or lost based on security requirements or capabilities. - Identify revenue streams that depend entirely on customer trust (subscriptions, data-dependent services, etc.). - Research the premium customers are willing to pay for enhanced security features. **3\. Connect Security Investment to Market Position** Demonstrate competitive reality: - Benchmark your security posture against direct competitors and identify where you lead or lag. - Document RFPs lost due to security requirements you couldn't meet. - Track competitive wins where security was a differentiator. - Calculate your share of security-conscious market segments versus the overall market share. 💡 ****Quick Win**: Start with the data you can access immediately. Most organizations can identify reasons for deal losses within a few weeks by reviewing CRM systems, customer satisfaction trends, and competitive analysis. Don't let the perfect be the enemy of the good – an 80% complete picture built on real data beats a perfect hypothesis. **4\. Measure the Emotional Impact** Yes, this is even harder – but it matters: - Collaborate with your marketing team to incorporate security-related questions into customer research. - Test whether customers feel "safe," "confident," or "optimistic" about your data practices. - Measure support ticket volume and resolution costs for security-related concerns. - Track brand sentiment in relation to security announcements or incidents. --- This work requires time, cross-functional collaboration, and may involve new data collection methods. You'll need allies in finance, marketing, customer success, and sales, at the very least. But without this organizational intelligence, you're asking leadership to fund security on faith rather than evidence. Budget 3-6 months to build your first comprehensive business case, and don’t get discouraged if some of this data doesn’t exist yet in your organization. That's OK. Identifying measurement gaps is itself a valuable source of intelligence. Start with what's accessible, document what's missing, and build your case iteratively. The Edelman data shows the macro trend, and now your job is to prove it exists in your business. ### Privacy Needs a Better Story URL: https://www.discernibleinc.com/privacy-needs-a-better-story/ Last updated: 2026-07-11T22:39:11.000Z Privacy professionals have long struggled with how to position privacy work as business value rather than compliance overhead. A recent blog post by our friends at [Privatus Consulting](https://privatus.online/2025/07/14/privacy-and-the-value-chain/?ref=discernibleinc.com) offers a compelling solution by applying Michael Porter's value chain framework to privacy operations. The real power of this approach lies in how it reframes the entire conversation about privacy in business. The connection that Porter’s framework draws between analysis and communication isn't coincidental – it's central to what communication scholars call "Framing Theory," referring to the way that information is structured and fundamentally shapes how audiences understand and respond to it. When privacy professionals map their work against Porter's value chain categories, as Privatus suggests, they're building a strategic communication framework that transforms how stakeholders perceive the business impact of privacy. ## **The Framing Problem in Privacy Communications** Most privacy professionals fall into what Privatus calls the "cost-avoidance corner." They communicate about privacy through frames like "we reduce risk" or "we help avoid fines." While technically accurate, this defensive framing creates a self-fulfilling prophecy. If you consistently position privacy as protection against negative outcomes, stakeholders will inevitably view it as a cost rather than a strategic asset. This mirrors a pattern we see across security and privacy communications in general. As I've [written before](https://www.discernibleinc.com/organizations-lack-sufficient-decision-frameworks-to-expand-incident-response-options/), traditional incident response communications focus heavily on risk mitigation and compliance requirements. While these elements remain crucial, leading with positive outcomes transforms how stakeholders perceive privacy investments by aligning with something business leaders are already motivated to achieve, rather than asking them to care about what privacy professionals worry about. The problem isn't that executives don't understand what privacy teams do. The problem is that they don't know why they should prioritize privacy initiatives at this time, given the numerous competing demands for their attention and budget. Here's the psychological mechanism we’re dealing with: When you lead with risk mitigation ("we need this to avoid GDPR fines"), you're asking stakeholders to imagine negative scenarios and invest money to avoid them. This creates a mental framework where privacy is inherently about spending money on problems that might never happen. Even when they approve the investment, it’s not exciting and doesn’t leave them with a desire to invest more. But when you lead with positive outcomes ("this consent management system will increase email engagement rates by 20% because we'll only be reaching genuinely interested prospects"), you're connecting privacy work to outcomes business leaders actively want to achieve – marketing efficiency, customer engagement, and competitive advantage. Does this approach require more effort on our part? Absolutely. That’s the job. Business leaders want to fund initiatives that help them win, not just avoid losses. The transformation happens because you're speaking to their existing motivations rather than asking them to adopt yours. It’s accurate communication about the full value of what good privacy work actually accomplishes. The positive outcomes are real; most privacy communications just fail to emphasize them. ## **The Ladder of Inference in Privacy Value Communication** As we move beyond simple reframing into true influence, privacy professionals can apply what we call the [Ladder of Inference](https://www.discernibleinc.com/why-effective-security-communication-starts-with-strategy-not-translations/) – a framework that helps build communication strategies that change minds and drive action. Here’s how it works: **Actions**: Start with what you want to accomplish. "I need the executive team to approve $200,000 for enhanced consent management by Q3" is infinitely more useful than "I want them to understand our privacy challenges." **Beliefs**: What does your audience currently think about privacy investments? They may believe current privacy measures are sufficient, or that privacy spending doesn't generate measurable ROI. **Conclusions**: Surface the resistance. The CFO might conclude that privacy tools never deliver promised business benefits. The CMO might believe that privacy restrictions inherently conflict with marketing effectiveness. **Assumptions**: Find the faulty foundation. Often, resistance stems from outdated information. The executive team might assume that "good enough" privacy from five years ago still applies, or that privacy is purely a concern of the legal department. **Interpreted Reality**: Connect to their world. A privacy breach doesn't just mean "compliance violation" to a CEO – it means customer churn, congressional hearings, and career-threatening headlines. **Selected Reality**: Expand their experience. If their only experience with privacy involved restrictive policies that slowed down business initiatives, they'll be skeptical of your proposals. Share case studies from similar organizations that have successfully turned privacy into a competitive advantage. **Reality & Facts**: Fill the information gaps. Only at this bottom rung do you focus on data, technical specifications, and regulatory requirements. However, this information is now targeted and contextual, designed to support the journey up the ladder rather than overwhelm with compliance details. ## **Reverse Engineering Privacy Success** Just as we can reverse engineer positive incident outcomes, privacy professionals can work backward from desired business results to build more compelling value propositions. Start by conducting an aspirational reflection exercise with your privacy team. Six months from now, what do you want business leaders to say about how privacy contributed to our success? Document your team’s desired outcomes, then reverse engineer your privacy strategy to make them a reality. Common aspirational statements might include: "Our privacy-by-design approach reduced our product development cycle by 30%," "Our transparent data practices became a key differentiator in competitive deals," or "Our privacy program enabled us to enter new markets ahead of competitors." Once you’ve identified your desired outcomes, you can map them against the value chain to identify specific opportunities where privacy work creates measurable business value. ## **Practical Implementation: The Privacy Value Workshop** The Privatus blog post also suggests running a workshop with business stakeholders to co-create your privacy value chain. This collaborative approach leverages a key insight from the communications framing theory: people are more likely to accept and act on plans they help construct. Here's how to structure this workshop: 1. **Map the Current State**: Start by sketching your organization's value chain using Porter's categories or adaptations that fit your context. 2. **Overlay Privacy Touchpoints**: Work with stakeholders to identify where privacy considerations intersect with each value chain activity. 3. **Identify Value Creation Opportunities**: For each intersection, ask: "How could privacy improve efficiency, reduce costs, increase revenue, or create competitive advantages here?" 4. **Quantify Impact**: Where possible, attach metrics to these opportunities. "Privacy vetting of vendors can reduce onboarding time by 20%" is more compelling than "privacy helps with vendor management." Doing math won’t kill you, even if you’re a lawyer. 5. **Build Shared Ownership**: Ensure stakeholders contribute to both problem identification and solution development. This creates buy-in and surfaces insights that your privacy team might otherwise miss. ## **Moving from Translating to Influencing** Remember that the real power of value chain framing isn't translating privacy jargon into business language, but translating privacy priorities into outcomes that matter to someone else, thus connecting the privacy risks you understand deeply to the business opportunities that keep your executives engaged. When privacy professionals master this strategic kind of translation, they find that their technical expertise becomes far more impactful and privacy recommendations move from the "someday maybe" pile to approved and resourced initiatives. The goal was never to make everyone understand privacy the way we do. The goal is to help them understand why privacy matters for what they're trying to accomplish. That's a much more achievable (and valuable) objective. The value chain approach gives privacy professionals a systematic method for moving beyond defensive risk communication toward strategic value creation. By mapping privacy work against core business activities and identifying specific opportunities for improvement, you create a compelling narrative that isn’t about a compliance burden. When you can show how privacy work directly contributes to speed-to-market, operational efficiency, customer loyalty, and brand differentiation, you elevate the entire conversation about privacy's role in business. The framework is straightforward, but the shift in communication is profound. ### Trust Recovery Starts Before the Incident, Not After URL: https://www.discernibleinc.com/trust-recovery-starts-before-the-incident-not-after/ Last updated: 2026-07-11T22:40:12.000Z How you communicate before and during an incident significantly impacts your ability to retain or recover customer trust. Even when customers understand that there will be occasional issues, they still need to see competent incident management and clear communication. Demonstrating operational maturity during the incident becomes evidence of your organization’s reliability. Yet, most organizations approach incidents with a defensive mindset, becoming so focused on minimizing perception of the problem that they inadvertently create a trust problem. They treat customers as outsiders to be protected from incident details, when in reality, your incidents aren't just happening to you; they're also happening to your customers. By keeping information from the people who are directly affected, you're withholding context that could actually help them understand and work with you through the disruption. ​​Moreover, this erosion of trust doesn't simply reset once your team closes the incident — it carries forward, making every future incident harder to navigate as customers approach each new disruption with accumulated skepticism. ## What Could Go Right: Reframing Incident Communication Our “[What Could Go Right](https://www.discernibleinc.com/what-could-go-right/)” principle asks teams to consider: *What if this incident actually demonstrated our organizational strengths?* *What if clear communication during the outage became evidence of our reliability rather than proof of our problems?* When incidents occur, this reframing becomes especially powerful because: 1. **Most incidents involve legitimate operational decisions.** Many incidents stem from routine maintenance, capacity planning, or protective measures that didn't work as expected. The narrative shift from "we broke something" to "we were being proactive and hit an edge case" requires intentional communication during the incident. 2. **Customers expect operational complexity.** Most business customers understand that robust systems sometimes create unexpected interactions. They're more concerned with how quickly and professionally you handle the situation than with the fact that it happened at all. 3. **Operational maturity becomes visible in real-time.** How you coordinate between technical teams and customer support during an incident provides customers with direct evidence of your organizational competence. Smooth information flow and clear communication demonstrate the kind of operational excellence customers want in their vendors. ## Building Better Incident Communication Incident response communication shouldn't be a special mode you switch into during emergencies. It should be an extension of how you engage with customers every day. Incidents may be punctuated moments, but they don't happen in a vacuum. The trust and communication patterns you've established during normal operations become the foundation customers rely on when things go wrong. Think of it like a Formula 1 pit crew making adjustments mid-race. The driver doesn't suddenly freak out at the team because they need to change tires or adjust the wing – they expect the crew to handle these situations smoothly because they've practiced together countless times. The difference between a winning pit stop and a race-ending disaster is the seamless communication and coordination that comes from working as a unified team long before race day. Similarly, the most effective incident communicators prepare for trust-building opportunities by: 1. **Training customer-facing teams on technical concepts.** Your support agents need ongoing education about your systems and operations, not just crisis briefings. When they understand how your infrastructure works day-to-day, they can explain disruptions confidently without revealing sensitive details that could compromise operational security or your competitive advantage. 2. **Establishing clear information-sharing protocols.** Technical teams often hold information too tightly during incidents because they've never practiced sharing it during calm periods. Defining what can and can't be communicated (and training teams on those boundaries) enables faster, more confident customer communication when it matters most. 3. **Planning for uncertainty as a normal state.** Most technical work involves uncertain timelines, not just incident resolution. Rather than treating timeline uncertainty as an incident-specific problem, successful teams develop frameworks for managing customer expectations around evolving situations as part of their regular communication practice. ## Practicing What Could Go Right Our Discernible Experience incorporates this “what could go right” principle in the tasks assigned to participants each week. Rather than just focusing on technical resolution, our scenarios challenge participants to consider how their incident response choices impact stakeholder trust and organizational reputation. Participants practice communicating technical security issues into executive- and customer-facing explanations, coordinating between security engineering and cross-functional partners, and managing stakeholder expectations during extended resolution processes. The goal isn’t just to restore service, but to emerge from the incident with critical relationships intact or even strengthened. Organizations that apply “what could go right” thinking to incident communication often discover that incidents become opportunities to demonstrate their operational maturity. Customers who see competent incident management and transparent communication during outages frequently become more loyal, not less. ### Your Team's Communication Isn't Just What You Say – It's Who You Are: Understanding Constitutive Theory URL: https://www.discernibleinc.com/your-teams-communication-isnt-just-what-you-say-its-who-you-are-understanding-constitutive-theory/ Last updated: 2026-07-11T22:41:28.000Z *How your security and privacy teams communicate doesn't just convey information—it actively creates your organization's security culture, decision-making processes, and operational reality.* Security and privacy leaders often view communication as a tool — a way to convey policies, report incidents, or train employees. But communication is far more fundamental than that. The way your team communicates doesn't just describe your organization's security or privacy posture; it creates it. This is the core insight of the [constitutive theory of communication](https://onlinelibrary.wiley.com/doi/10.1111/j.1468-2885.1999.tb00355.x?ref=discernibleinc.com), a body of scholarship that’s transformed how we understand organizations for more than two decades. For security and privacy leaders, constitutive theory offers a powerful lens for understanding why some programs thrive while others struggle, regardless of their technical investments. ## **Communication as Creation** Historical approaches to organizational communication view it as a conduit or container that facilitates the flow of information from sender to receiver through various channels. This "conduit metaphor" assumes that communication simply transports meaning from one place to another, implying that your team's job is to craft clear messages about policies and threats, then push them through the right channels to reach employees. Constitutive theory fundamentally challenges this assumption. Communication as Constitutive of Organization (CCO) is the idea that an organization emerges in and is sustained and transformed by communication. Rather than viewing communication as something that happens within your organization, constitutive theory presents that communication *is* your organization. I’m not referring to semantic wordplay; this has profound practical implications. When your team holds a meeting, sends an alert, or conducts an incident response, you're not simply exchanging information; you're sharing insights and influencing behavior. You're essentially constructing what your organization is, how it operates, and what it values. ## **Communication Systems Change Behavior** The most immediate implication of constitutive theory is understanding how different communication approaches fundamentally alter organizational behavior. CCO provides leaders with new perspectives on how their organization operates – identifying who has influence, how decisions are made, and what everyone's actual role is — by paying attention to how people communicate with each other. When working with Discernible clients, we observe how each communication pattern actively shapes their individual and team roles through ongoing interactions. Consider two security teams facing the same phishing incident: **Team A** follows a traditional top-down communication approach. The CISO sends an email blast warning about the threat, IT blocks malicious domains, and security awareness schedules mandatory training sessions. Information flows from experts to employees. **Team B** adopts a constitutive approach. They lead cross-functional incident response conversations that include voices from affected departments, ongoing dialogue about emerging threats rather than one-way announcements, and they recognize that every conversation shapes how the organization understands and responds to security challenges. The difference isn't just in style, but in the organizational reality each approach creates. Team A constructs an organization where security is something done *to* employees by experts. Team B constructs one where security emerges *through* collective engagement and shared accountability. Each communication approach also determines how much influence and political capital your program accumulates. Team A's top-down approach positions security as a cost center that restricts business activities, which will gradually erode leadership support. Team B's collaborative approach positions security as a business partner, building the political capital necessary for budget approvals, strategic alignment, and organizational change. ## **Your Organization Is Your Communication Patterns** Perhaps the most radical insight of constitutive theory is that your organization doesn't have communication patterns; it *is* those communication patterns. Think about what this means for incident response. When a security incident occurs, how does your team communicate? Do you: - Hold meetings with predetermined hierarchies and speaking orders? - Create ad-hoc channels for rapid information sharing across departments? - Default to formal reporting structures that delay critical decisions? - Enable real-time collaborative problem-solving with diverse stakeholders? Each approach actively creates an organizational structure in the moment. CCO scholarship argues that communication itself is responsible for bringing organizations into being, and then perpetuating and transforming them. The implications extend beyond incident response. For example, every team stand-up, every policy review meeting, every board interaction is simultaneously describing and creating your organization’s reality. This becomes particularly visible in how your team interacts with other departments, actively building or destroying your political capital. Are you: - **The Department of No**: Creating interactions based on restriction, compliance, and gatekeeping? This communication pattern creates adversarial relationships that drain political capital. - **Strategic Enablers**: Fostering conversations focused on business objectives and risk-informed decision-making? This approach earns influence by making business objectives achievable. - **Collaborative Partners**: Building ongoing dialogues that value security considerations in organizational planning? Teams using this approach accumulate political capital by making others more successful. In constitutive theory terms, influence is something you create through repeated communication patterns. Every interaction either deposits or withdraws from your political capital account. When you consistently communicate in ways that make other teams more successful, you establish yourself as an indispensable organizational asset. Imagine if anyone on your team were seen this way by business stakeholders. ## **Designing Communication Intentionally** Most security communication strategies focus on tools and channels, such as better dashboards, clearer policies, and more engaging training platforms. While these have value, constitutive theory suggests a more fundamental approach: intentionally designing the communication patterns that will constitute your desired organizational reality. Building trusted relationships with various stakeholders is crucial, but as we’ve [pointed out before](https://www.discernibleinc.com/boost-your-teams-influence-with-corporate-anthropology/), we build trust through consistent communication patterns, not solely communication content. Team leaders who think like organizational architects understand that every interaction is an opportunity to shape the culture, operational processes, and stakeholder relationships that will improve your organization's resilience, agility, and reputation. So, instead of viewing business leaders and cross-functional partners as audiences for security messages, recognize them as co-creators in your organization's security and privacy reality. Moreover, CCO scholarship promotes a "post-heroic" understanding of management, where human impact is a result of the network of communication, rather than a lone individual. Instead of centralizing all security and privacy decisions with a small group of experts, you can create communication processes that enable distributed, informed decision-making. Since the question isn't really whether you're shaping your organization through communication (because you inevitably are, whether you realize it or not) – the question is whether you're doing so intentionally, with awareness of how your communication choices create the culture, operational capabilities, and stakeholder relationships that determine your program's success. ### How Organizations Sabotage Media Relations by Misunderstanding Security Communications URL: https://www.discernibleinc.com/how-organizations-sabotage-media-relations-by-misunderstanding-security-communications/ Last updated: 2026-07-11T22:43:16.000Z When most organizations think about security communications, they picture a crisis scenario with executives huddled in a conference room, crafting carefully worded press statements while reporters circle like sharks. It's no wonder that many companies treat security communications as synonymous with media relations, a reactive function that only matters when everything has already gone wrong. Unfortunately, this narrow view isn't only incomplete but also actively sabotages the very media relationships these organizations need to protect. # The Credibility Gap Here's the uncomfortable truth: traditional media relations account for a small fraction of effective security communications. The other vast majority of security communications — the part that determines whether your media interactions succeed or fail – happens long before any reporter reaches out with questions. This is because when knowledge of (or the rumor of) a security incident reaches them, journalists aren't starting from scratch. They're drawing on months or years of accumulated context about your organization, including how you've communicated with customers during smaller issues, how transparent you've been with regulators, how you've engaged with your employees about security priorities, and whether your executives have built credibility in this space through consistent messaging over time. This foundation of trust and understanding (or lack thereof) shapes every media interaction you'll have during an incident. Organizations that treat security communications as purely external and reactive often discover too late that they lack sufficient credibility and influence with the right stakeholders to make a meaningful impact on external perception. # Internal Foundations The most critical security communications occur within your organization, often in rooms that traditional PR professionals are unfamiliar with. These conversations aren't just preparation for external messaging, but the operational backbone that determines whether your security program is effective. When your incident response team discusses how much detail to share with affected customers to help their technical teams mitigate risk, they're making communications decisions that directly impact response effectiveness. When engineering debates whether to mention a security improvement in release notes, that's a communications strategy that influences developer adoption and user trust. When executives decide how to frame security investments in board presentations, they're building the organizational support that determines resource allocation and strategic priority. Effective security operations depend on these internal communications. Your ability to secure budget approval, gain cross-functional cooperation, drive policy compliance, and coordinate incident response all hinges on how well you communicate with internal stakeholders. The security team that can't persuade developers to prioritize vulnerability remediation will struggle with patch management regardless of their technical capabilities. The CISO who can't articulate security ROI to executives will find their program perpetually under-resourced. This internal communication competence becomes externally visible during media interactions. Journalists immediately recognize the difference between organizations where security communications flow naturally across all functions and those that scramble to coordinate their story during an emergency. A company that struggles to communicate clearly about security internally consistently fumbles in convincing external audiences of its operational competence. We regularly see organizations invest heavily in media training for executives while completely ignoring how their customer service team handles security-related inquiries, or how their sales engineers discuss security architecture with prospects. They'll spend months crafting the perfect incident response templates ([an asset I’ve never found valuable](https://www.discernibleinc.com/decisive-under-fire/)) while their engineering teams can't effectively influence security requirements in product roadmaps. Not only does operational dysfunction confuse stakeholders and undermine your effectiveness as a security organization, but it also creates the contradictions that journalists love to explore. # Stakeholder Communications: The Foundation of Media Success Your relationships with customers, partners, employees, and regulators aren't separate from media relations because every stakeholder is a potential source for journalists covering your organization. The customer service representative who fields security questions, the employee who posts on social media, the partner who gets briefed on your security posture – they're all part of your reputation and communications ecosystem. When organizations compartmentalize these relationships, they create inconsistencies that journalists inevitably discover. The company that projects confidence to the press while sending panicked emails to customers creates exactly the kind of story that reporters find irresistible. Conversely, organizations that maintain consistent and honest communications across all stakeholder groups find that their media interactions feel like natural extensions of existing relationships, rather than adversarial interrogations. This is why the "[what could go right?](https://www.discernibleinc.com/what-could-go-right/)" approach we've discussed previously is so powerful for media relations. When you've prepared to communicate positively with all stakeholders, you're not scrambling to craft a different narrative for reporters. Instead, you're sharing the same story of competence and accountability that's already resonating across your organization. # The Trust Account Theory Every security communication — whether it's an incident report to customers, a blog post about your security program, or even guidance on how you handle security questions in sales calls — makes deposits or withdrawals from your organizational trust account. Media relations heavily draw on this account during high-profile situations. Organizations that focus exclusively on managing press relationships are essentially trying to make major withdrawals from an account they've never bothered to fund. They discover during incidents that they have no credibility to spend, no track record of transparency to point to, and no stakeholder advocates willing to vouch for their character or capabilities. Meanwhile, companies that invest consistently in comprehensive security communications build substantial trust reserves. When incidents occur, they're not asking journalists to take their word for their competence because they can point to a demonstrated pattern of responsible behavior that reporters can easily verify through other sources. # Moving Beyond Reactive Comms Effective security communications start with recognizing that every touchpoint is a communications opportunity. Customer support interactions, employee onboarding materials, vendor assessments, regulatory filings, conference presentations — all of these shape the perceptions that will eventually reach the media. Start by conducting a communications audit across your organization. How does sales discuss security with prospects? What do customer success teams tell clients about your security posture? How do executives frame security investments internally? Look for inconsistencies, gaps, and missed opportunities to build credibility and trust. Develop consistent messaging frameworks that work across all these channels. Your security story shouldn't change depending on whether you're talking to customers, employees, or reporters; however, the level of detail and technical sophistication should. This consistency isn't about controlling the message as much as ensuring that your communications reflect a coherent and accurate understanding of your security program and priorities. Invest in training and systems that help all stakeholder-facing teams communicate effectively about security. The customer service representative who can confidently explain your incident response process, the sales engineer who can thoughtfully discuss your security architecture, and the executive who can articulate security ROI — these are the people who build the foundation that makes productive media relations possible. # The Strategic Advantage Organizations that understand security communications holistically don't just handle media better; they fundamentally change their relationship with all stakeholders, becoming trusted sources of information rather than defensive reactors to events. This allows them to build coalitions of advocates rather than managing lists of critics. When a security incident occurs, these organizations don't face hostile media environments because they've spent months or years demonstrating their competence and accountability through consistent, stakeholder-focused communications. Media interactions with these companies often feel collaborative rather than adversarial, as reporters recognize them as credible sources and the security community supports them. This is the real competitive advantage of [proactive security communications](https://www.discernibleinc.com/turning-incident-response-communications-into-a-sustainable-security-communications-program/). It's the ability to navigate challenges from a position of strength rather than constantly playing defense. By investing in security communications that occur out of reporters' line of sight, organizations establish the credibility and trust that make visible communications not just manageable, but genuinely effective. The next time your organization faces a security incident, the quality of your media interactions won't be determined by the press statement you craft in the moment. It will reflect the thousands of communications decisions you made in the months and years leading up to it. Ensure that those decisions are laying the foundation you'll need when everyone is watching. ### Transparency Schmarency: Security Disclosures Should Be Honest and Helpful URL: https://www.discernibleinc.com/transparency-schmarency-security-disclosures-should-be-honest-and-helpful/ Last updated: 2026-07-11T22:44:48.000Z Organizations often default to promising "transparency" in their incident communications. But transparency alone is insufficient – and sometimes counterproductive. What we really need are disclosures that are both honest *and* helpful. ## **The Problem with "Transparency"** Transparency is often misinterpreted as merely revealing an incident. It should mean a comprehensive and clear communication that provides the necessary context and actionable information. This approach treats disclosures not as confessions, but as resources that empower stakeholders. Many organizations approach security disclosures as a legal obligation, minimizing the information they reveal to only what is required by contracts or regulations, or what they believe will limit their liability. However, this defensive stance overlooks the opportunity to build trust and enhance security outcomes (the lawsuits are coming no matter what; you might as well extract some value from the experience). As we discussed in a previous [post](https://www.discernibleinc.com/what-could-go-right/), it’s helpful to develop your strategy by first asking “what could go right?” so you can reverse-engineer that outcome. When organizations are genuinely helpful in their disclosures, they: - Build credibility for future communications - Contribute to the broader security community's understanding of threats - Enable faster, more effective responses from affected parties - Demonstrate that they view security with [shared accountability](https://www.discernibleinc.com/the-myth-of-shared-responsibility/) ## **The Honest and Helpful Alternative** Being honest and helpful means shifting from a defensive, liability-focused mindset to one that prioritizes empowering those affected to take action because no one knows your environment better than you, so it’s your responsibility to ensure disclosures serve a practical purpose beyond legal compliance. My colleague [Leona Laurie](https://www.linkedin.com/in/leonalaurie/?ref=discernibleinc.com) often says that every communication has a job to do – and in the case of security disclosures, we need specific objectives for every asset we create. ### **What "Honest" Means** Honesty in security disclosure goes beyond acknowledging that an incident occurred. It means: - **Clarity about scope**: Which systems, data types, and timeframes were affected? - **Admission of unknowns**: Being explicit about what you don't yet know rather than hiding behind vague language. - **Context about severity**: Helping people understand the actual risk level. - **Accepting responsibility**: Taking ownership without deflecting or minimizing. ### **What "Helpful" Means** Helpful disclosures provide actionable intelligence such as: - **Specific indicators**: What should people look for to detect if they've been affected? - **Immediate actions**: What steps can individuals or organizations take right now to protect themselves? - **Timeline guidance**: When should people expect more information, and what should they do in the meantime? - **Resource provision**: Links to tools, guides, or services that can help with response and recovery. ## **Structure and Format Matter** The way information is organized and presented directly impacts its usefulness and effectiveness. A helpful disclosure isn't just about vomiting out internal information – it's about making that information accessible and understandable. #### **Lead with Impact and Actions** Traditional disclosures often bury the most important information in legal language or lengthy chronological narratives. Helpful disclosures front-load what people need to know: - **Impact summary first**: What data was affected, and who needs to act? - **Immediate actions second**: What should people do right now? - **Technical details third**: How did the incident happen, and what's being done about it? #### **Use Scannable Formatting** Well-structured information presented in a scannable format allows people to easily find what they need without having to wade through irrelevant details or search online for other sources that may or may not be accurate. This not only saves time but also reduces stress, making the disclosure more effective. Helpful formatting also includes: - **Clear section headers** that let people jump to relevant information, for example: - **Executive summary** for quick understanding - **Detailed findings** for those who need specifics - **Technical appendix** for security professionals - **FAQ** to address common concerns - **Bulleted action items** rather than buried recommendations in paragraphs (see what I did there?) - **Timeline tables** that show what happened when and what comes next - **Risk level indicators** that help people prioritize their response For open source projects, GitHub's Security Advisory feature demonstrates this approach well. Their standardized template includes severity ratings upfront, clearly lists affected products, provides specific remediation steps, outlines disclosure timelines, and acknowledges the contributions of researchers where appropriate. This format helps developers quickly assess the impact and take action, exactly what a helpful resource should do. #### **Separate but Overlapping Audiences** Different stakeholders require different types of information, and various organizations serve different sets of stakeholders. The industry, market, and geographies where you operate all impact how your stakeholders best receive and consume information. A single wall of text or generic media statement serves no one well. Consider organizing disclosures with distinct, but consistent details for: - **Individual users**: Personal protective actions and account security steps - **Business customers**: Enterprise-level implications and B2B considerations - **Technical community**: Indicators of compromise and technical prevention measures If the incident is high-profile enough to generate media interest, don’t be afraid to use these assets in your engagements with journalists. They’re extremely valuable in driving consistent and accurate reporting based on your investigation (rather than an ambulance chaser’s), while demonstrating that you’re providing everyone with the information they need. ## **Making the Shift** Moving from transparency to honest helpfulness requires changing how we think about our relationship with those affected by security incidents. Instead of treating disclosure as damage control, we should view it as an opportunity to provide a valuable service. What does this look like in practice? 1. **Preparing helpful frameworks in advance**: Don't wait until an incident occurs to figure out how to communicate effectively. Call us, this is what we do! 2. **Investing in investigation capabilities**: You can't be helpful if you don't understand what happened. 3. **Prioritizing usefulness over perfection**: Sometimes it’s better to share actionable preliminary information than to wait for a complete picture, especially when people are at risk. 4. **Measuring success by outcomes**: Did your disclosure help people protect themselves, strengthen trust in your organization, or just check a legal box? Security incidents will continue. When they do, we have a choice: we can be transparent in name only, or we can be genuinely helpful and become a trusted source of information and support. The organizations that choose the latter don’t just meet their obligations – they'll contribute to a more secure ecosystem for everyone while building credibility and resilience for their brand. ### Why Effective Security Communication Starts with Strategy, Not Translations URL: https://www.discernibleinc.com/why-effective-security-communication-starts-with-strategy-not-translations/ Last updated: 2026-07-11T22:47:33.000Z Security professionals often approach business communication like translators working with a technical dictionary. They take terms like "zero-day vulnerability" and convert them to "unknown security weakness," or transform "multi-factor authentication" into "extra login steps." While this translation approach may seem productive, it overlooks the fundamental purpose of communication entirely. The problem isn't that executives don't know what endpoint detection is. The problem is that they don't understand why they should care about your specific EDR recommendation right now, given everything else competing for their attention and budget. ## **Start with the End in Mind** Effective security communication begins with a simple but often overlooked question: > **What exactly are you trying to accomplish?** This mirrors Harold Lasswell's classic communication model, which asks "to what effect?" – a question we explored in depth in our previous post on [measuring communication effectiveness](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/). Are you seeking budget approval for a new security tool? Trying to change employee behavior around authentication practices? Attempting to get executive buy-in for an AI security program? Each objective requires a fundamentally different communication approach, regardless of the technical complexity involved. Too many security professionals start with the information they want to share rather than the outcome they want to achieve. This backward approach leads to presentations packed with technical details that impress other security professionals but fail to make a meaningful impact on business leaders. ## **Know Your Audience's Reality** Once you're clear on your objective, the next critical step is understanding your audience – not just their role, but their current challenges, priorities, and constraints. The CFO, who is worried about quarterly earnings, isn't primarily concerned with your vulnerability scan results. They're concerned with financial risk, operational efficiency, and competitive advantage. The operations manager dealing with system uptime and performance isn't focused on arbitrary security metrics. They're focused on reliability and user experience. Your audience falls into two categories: 1) those who can help you achieve your objective, and 2) those who might stand in your way. Both groups deserve your attention, but they require different approaches. ## **What Do They Actually Need to Hear?** Here's where a lot of security communication goes wrong. Instead of asking "How do I explain this technical concept?" the right question is "What does this person need to believe or understand to take the action I'm requesting?" Consider these scenarios: **Wrong approach:** > "We need to implement privileged access management (PAM) solutions to control administrative credentials and reduce our attack surface." **Right approach:** > "Three of our competitors have been breached through compromised admin accounts in the past year. This solution will prevent unauthorized access to our critical systems and customer data, protecting us from the estimated $4.8 million cost for this kind of breach." The technical solution (PAM) is the same, but the second approach directly connects to what executives already care about, such as industry-relevant risk context, business impact, and financial justification. ## **Persuasion > Translation** Effective security communication is persuasion, not translation. Persuasion requires understanding what motivates your audience and crafting messages that align with those motivations. The operations manager cares about system uptime and efficiency. Frame your security initiatives around operational stability and reduced downtime from incidents. The marketing director cares about brand reputation and customer trust. Position your security program as an investment in protecting customer relationships and enhancing your competitive advantage. This doesn't mean manipulating or misleading anyone. It means presenting accurate information in the context that matters most to your audience. ## **Ladder of Inference: A Framework for Strategic Security Communication** To move beyond translation and into true influence, we use a framework at Discernible called the [Ladder of Inference](https://gould.usc.edu/news/understanding-the-ladder-of-inference-navigating-cognitive-pitfalls/?ref=discernibleinc.com). This seven-step process helps you build communication strategies that change minds and drive action. The framework uses a ladder metaphor because influence requires moving people step by step from where they are to where you need them to be. You can't skip rungs – trying to jump from facts directly to action rarely works. You have to address each level of resistance systematically. The ladder also emphasizes that you start at the top (what you want to accomplish) and work downward to understand what's preventing that action. This is the opposite of most communication approaches used by technical teams, which typically begin with facts and hope they will eventually lead to action. ### **Actions: Start at the Top** *What outcome are you seeking? What do you need your audience to do?* Be ruthlessly specific here. "I need the executive team to approve $150,000 for identity management software by the end of Q2" is infinitely more useful than "I want them to understand our authentication challenges." ### **Beliefs: Their Current Position** *What does your audience currently think about this outcome?* Perhaps they believe your current security measures are sufficient, or that security spending is already excessive. Maybe they think your team cries wolf too often. Understanding their starting position is crucial for plotting the path forward. ### **Conclusions: Surface the Resistance** *What judgments or opinions could prevent this outcome?* The CFO might conclude that security tools never deliver the promised return on investment (ROI). The CEO might believe that compliance requirements are just bureaucratic overhead. These conclusions are your real obstacles. ### **Assumptions: Find the Faulty Foundation** *What assumptions are driving those opinions? What are they missing?* Often, resistance stems from outdated information or incomplete understanding. The executive team might assume that "good enough" security from five years ago still applies, or that cyber insurance eliminates the need for prevention. ### **Interpreted Reality: Connect to Their World** *What would this outcome mean to them, emotionally, professionally, etc? How will you demonstrate empathy for this?* A data breach doesn't just mean "security incident" to a CEO – it means congressional hearings, customer churn, and career-threatening headlines. Acknowledge these real concerns before presenting your solution. ### **Selected Reality: Expand Their Experience** *What previous experience shapes their perspective? How can you broaden their viewpoint?* If their only experience with security involved oversold solutions and underwhelming results, they'll be skeptical of your proposal. Share case studies from similar organizations or arrange conversations with peers who have successfully implemented similar solutions. ### **Reality & Facts: Fill the Information Gaps** *What information and resources are available to them? What's missing?* Only at this bottom rung do you focus on data, technical specifications, and factual evidence. However, this information is now targeted and contextual, designed to support the journey up the ladder rather than overwhelm with technical details. ## **Climbing the Ladder IRL** Let's see how this works with a real scenario. Here’s an example of what it looked like for a security team trying to implement mandatory multi-factor authentication across their organization. - **Actions:** Get all department heads to mandate MFA for their teams within 60 days - **Beliefs:** "MFA will slow down our employees and hurt productivity." - **Conclusions:** "Security measures always create more problems than they solve." - **Assumptions:** "Our current password policy is sufficient," and "We're not a target because we're not a tech company." - **Interpreted Reality:** MFA means daily user complaints, IT support calls, and being blamed for productivity drops during a busy season. - **Selected Reality:** Their experience with previous security rollouts involved weeks of user frustration, help desk chaos, and ultimately having to scale back requirements. - **Reality & Facts:** Modern MFA solutions like push notifications take 3 seconds, reduce support tickets by eliminating password resets, and recent attacks in your industry specifically targeted companies with single-factor authentication By mapping this out, the team was able to develop a communication strategy that addressed each level to acknowledge the concerns about productivity and support burden, share examples of smooth MFA rollouts at similar organizations, demonstrate how MFA reduces IT workload over time, and provide evidence that their industry is actively being targeted through credential-based attacks. ## **The Real Translation Challenge** The hardest translation in security communication isn't from technical jargon to business language. It's translating your priorities into outcomes that matter to someone else. It's connecting the security risks you feel in your bones to the business risks that keep your executives awake at night. When you master this translation, you'll find that your technical expertise becomes far more impactful. Business leaders will seek your input rather than avoid your meetings. Your recommendations will move from the "someday maybe" pile to an approved (and resourced!) initiative. The goal was never to make everyone understand security the way we do. The goal is to help them understand why security matters for what they're trying to accomplish. That's a much more achievable (and valuable) objective. ### Four Ways Exceptional Incident Response Creates Competitive Advantage URL: https://www.discernibleinc.com/four-ways-exceptional-incident-response-creates-competitive-advantage/ Last updated: 2026-07-11T22:49:29.000Z When most organizations think about incident response, they focus on damage control. How do we minimize impact? How do we satisfy compliance requirements? These are important and necessary questions, but when they’re treated as the ceiling, rather than the floor, organizations often miss a crucial opportunity — exceptional incident response can strengthen your competitive position. In our previous post on [transforming incident response through positive framing](https://discernibleinc.com/blog/what-could-go-right?ref=discernibleinc.com), we challenged security professionals to shift their perspective from "what could go wrong?" to "what could go right?" and imagine a best-case scenario that can be reverse-engineered. This shift in perspective unlocks powerful opportunities to demonstrate differentiated competence. From our Discernible Drill last week, designed specifically to practice this positive framing approach, we identified four key insights about how well-prepared organizations can transform security incidents from guaranteed liabilities into strategic advantages. These aren't theoretical concepts; they're patterns we see repeatedly when clients approach incident response with the right mindset and preparation. ## Excellence Under Pressure Reveals True Capabilities The most powerful external communications during incidents don't just explain what happened; they demonstrate organizational competence under pressure. For example, when a company recovers from ransomware in 48 hours while their industry average hovers around 2-3 weeks, that rapid response showcases months of preparation paying dividends by providing concrete evidence of capabilities that no marketing campaign could match. Real-world validation becomes far more persuasive than theoretical promises. Prospects can dismiss marketing claims about "industry-leading security" or "24/7 operations," but they can't argue with documented recovery metrics during an actual incident. When your incident response demonstrates operational excellence, it becomes the ultimate proof point for every future sales conversation. This is why preparation matters so much. The organizations that can respond exceptionally well during incidents aren't lucky—they're prepared. They've invested in the right systems, processes, and relationships. When pressure reveals their true capabilities, those capabilities become undeniable competitive differentiators. ## Proactive Transparency Creates Competitive Moats Organizations that communicate proactively about their incident response often find that transparency becomes a competitive advantage. When companies openly discuss their response metrics, recovery timelines, and lessons learned, they demonstrate operational maturity that surpasses their competitors. This transparency works on multiple levels. First, it fosters trust with stakeholders who appreciate honest and detailed communication during challenging situations. Second, it raises the bar for industry standards—competitors now have to match not just your technical capabilities, but your communication excellence. Third, it positions your organization as a thought leader willing to share insights that benefit the broader industry. The key is being proactive rather than reactive. Organizations that get ahead of the narrative by sharing their response approach, metrics, and outcomes control how the incident is perceived. Those who remain silent allow others to fill the information vacuum, often with speculation that's far worse than reality. ## Incident-Tested Partnerships Are Stronger Here's a counterintuitive truth: clients who experience a well-managed incident response often develop deeper trust in their service providers than those who never face challenges together. When a healthcare client considers contract expansion after witnessing their provider's exceptional incident response, it demonstrates how excellence during incidents can strengthen relationships in ways that routine service delivery cannot achieve. This happens because incidents reveal character and competence under pressure. Routine operations may run smoothly for months or years, but stakeholders never truly know what to expect when things go wrong. A well-managed incident response demonstrates that the organization can effectively handle adversity while maintaining high service quality and excellent communication. The strongest partnerships are forged through shared challenges successfully navigated together. When stakeholders see that their provider not only promises excellence but also delivers it during the most stressful circumstances, trust deepens in ways that smooth operations alone cannot achieve. ## Success Stories Need Systematic Amplification The positive outcomes from incident response don't automatically translate into lasting business value without systematic communication and amplification. Organizations must be intentional about capturing success metrics, documenting lessons learned, and creating repeatable narratives that can be leveraged long after the incident is resolved. This means thinking beyond immediate incident communications to develop comprehensive documentation that can be used in sales materials, case studies, thought leadership content, and competitive differentiation messaging. The incident response becomes a strategic asset that continues delivering value months or years later. Even organizations that excel at incident response often fail to capitalize on it strategically, especially in building goodwill in advance of future incidents. # Building Your Foundation for Success These insights reveal a crucial truth: exceptional incident response that creates a competitive advantage doesn't happen by accident. It requires systematic preparation across technical capabilities, organizational processes, stakeholder relationships, and communication frameworks. The organizations that can transform incidents into advantages have built the foundation that makes excellence possible. They've invested in the right technology, trained their teams properly, established clear communication protocols, and created decision-making procedures that enable exceptional performance under pressure. Most importantly, they've recognized that incident response isn’t limited to technical recovery — it's also about demonstrating organizational character and expertise in ways that strengthen their competitive position and stakeholder relationships. --- Want to practice these skills with us? Our weekly scenario-based drills help security and privacy professionals develop the communication skills and strategic thinking necessary to transform incidents into competitive advantages. Subscribers get access to our complete library of scenario briefings, postmortem documentation, and executive insights that help teams prepare for excellence under pressure. Each drill includes realistic scenarios, progressive challenges, and practical frameworks you can immediately apply in your organization. Subscribe at [DiscernibleInc.com/experience](https://discernibleinc.com/experience?ref=discernibleinc.com). ### A Communicator's Guide to Software Harm Prevention URL: https://www.discernibleinc.com/a-communicators-guide-to-software-harm-prevention/ Last updated: 2026-07-11T22:50:37.000Z *Building on our privacy outrage prevention framework to address the full landscape of software harms* Communications professionals have long focused on crisis management – responding to problems after they occur. But as software becomes increasingly central to how organizations serve customers and communities, our role must evolve from reactive damage control to proactive harm prevention. The [Internet Safety Lab's](https://internetsafetylabs.org/?ref=discernibleinc.com) "Landscape of Software Harms" framework (shown below) highlights why this shift is so important. Software-related risks extend far beyond traditional concerns into areas where communication professionals' skills in stakeholder perception, narrative framing, and risk assessment can prevent real harm before it reaches the market. ![](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/676301e2-9ca0-4f3c-a839-8b829d5f9afa/LandscapeofSoftwareHarms_InternetSafetyLabs.jpeg) **Copyright Internet Safety Labs. Used with permission.* # **From Privacy Outrage to Software Harm Prevention** In our previous post on [preventing privacy outrage](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/), I outlined how communications professionals can use proactive questioning to prevent privacy-related incidents. That framework focused primarily on what the Internet Safety Lab categorizes as "Programmatic Harms" – unintended consequences that occur through normal use of technology. But the ISL framework reveals two additional categories where communications expertise becomes crucial: - **Sustained Use Harms** occur when prolonged engagement with technology creates negative outcomes, such as social media addiction, algorithmic bias reinforcement, or data-driven discrimination. These harms often involve complex stakeholder narratives about corporate responsibility and user agency. - **Malicious Use Harms** represent the weaponization of technology — from deepfakes to cyberbullying to disinformation campaigns. Here, communications professionals must help organizations think through not just how their technology might be misused, but how they'll explain their mitigation efforts to stakeholders. # **The Comms Professional's Role in Harm Prevention** Our core competencies as communication experts — understanding audience perception, crafting compelling narratives, and managing stakeholder relationships — are precisely what's needed to address software harms proactively. ## **Stakeholder Impact Assessment** While engineers focus on technical functionality and lawyers focus on compliance, communications professionals naturally think about how different stakeholder groups will perceive and be affected by technology decisions. This perspective is essential for identifying potential harms before they manifest. ## **Narrative Vulnerability Analysis** We excel at understanding how stories spread and evolve across different audiences. This skill helps predict which aspects of a technology might become focal points for criticism, regulation, or misuse. ## **Risk Communication and Education** When harms can't be eliminated, communications professionals can help organizations explain trade-offs transparently and educate users about risks and mitigation strategies. # **An Expanded Framework for Software Harm Prevention** Building on the privacy outrage prevention checklist, here are key questions communications professionals should ask during product development: ### **Understanding the Technology** - What specific problems does this technology solve, and for whom? - What are the potential unintended consequences of normal use? (Programmatic Harms) - How might prolonged or repeated use affect users over time? (Sustained Use Harms) - How could bad actors weaponize this technology? (Malicious Use Harms) ### **Stakeholder Impact Analysis** - Which stakeholder groups will be most affected by this technology? - How will different communities experience the benefits and risks differently? - What power dynamics does this technology create or reinforce? - Who has agency over how this technology affects them, and who doesn't? ### **Narrative Risk Assessment** - What stories might critics, journalists, or activists tell about this technology? - How will we explain our design choices to skeptical audiences? - What analogies or comparisons will people make to understand this technology? - If this technology causes harm, how will we explain what went wrong and what we're doing about it? ### **Mitigation and Transparency** - What safeguards have we built in to prevent or minimize potential harms? - How will users understand and control their exposure to risks? - What research or expertise informed our harm assessment? - How will we monitor for emerging harms and adjust our approach accordingly? ### **Organizational Readiness** - Do we have processes for responding quickly when harms are identified? - Have we prepared our customer service, legal, and executive teams for difficult questions? - What public commitments have we made that this technology must honor? - How does this technology align with our stated values and mission? # **The Business Case for Proactive Harm Prevention** Organizations often resist investing in harm prevention because the benefits are invisible — problems that don't happen, crises that don't occur, trust that doesn't erode. Communications professionals can help make this case by: - **Quantifying reputation risk**: Calculate the potential cost of regulatory attention, media scrutiny, user exodus, and talent retention challenges that result from software harms. Think about how many engineering hours are spent responding to these issues — that’s time not spent on priority projects. - **Highlighting competitive advantage**: Organizations that proactively address software harms can differentiate themselves and build stronger stakeholder relationships. - **Connecting to business metrics**: Show how harm prevention supports customer retention, employee satisfaction, regulatory compliance, and long-term sustainability — and again, consider where the business wants employee time spent compared to where their focus will be pulled if something goes wrong. Nobody wants their expensive engineers spending weeks in interviews with legal teams responding to an FTC complaint. ## **The Path Forward** The landscape of software harms will only become more complex as AI, quantum computing, and other emerging technologies evolve. Communications professionals who develop expertise in proactive harm prevention will become invaluable partners in building technology that truly serves society. We already know how to spot narrative vulnerabilities, understand stakeholder concerns, and communicate complex trade-offs. Now we need to apply these skills earlier in the development process, before harms reach the market. Organizations that embrace this approach build stronger, more sustainable relationships with the communities they serve. And in an era where trust in technology companies continues to decline, that may be the most valuable competitive advantage of all. --- *The Internet Safety Lab's "Landscape of Software Harms" framework provides a crucial foundation for understanding how technology can impact society. Learn more about their work at*[ *Internet Safety Labs*](https://www.internetsafetylabs.org/?ref=discernibleinc.com)*.* ### What Could Go Right? URL: https://www.discernibleinc.com/what-could-go-right/ Last updated: 2026-07-11T22:51:57.000Z *Transforming Incident Response Through Positive Framing* As security and privacy professionals, we’ve long operated in the shadow of Murphy's Law, constantly asking "what could go wrong?" while preparing for incidents. This defensive mindset, though necessary, often positions us as the harbingers of doom within our organizations. But what if we flipped the script? > **What if we started asking "what could go right?"** This shift in perspective isn't about reckless positivity or ignoring real threats. It's about reframing our incident readiness and response communications to highlight opportunities, demonstrate value, and build the social capital we need to be effective long-term. ## **The Power of Positive Incident Planning** Well-executed incident response doesn't just minimize impact. It can strengthen customer trust, demonstrate organizational resilience, and showcase the security team's strategic value. Companies that handle incidents with transparency and swift action earn the opportunity to grow stronger customer relationships than before the incident. Customers who might have previously taken the company's integrity for granted now have concrete evidence of how the organization behaves when the stakes are high. The transparent and masterful handling of a difficult situation often builds more trust than years of smooth operations, because it proves the company's values aren't just marketing copy – they guide decision-making even when it's costly or uncomfortable. By planning for these positive outcomes, we prepare our teams to thrive through incidents, not merely survive them. This isn't the first time we've explored how strategic framing transforms security communications. In our [previous post about vulnerability communication with developers](https://www.discernibleinc.com/mailbag-whats-the-best-approach-for-sharing-vulnerability-findings-with-developers-to-avoid-inciting-defensiveness/), we demonstrated how positioning findings as opportunities rather than failures dramatically improves developer engagement and remediation outcomes. The same communication theory principles that work for vulnerability management apply powerfully to incident response. ## **Creating New Possibilities & Preserving Choice** Perhaps most importantly, asking "what could go right?" fundamentally expands your options when incidents occur. Traditional incident response planning focuses on damage control and crisis management, often defining a “good” response as one that “went as well as could be expected.” Talk about forfeiting before the game even starts! When teams effectively prepare for positive outcomes, they build the capabilities and stakeholder relationships that give them more flexibility during real incidents. This preservation of choice is one of the most valuable reasons to invest in incident response capabilities in the first place. We're not just buying insurance against disaster — we're purchasing the freedom to choose how we respond when challenges arise. A well-prepared team can pivot quickly between different communication and disclosure strategies that aren’t even available to less-prepared organizations. When you've reverse-engineered success scenarios and built the capabilities to achieve them, incidents become decision points rather than predetermined disasters. Without this preparation, it's nearly impossible to meet or exceed stakeholder expectations during the chaos of an actual incident. Teams that haven't planned for positive outcomes find themselves reactive and defensive, scrambling to manage immediate damage rather than pursuing strategic opportunities. However, new possibilities emerge when you've properly prepared for positive outcomes. You can proactively engage with media to shape the narrative rather than simply responding to criticism. You can turn regulatory interactions into demonstrations of your commitment to excellence rather than grudging compliance exercises. You can use the incident to showcase your organizational values and leadership to customers, partners, and industry peers. Most importantly, you can transform what could have been a reputation-damaging event into proof of your organization's resilience and trustworthiness. ## **Starting with the End** I regularly work with clients using a powerful exercise: imagine it's six months after a major incident, and you're reflecting on how well your organization handled it. What would you want to be true? What would you like to say about your response? Common aspirational statements include: > "Our customers praised our transparency and quick action." > > "We detected and contained the incident faster than industry averages." > > "Our communication was so clear that it became a case study." > > "The incident actually strengthened our relationship with regulators." After identifying these desired outcomes, we reverse-engineer the incident response plan to make the aspirations achievable. If you want to be known for transparency, you build proactive communication protocols, tools, and platforms. If you want faster detection and response, you invest in monitoring capabilities and frameworks for rapid decision-making. If you want regulatory praise, you design compliance-forward response procedures and direct relationships. None of these things will happen accidentally. ## **Practical Implementation** Start by conducting the aspirational reflection exercise with your incident response team. Ask: "Six months post-incident, what do we want stakeholders to say about how we handled it?" Document these desired outcomes, then reverse-engineer your response plans to make them a reality. Rewrite your incident communication plans to include potential positive outcomes and opportunities. Train response teams to identify moments during incidents where proactive communication can strengthen stakeholder relationships. Develop metrics that capture what you enabled and improved, not just what you prevented. Create "success scenarios" alongside your traditional incident scenarios. If you're tabletop testing a data breach, don't just practice damage control or legal disclosure requirements – practice the communications and actions that would earn stakeholder praise. This preparation ensures your team is ready to seize positive opportunities when they arise during real incidents. ## **The Strategic Advantage** Security and privacy professionals who master this positive framing fundamentally change their role within their organizations by becoming strategic partners who can help navigate challenges while identifying opportunities for growth and improvement. Asking "what could go right?" transforms incident readiness from a defensive necessity into a strategic capability that drives organizational resilience and competitive advantage. ### Organizations Lack Sufficient Decision Frameworks to Expand Incident Response Options URL: https://www.discernibleinc.com/organizations-lack-sufficient-decision-frameworks-to-expand-incident-response-options/ Last updated: 2026-07-11T22:54:53.000Z *After five years of Discernible, this is my #1 concern.* As we mark Discernible’s fifth anniversary, I find myself reflecting on the most profound insight from our journey: > Your choices today directly determine what options will be available to you during a security incident tomorrow. ## The Decision Trail That Leads to Crisis (or Success) When an organization faces a security incident, what appears as a sudden situation is usually the culmination of hundreds of previous decisions. The disturbing pattern I've witnessed over these five years is how few organizations recognize this connection until it's too late. The reality is stark. The series of decisions and context leading into an incident — the entire "how did we get here?" story — directly impacts and often severely limits the choices available for managing our response. When you've consistently made expedient rather than secure decisions, failed to document critical systems, or neglected communication channels with stakeholders, those past decisions drastically narrow your response options. Most concerning is how many organizations expect they will somehow make better decisions under the intense scrutiny of an incident, even when they struggle with cross-functional relationships during normal operations. Neither research nor experience supports this expectation. ## The Communication Gap: Why Security Teams Struggle to Influence Outcomes This disconnect stems from a critical communication failure — security and privacy teams often possess the technical knowledge to identify risks and recommend appropriate controls. Still, many lack the persuasive communication skills needed to influence organizational decision-making. This is precisely why our business focuses so intensely on helping security and privacy professionals become more [effective communicators and internal influencers](https://www.discernibleinc.com/turning-incident-response-communications-into-a-sustainable-security-communications-program/). The most technically sound recommendation means nothing if it fails to persuade decision-makers to act. The security teams that successfully shape organizational decisions — and by extension, create more favorable options during incidents — invest in strategic relationship building and accumulating political capital on an ongoing basis. They don't just deliver technical assessments; they [cultivate trust across departments](https://www.discernibleinc.com/this-years-strategic-relationships-do-you-have-what-you-need/), build alliances with business leaders, establish credibility through consistent follow-through, and carefully choose which battles to fight. When incidents occur, these relationship investments become invaluable currency. ## Senior Leaders: The Critical Link to Executive Decision-Making This communication challenge escalates for senior security and privacy leaders when engaging with the C-suite and board. These interactions determine whether security considerations integrate into the organization's highest-level decisions or remain perpetually siloed. The most effective security leaders we've worked with excel at three specific communication practices: 1. **Translating technical risk into a business context** that connects directly to metrics and objectives executives already care about. 2. **Providing decision frameworks** rather than binary choices, helping executives understand the full spectrum of options and associated tradeoffs. 3. **Building narrative continuity** by consistently connecting current recommendations to past decisions and future scenarios, creating a coherent story arc that executives can follow over time. These practices help establish security as a business enabler rather than a cost center or obstacle, fundamentally changing how executives factor current and future security into their decisions. ## Frequent Practice Builds Muscle Memory Our core belief continues to be that effective security communications must be proactive, not reactive. More than a philosophy, we’ve observed this practical reality across numerous organizations. Those who wait until an incident to develop their communication strategy invariably struggle, while those who [proactively build communication capabilities](https://www.discernibleinc.com/turning-incident-response-communications-into-a-sustainable-security-communications-program/) navigate incidents with significantly more success. This experience drives our subscription service [Discernible Experience](https://discernibleinc.com/experience?ref=discernibleinc.com), built around the understanding that frequent practice makes security communications work best, rather than only being activated during a crisis. Through frequent exposure to different types of incident communication tasks – from technical team briefings to customer education campaigns – security professionals develop the communication muscle memory needed to perform under pressure. I often tell clients that incident communications is not like a caterpillar waiting to emerge dramatically like a butterfly when trouble strikes. It's more like a dung beetle that constantly rolls, tunnels, and lives in dung to provide plant roots with nutrients and help spread seeds by burying them deep in the soil, protecting them from animals and increasing their chances of germination. Not the most glamorous metaphor, but profoundly accurate. The daily, unglamorous work of building communication muscle memory creates resilience when incidents occur. ## Values-Based Communication is a Strategic Advantage As we look to the next five years, our commitment is to helping organizations recognize that consistent, values-based communication about security is not just a risk management tactic – it's a strategic advantage. When security teams can effectively communicate and influence decisions before incidents occur, they create an environment where: - Security considerations become naturally integrated into business decisions. - Technical debt is recognized as a future limitation on incident response. - Investments in security capabilities are understood as investments in business resilience. - Response options during incidents are expanded rather than constrained. The organizations that weather security incidents most successfully are those whose response feels authentic because it's built on consistent, values-based decision-making before, during, and after incidents occur. They don’t demonstrate a stark pivot to a crisis persona. Instead, we see a continuation of the same principled approach to how they always make decisions, operating under more challenging circumstances. Organizations that upgrade incident response communications into proactive programs can help avoid incidents or significantly improve their impact on customer trust and brand reputation. ## A Final Thought Some security incidents are truly unavoidable, but many are not. Our experience has shown that the creation, scope, and impact of nearly every incident are directly shaped by the quality of decisions and communications that preceded it. Define now how you want to be perceived when something goes wrong, including the values, ethics, and characterizations you want associated with your brand. Then, deliberately build those things into how you communicate about security and the decisions you make every day. This is the wisdom I wish every company understood before they face their first security incident: **Your response capabilities are being built or diminished with every security conversation you have today.** --- *As we celebrate this milestone, I'm grateful for the trust our clients have placed in us and for the lessons they've helped us learn. Here's to building organizations where security communication excellence is a daily practice!* ### 📬 Mailbag: What's the best approach for sharing vulnerability findings with developers to avoid inciting defensiveness? URL: https://www.discernibleinc.com/mailbag-whats-the-best-approach-for-sharing-vulnerability-findings-with-developers-to-avoid-inciting-defensiveness/ Last updated: 2026-07-23T00:41:23.000Z *Mailbag questions are submitted by our readers. Submit your own question for our team at discernibleinc.com/contact.* Effectively communicating about security vulnerabilities with developers requires more than technical accuracy. When done poorly, security teams can inadvertently trigger defensiveness, create organizational silos, or delay critical fixes. But when done well, these interactions can build trust, foster collaboration, and strengthen relationships (read why this matters in our previous post about building influence [here](https://www.discernibleinc.com/boost-your-teams-influence-with-corporate-anthropology/)). ## The Communication Challenge Security and product engineering teams often operate with different mindsets, priorities, and even languages (and that’s OK!). According to [Schein's Organizational Culture Theory](https://mitsloan.mit.edu/ideas-made-to-matter/5-enduring-management-ideas-mit-sloans-edgar-schein?ref=discernibleinc.com#:~:text=Schein%20understood%20that%20organization%20change,that%20makes%20sense%20to%20people.%E2%80%9D&text=Your%20browser%20can't%20play%20this%20video.), distinct subcultures within the organization typically have their own assumptions and values. Most security teams prioritize risk mitigation, while product developers focus on feature delivery and user experience (to varying degrees of success all around). This fundamental difference creates what [Watzlawick's Interactional View](https://www.afirstlook.com/docs/interactionalview.pdf?ref=discernibleinc.com) would identify as a content/relationship paradox, meaning the "content" (vulnerability findings) becomes inseparable from the relationship between the communicating parties, making the exchange inherently emotionally charged. The consequences of emotionally charged interactions extend far beyond the immediate conversation. Emotional undercurrents can significantly impact organizational effectiveness and team dynamics. The theories and communication strategies outlined in this blog post aren’t specific to security teams, but they appear to be things most security teams aren’t using. Why do we care about emotionally charged interactions with cross-functional partners? Because they can cause the following: - **Delayed remediation timelines** – including questioning the validity of findings, deprioritizing security tickets, seeking excessive confirmation before acting, or requesting unnecessary documentation. - **Information filtering & distortion** – when we receive information that conflicts with our self-image (such as "your code has security flaws"), we often unconsciously filter or distort that information to protect ourselves. - **Trust erosion and communication breakdown** – most professional relationships operate on reciprocity. When security communications feel like attacks, the natural response is to pull back from future exchanges. - **Knowledge transfer failure** – organizations function best when team members can efficiently share knowledge and expertise. Emotionally charged exchanges disrupt this process, preventing the cross-pollination of information and experience across teams. - **Organizational politics and reputation damage** – emotionally charged conversations rarely remain private. They become discussion topics with other people, shaping how entire teams perceive one another. Security teams that consistently trigger defensive responses with emotionally charged conversations eventually realize that their input is sought later in the development cycle (when changes are costlier & messier), they're viewed as blockers rather than enablers. If their recommendations are implemented, they are usually done superficially rather than fully embraced. ## 3 Communication Theories That Inform Better Practices Emotionally charged dynamics between teams (including security & developers) present a significant challenge, but communication research offers hope and direction. Understanding the psychological impact of vulnerability reporting is only the first step. The next step is translating it into practical communication strategies, where real transformation occurs. Drawing on established communication theories, security professionals can develop approaches that acknowledge emotional realities while effectively conveying critical security information. These theories provide more than conceptual frameworks but actionable suggestions for how security teams can reframe their messaging and structure interactions to build bridges rather than silos. The following communication theories offer particular value: ## Face Theory and Psychological Safety Brown and Levinson's [Politeness Theory](https://www.ebsco.com/research-starters/social-sciences-and-humanities/politeness-theory?ref=discernibleinc.com#overview) (sometimes called the “Face Theory”) provides a useful framework here. The “face” in this theory refers to someone’s self-image and social identity, which can be threatened during social interactions. When developers receive vulnerability reports, both their "positive face" (AKA the desire to be appreciated and liked by others) and "negative face" (AKA the desire for autonomy and freedom from imposition) can feel threatened. Security professionals who acknowledge the skill and complexity of the developer's work before presenting findings demonstrate respect for both the positive and negative face. This is important because, as Amy Edmondson's Psychological Safety [research](https://web.mit.edu/curhan/www/docs/Articles/15341%5FReadings/Group%5FPerformance/Edmondson%20Psychological%20safety.pdf?ref=discernibleinc.com) suggests, team members need to feel safe taking interpersonal risks for high-performance collaboration. Psychological safety increases when vulnerability findings are communicated as shared challenges rather than individual failures. Understanding how our approach or language can threaten someone's self-image and social identity helps us ensure the environment feels safe enough for them to engage in productive discussions. A particularly challenging situation happened with a client’s mobile app team during the final weeks leading up to a major release. The security team had discovered several critical API vulnerabilities and were hesitant on how to address this with product managers because historically, bringing findings to this developer team had been met with tension and pushback. Instead of leading with the vulnerabilities as they typically would, we completely changed the security team’s approach. We scheduled a quick informal chat with their tech lead before the formal meeting and asked about their current challenges. They opened up about the immense pressure they were under – marketing had already announced the release date, they were struggling with unexpected iOS compatibility issues, and two team members were on leave. When we gathered for the vulnerability review the next day, our client (a senior security engineer) started by acknowledging the situation. "Before we dive in, I want to recognize you're dealing with significant constraints right now – the announced release date, the iOS issues you mentioned yesterday, and being short-staffed. I know adding security concerns doesn't make that easier." The air in the room immediately changed. Body language shifted from crossed arms and tense postures to more open engagement. Rather than immediately challenging the validity of security’s findings, they asked clarifying questions about the vulnerabilities. One developer even volunteered, "This actually connects to something we've been worried about in the payment flow." What had previously been confrontational meetings transformed into a collaborative session where we jointly categorized which issues needed fixing before release and which could be addressed in the first update. By the end of the meeting, our client’s team was invited to the mobile team’s daily standups during the remediation period, which had never happened before. The vulnerability fixes were implemented more thoroughly than we had expected. For the first time, the development team proactively reached out when they spotted a potential security concern in another area of code. This single shift in approach – taking the time to acknowledge their reality before presenting security’s findings – protected everyone’s positive and negative face, creating psychological safety conducive to honest and productive discussions. ## Framing Theory and Loss Aversion [Prospect Theory](https://www.sciencedirect.com/topics/neuroscience/prospect-theory?ref=discernibleinc.com#:~:text=Prospect%20Theory%20is%20a%20theory,well%20as%20their%20associated%20probabilities.) tells us that people respond differently to information depending on whether it's framed as a potential gain or loss. Security findings traditionally emphasize potential losses (breaches, data theft, reputational damage, etc.), which trigger loss aversion and defensive responses. Reframing vulnerability communication around opportunities such as improving product quality, enhancing user trust, and developing more secure coding practices can shift this dynamic in a really powerful way. I witnessed a powerful transformation when working with an e-commerce client's development team. After completing a thorough security assessment of their payment processing system, several vulnerabilities related to data encryption and input validation were discovered, which created potential injection attack vectors. Recognizing how traditional security reporting often triggered defensiveness, we deliberately reframed our approach for the findings presentation. Rather than using alarming language about vulnerabilities and risks, we titled the meeting "Payment Experience Enhancement Opportunities" and structured the conversation around business value. We began by contextualizing security improvements within industry trends, showing where consumers increasingly consider security indicators when deciding whether to complete purchases, and that visible security measures can positively impact conversion rates. This shifted the conversation upfront from preventing theoretical losses to gaining competitive advantages. When addressing the encryption findings, we presented it as an opportunity to implement industry-leading protection that could be promoted to users as a differentiating feature. We highlighted how companies emphasizing security measures in checkout flows often see improved completion rates and customer retention. We emphasized the dual benefits of security and user experience for the input validation issues. We noted how proper validation would prevent attacks while catching common user input errors, reducing customer frustration and support requirements. We provided examples of leading payment processors successfully transforming similar security improvements into marketable trust-preserving features. As a result, the development team's response was different from their previous reactions to security findings. Instead of reacting defensively, the conversation turned to implementation options and best practices, focusing on how these improvements could be highlighted in the user experience rather than treating them as invisible technical requirements. What began as potentially uncomfortable security findings became a collaborative planning session for enhancing their product. The team implemented the security fixes promptly, and we then worked with their marketing department to highlight these security enhancements in their release communications and checkout interface. In subsequent development cycles, the team began proactively consulting our client during feature planning, approaching security as an integral part of product quality. This experience demonstrated how reframing security communication (from loss prevention to opportunity creation) can transform the entire development relationship and ultimately lead to more secure, successful products. ## Dialogic Communication [Buber's Dialogic Communication Theory](https://www.researchgate.net/publication/340093973%5FMartin%5FBuber's%5FDialogical%5FCommunication%5FLife%5Fas%5Fan%5FExistential%5FDialogue?ref=discernibleinc.com) suggests moving from treating people as mere recipients of information to recognizing them as partners in solving a shared problem. This shift from one-way transmission to true dialogue fundamentally transforms vulnerability communication. Here are a few examples of how this theory works in practice: ### Mutual Exploration vs. Declaration **Traditional Approach**: Security presents findings as definitive declarations, with developers expected to implement the recommended solutions. **Dialogic Approach**: Findings become starting points for joint exploration where both security and development expertise are valued. - Beginning with open questions: "What do you see when you look at this code pattern?" - Using genuine inquiry: "What constraints might make addressing this challenging?" - Acknowledging limitations: "I understand how the authentication system works, but I'd value your deeper perspective on it." - Co-creating solutions: "Let's think together about approaches that meet both security needs and your performance requirements." ### Embracing the "Between Space" **Traditional Approach**: Each team maintains rigid boundaries and speaks from their specialized domains without empathy for the other's world. **Dialogic Approach**: Security professionals intentionally step into a shared conceptual space where neither security nor development perspectives dominate. - Use inclusive language: "The challenge we're facing" rather than "The vulnerability you've created." - Create tangible "between spaces" like shared whiteboards or online collaboration tools, where both teams contribute. - Develop shared vocabularies that bridge security and development - Establish regular cross-functional sessions dedicated to security topics ### Reciprocal Vulnerability **Traditional Approach**: Security teams position themselves as authoritative experts, rarely acknowledging their own knowledge gaps or uncertainties. **Dialogic Approach**: Security professionals model vulnerability by: - Openly acknowledging the limitations of their technical understanding - Sharing stories of their own security mistakes or learning experiences - Asking for help understanding complex development considerations - Admitting when a security recommendation might need refinement based on development insights ### Standing With, Not Against **Traditional Approach**: Security positions themselves as inspectors or auditors standing in judgment of development work. **Dialogic Approach**: Security professionals position themselves alongside developers facing shared challenges: - When in-person, physically sitting on the same side of the table during discussions - Using "we" language when discussing both problems and solutions - Establishing shared metrics for security success - Jointly presenting security wins and challenges to leadership - Attending each other's regular team meetings to build relationship continuity When security teams shift from transmitting information to engaging in a two-way dialogue, the entire communication dynamic improves. Developers move from passive recipients who must be convinced of something to active co-creators who bring their valuable insights to security challenges. The "us versus them" mentality dissolves into a shared accountability model. ## Practical Approaches Based on These Theories ### 1\. Build Shared Mental Models Communication effectiveness increases when everyone shares an understanding of the situation. Create this shared foundation by developing a common security vocabulary that translates security concepts into developer-friendly terms, conducting collaborative threat modeling sessions where both teams map risks together, connecting vulnerabilities to business impacts rather than focusing solely on technical details, and establishing learning feedback loops that review successes and failures. When security and development operate from the same mental model, vulnerability discussions become less about education and more about collaboration toward shared goals. ### 2\. Establish Communication Rituals Consistent communication patterns reduce uncertainty and build trust between teams. Implement regular touchpoints like security office hours and recurring vulnerability reviews, standardize reporting formats with clear severity rubrics and contextual information, create cross-team rituals such as security retrospectives and joint presentations to leadership, and establish recognition systems that celebrate security achievements. These predictable communication patterns create psychological safety, allowing vulnerability discussions to become normal, expected interactions rather than anxiety-inducing confrontations. ### 3\. Focus on the Problem, Not the Person Security findings often trigger a fundamental attribution error – attributing vulnerabilities to the developer's skill rather than situational factors like deadlines or technical constraints. You can avoid this pitfall by using language that separates code from identity ("This function lacks validation" vs. "You didn't validate inputs"), acknowledging systemic factors and constraints that contributed to the issue, focusing on future prevention rather than past mistakes, and humanizing the process by sharing your own learning experiences. The goal is to avoid making vulnerability discussions feel like personal criticism by turning them into collaborative problem-solving. ### 4\. Promote Reciprocal Conversations Effective communication is never one-way. So, actively solicit feedback on your communication approach, inquire about development constraints before proposing solutions, practice deep listening to understand rather than simply respond, and acknowledge when security requirements create legitimate challenges for development teams. This demonstrates respect for developers' expertise and creates the conditions for genuine partnership, where security becomes a shared opportunity rather than an imposed requirement.​​​​​​​​​​​​​​​​ ### Boost Your Team's Influence with Corporate Anthropology URL: https://www.discernibleinc.com/boost-your-teams-influence-with-corporate-anthropology/ Last updated: 2026-07-11T22:58:01.000Z ## 3-Steps to Get You Started Despite possessing critical technical expertise or emerging regulations, many security and privacy teams still fight an uphill battle when implementing protocols, securing budget, or simply being included in strategic conversations. Corporate anthropology is a powerful yet underutilized discipline that can dramatically change how security and privacy teams operate by influencing how they’re perceived within their organizations. When leaders invest in the principles of corporate anthropology to understand and connect with cross-functional stakeholders, they elevate their teams from isolated subject matter experts into trusted business partners whose guidance shapes decisions at all levels. ## What is Corporate Anthropology? Corporate anthropology applies traditional ethnographic research methods to understand a business environment’s culture, behaviors, and social dynamics. Unlike conventional business analysis, which focuses primarily on processes and metrics, corporate anthropology examines the human elements – the relationships, unwritten rules, communication patterns, and shared values that actually drive organizational behavior. This approach provides invaluable insights for security and privacy teams that technical expertise and compliance requirements alone can’t deliver. ## Why Infosec Needs Anthropological Thinking Infosec has traditionally been viewed through a technical lens – threats, vulnerabilities, and controls – while privacy is still predominantly seen as legal or regulatory compliance. This perception creates a weak reputation for security and privacy teams as innovation blockers, directly undermining their influence. Signs that your team isn’t seen as a critical partner: - Being excluded from early product development - Privacy is relegated to compliance checks rather than experience design - Initiatives are deprioritized as cost centers - Technical expertise is dismissed as irrelevant to business goals Because everyone is busy with priorities and deadlines, the quality of your relationships determines how quickly and helpfully people respond to your everyday requests. This "trust dividend" pays returns in seemingly mundane, yet powerful ways: - Product teams seeking security and privacy input proactively - Leaders allocate budget based on trusted ROI calculations - Better implementation of controls with cross-functional collaboration - Inclusion in strategic planning - Better M&A outcomes through early security/privacy involvement ## Applying Corporate Anthropology to Security and Privacy Most influence flows through relationships, not org charts or official titles. Corporate anthropology emphasizes the importance of creating opportunities for meaningful cross-departmental collaboration, establishing trust through consistent demonstration of business value, developing empathy for the challenges faced by various stakeholders, and participating in formal and informal organizational networks. Below are three initial steps for using anthropological principles in your engagements beyond your reporting chain. ## 1\. Map the Organizational Terrain #### The foundation for strategic relationship building begins with careful observation and analysis. Anthropologists call this "participant observation” or immersing yourself in a culture to understand its unwritten rules before trying to operate inside it. Here’s what that looks like in a corporate setting: - Identify formal and informal power structures (who really makes decisions) - Recognize departmental subcultures and their unique priorities - Observe how information flows throughout the organization - Document the "tribal knowledge" that guides daily operations This mapping process isn't just analytical – it's the first step in building your relationship network by understanding who to connect with and how. Now, think about the outcomes or initiatives you want to influence and create a stakeholder map that identifies key influencers, decision-makers, and potential allies who impact those goals. Then, identify existing relationships your team members have that you can leverage. (I wrote [previously](https://www.discernibleinc.com/this-years-strategic-relationships-do-you-have-what-you-need/) about a simple way to assess the state of these relationships periodically.) Finally, and perhaps the most “bang for your buck” tactic – look for opportunities to help other departments succeed in ways unrelated to security or privacy. ## 2\. Speak the Language of Different Business Units Each departmental relationship requires its own communication approach. Each department operates with its own terminology, priorities, and success metrics. Learning to "code-switch" between these different cultures gives you more influence and positions your team as an integrated business function, not as an isolated specialty. Here are a few techniques to practice: 1. **Ask questions about departmental goals before discussing security or privacy needs.** When approaching the product team about implementing additional authentication, start by asking, "What are your current user experience metrics and release timelines?" instead of immediately explaining security requirements. This shows you value their priorities before introducing yours. Their response also tells you where the goal line is for proving business value. 1. **Learn and use the specific terminology valued by each department.** When working with marketing, discuss security in terms of "brand protection" and "customer trust" rather than "vulnerability mitigation." For Engineering, translate security principles into "technical debt reduction" and "system reliability" concepts they’ve already prioritized. 1. **Share insights that help others achieve *their* objectives.** Provide sales with security benchmarking data that shows how your company compares to competitors, which they can use as a competitive differentiator in client conversations. For finance, share quantitative risk analyses that help them more accurately forecast potential future costs. ## 3\. Care For Your Team’s Reputation Your team's perceived value and relevance are impacted by how it’s discussed within your company, particularly when you’re not in the room. Here are a few anthropological approaches that have worked for me in my career: 1. **Replace fear-based messaging with empowerment narratives.** Fear-based security messaging positions your team as the harbinger of problems rather than solutions, creating resistance and avoidance. Empowerment narratives focusing on enabling safe innovation position security as a business accelerator, giving you a seat at strategic planning tables rather than being called only during emergencies. 1. **Connect your initiatives to core organizational values and mission.** When your work is perceived as peripheral to the organization's core purpose, it's easily deprioritized during resource allocation. By explicitly connecting security and privacy work to existing organizational values, you transform from a technical specialist into a guardian of the company's mission, dramatically increasing your influence in strategic decisions. 1. **Develop communication strategies tailored to influential audiences.** Generic security messages get generic responses, but tailored communication demonstrates diverse acumen that earns respect from your peers and their leadership. When other teams see that you understand their specific business priorities and pressures, they're more likely to include you in early planning stages where you can exert maximum influence on outcomes. ## **Measuring Progress** To determine whether your approach is working, start by identifying where your team currently stands, so you can focus your efforts on advancing to the next level of organizational influence. The evolution typically progresses through these four stages: 1\. **Subject Matter Expert**: Valued for specialized knowledge but limited in organizational influence 2\. **Trusted Advisor**: Consulted on security matters with growing credibility across departments 3\. **Business Enable**r: Recognized for contributing to business objectives beyond security 4\. **Strategic Partner**: Integrated into high-level decision-making and organizational strategy By viewing your organization through an anthropological lens, you'll discover new ways to influence outcomes that technical expertise and compliance requirements alone can’t do. In complex social environments like professional organizations, cultural fluency is just as important as technical proficiency. Corporate anthropology offers a framework and tools to navigate these dynamics. ### Breaking Down Barriers: Insights from Our Recent Bug Bounty Communications Scenario URL: https://www.discernibleinc.com/breaking-down-barriers-insights-from-our-recent-bug-bounty-communications-scenario/ Last updated: 2026-07-23T00:37:39.000Z This week, we facilitated a bug bounty communications scenario for Discernible Experience subscribers, where security practitioners experienced firsthand the challenges of vulnerability disclosure from both researcher and organization perspectives. This simulation placed participants in a scenario that highlighted the inherent tensions between external researchers and internal security teams, revealing communication gaps that often derail what should be collaborative and productive interactions. While many organizations focus on optimizing their processes for handling a compromised system, they struggle with the nuanced human dynamics of vulnerability disclosure. The experience reinforced that effective bug bounty programs require more than technical expertise – they demand disciplined and purposeful communication. ## **Bridging Information Asymmetry** We simulated the limited visibility many researchers have into organizational systems to give security professionals a new perspective on why misunderstandings frequently occur. It’s not uncommon for each side to perceive the same vulnerability differently. Researchers naturally focus intensely on observable behaviors and potential impacts, while security teams almost always jump to compensating controls and architectural context that researchers couldn't possibly know about from their external vantage point. This asymmetry mirrors real-world challenges I've seen across many organizations. Security teams often approach vulnerability reports with skepticism about researcher motivations, when in reality, researchers are simply operating with incomplete information, not malicious intent. Organizations that acknowledge this fundamental information gap tend to build more productive relationships with the research community. One of the most valuable insights from the two decades I’ve spent working with responsibility disclosure is how giving the benefit of the doubt, regardless of whether it was initially extended to you, can transform these information-asymmetry challenges. When security teams assume researchers were acting in good faith despite incomplete context, and when researchers assume security teams had valid reasons for their responses despite limited transparency, unnecessary friction dramatically decreases. Equally important is the need for researchers to demonstrate this same maturity in their communications. While high-profile examples of companies responding poorly to vulnerability disclosures have unfortunately created a perception that all organizations act in bad faith, this assumption is demonstrably false and counterproductive. Researchers who begin with aggressive or threatening communications damage their own professional reputation and often receive less cooperative responses. Those who approach disclosures professionally and patiently, even when they suspect delays or dismissiveness, ultimately achieve better outcomes and build stronger reputations within the security community. For both sides, documenting good-faith efforts to bridge this information gap creates powerful protection in the case of disputes or public disclosure. I’ve seen many independent researchers throughout my career who’ve been deeply embarrassed when their aggressive or abusive communication is publicly exposed. Fighting relentlessly on every report as if it’s the last time you will ever need information from a specific bug bounty team is short-sighted and a good way to isolate yourself from the people who could help you in the future. ## **Emotional Dynamics and Communication Barriers** Many bug bounty communication failures stem not from technical disagreements but from translation failures between independent researchers and internal teams, often compounded by emotional reactions. Different priorities, metrics, and terminologies create invisible barriers to effective vulnerability disclosure. Researchers speak in terms of technical findings and reproducible steps. Security teams focus on risk context and business impact. Triage vendors prioritize efficient categorization. Meanwhile, developers track remediation costs and release timelines. Moreover, emotional responses can quickly derail productive communication. Financially and reputationally invested in their findings, researchers often feel dismissed or undervalued when their reports aren’t immediately recognized as critical. Security teams, under constant pressure and often understaffed, can respond defensively to what they perceive as aggressive or exaggerated claims. This emotional cycle frequently escalates conflicts caused by incomplete information rather than technical disagreements. In my experience, what looks like dismissiveness or lack of respect is often simply miscommunication across these different perspectives, amplified by poor emotional regulation on both sides. I've observed researchers becoming increasingly frustrated and using more alarming language when they feel ignored, while security teams retreat into bureaucratic responses or silence when they feel attacked, creating a destructive feedback loop. It can be transformative when either party consciously decides to give the benefit of the doubt, regardless of whether they received it first. Security teams approaching seemingly aggressive reports with genuine curiosity rather than defensiveness often de-escalate tensions immediately. Similarly, researchers who maintain professional communication despite initial dismissive responses frequently achieve better outcomes in the long run. This approach isn't just about being kind (although the world could certainly use more of it) – it's strategically advantageous. Teams that documented their good-faith efforts to understand researcher perspectives, even when facing challenging communications, are in a much stronger position if vulnerabilities are eventually disclosed, voluntarily or not. A paper trail demonstrating reasonable, professional engagement despite communication challenges creates a powerful narrative should the exchange ever become public. The most successful teams I’ve worked with recognized these emotional dynamics, and together we created processes that acknowledged the technical and human elements at play. They established clear expectation-setting communications, provided regular updates even when there was no substantive progress to report, and built documentation assets that acknowledged different viewpoints. Rather than focusing exclusively on technical findings, they built a shared vocabulary that connected external observations to internal context while maintaining professional, emotionally regulated communication – a practice I strongly recommend for any organization running a vulnerability disclosure program. ## **Building Communication Muscle** Like any skill, effective communication across the researcher-organization boundary requires practice. Our subscription experiences provide a safe environment to strengthen these muscles before facing real-world challenges. As vulnerability disclosure programs become increasingly important and researcher communities grow, organizations that excel at vulnerability communication gain several advantages: 1) they're better positioned to avoid public disclosure controversies, 2) maintain productive researcher relationships, and 3) build a stronger reputation for their security programs overall. Effective vulnerability communication isn't about having perfect processes – it's about recognizing the inherent information asymmetry on both sides and building bridges despite these limitations. ### Decisive Under Fire URL: https://www.discernibleinc.com/decisive-under-fire/ Last updated: 2026-06-28T16:14:17.000Z #### Why Decision Frameworks Are the Secret Sauce of Effective Incident Communications, Not Templates As potential security incidents escalate, technical teams are often trained to spring into action with their investigation and containment plans. However, equally critical – and frequently overlooked – is how information flows through the organization and to external stakeholders. Pre-determined roles and responsibilities for communication decision-making enable rapid, consistent, and appropriate information sharing in ways that generic templates simply cannot match. ## **Deciding Who Needs to Know What and When** Communication decisions are as critical as technical ones during a security incident and extend beyond the Corporate Communications team's responsibility. It's a cross-functional effort to define and enforce consistency around communication decisions such as: - Which executives need to be notified at which thresholds? - When should the board be informed? - What details should legal counsel receive versus the social media team? - How much (and which) technical information should be shared with customers (and how)? These decisions can't be made effectively in the heat of the moment when anxiety is high and information is limited. Research on high-performing management teams shows that under pressure, communication often defaults to the loudest voice in the room or whoever has the CEO's ear, not necessarily the person with the right expertise. Communication frameworks establish these decision points in advance, when teams can think clearly and strategically about information flow. This approach eliminates the common scenario where the person with the most confidence, rather than the most expertise, drives the communication strategy during an incident. ## **Balancing Transparency with Protection** Communication during security incidents involves inherent tensions. Speed matters, but so does accuracy. Technical details help establish credibility but can expose vulnerabilities. Customer teams need answers, but oversharing creates more risk. Rather than leaving these tensions to be resolved during an incident, a communication decision framework defines (in advance) how these legitimate competing interests will be balanced. Research into effective management teams shows that focusing on facts rather than opinions is critical for productive conflict resolution. Ideally, your framework specifies what information must be gathered before different communications are approved, creating a common base of facts from which decisions flow. ## **Leveraging Specialized Communication Expertise** Too often, incident communication defaults to an executive's trusted inner circle regardless of whether those individuals understand the nuances of communicating with different stakeholders. This approach usually leads to well-intentioned but imprecise language that confuses and frustrates customers as well as inconsistent messaging across communication channels and audiences. Successful leadership teams create balanced power structures, where executives maintain appropriate authority but specialists contribute their expertise. The most effective decision-making frameworks I've seen (and the kind we build for our clients) explicitly define who drafts, reviews, and approves communication with different stakeholders. This approach prevents the common mistake of allowing a small group of executives to craft all communications without the benefit of specialized knowledge about stakeholder needs, historical context, or communication best practices. It also delivers a critical benefit that ad-hoc communications cannot: consistency across all channels and stakeholders. When different teams communicate independently during an incident, contradictions inevitably emerge. Customers hear one story while employees receive another. Regulators get technical details that differ from what's shared with the press. These inconsistencies destroy trust and create significant legal, regulatory, and reputation exposure. Predetermined communication decision frameworks ensure that all communications flow through a coordinated process that maintains message alignment while allowing appropriate customization for different audiences. ## **Building Common Goals into Communication Strategies** Building common goals is essential for managing conflict constructively. Teams working toward shared objectives are less likely to view disagreements personally and more likely to learn from different perspectives. Your framework should explicitly articulate the team's overarching communication priorities. These might include: - Maintaining stakeholder trust by demonstrating accountability and transparency - Protecting sensitive information that could impact an ongoing investigation - Ensuring consistency across all communication channels With shared goals established in advance, teams can evaluate communication decisions against these common criteria rather than departmental interests when the pressure is on. I'm not looking *only* at litigators when I say this, but I'm looking at them. ## **Moving Beyond Templates to Decision Frameworks** While generic communication templates appear helpful, they inevitably fall short during actual incidents. Security events rarely fit neatly into predetermined scenarios, making rigid templates too vague to be useful or too specific to apply. Instead, effective communication decision frameworks establish agreed-upon criteria that guide judgment calls during high-pressure situations such as: - Severity assessment criteria that trigger different communication paths. - Authorization requirements based on message content and audience. - Review requirements with clear service level agreements to keep up with incident velocity. - Escalation procedures that enforce timely decisions. - Factual requirements for different types of statements. (Demand receipts – if they’re not producible today, fix that ASAP so you can show your work before you need to.) When your team uses your predetermined framework, they can craft appropriate communications tailored to the specific situation while maintaining consistency with organizational values and regulatory requirements. Additionally, when regulators investigate after an incident, they're particularly interested in your communication decisions, such as: - How did you determine when to notify affected parties? - What factors influenced the content of your disclosures? - How did you ensure consistent communications across channels? - What role did legal counsel play in communication decisions? Pre-determined communication decision roles provide exactly the evidence regulators seek by: - Demonstrating that communication considerations were embedded into operational practices before any incident occurred - Providing clear documentation of how and why specific communication decisions were made - Showing consistency between stated policies and actual communications - Establishing that appropriate subject matter experts were consulted before information was shared This documentation creates a defensible audit trail that proves your communication commitments weren't just lip service but were operationalized throughout your organization. ## **The Bottom Line** Organizations that invest in pre-determined communication decision roles respond to security incidents with greater clarity, consistency, and credibility – all while maintaining documentation that demonstrates their commitment to appropriate transparency. When every minute counts and reputations are on the line, the ability to make informed communication decisions quickly becomes your greatest asset. Pre-determined decision roles deliver this capability by leveraging your team's collective wisdom before the pressure rises. Research into high-performing teams consistently demonstrates that the objective isn't to eliminate conflict about communications – it's to make that conflict productive. The right predetermined communication decision framework makes your security response faster and smarter by allowing your team to discuss the right information at the right time. ### Beyond Breach Response URL: https://www.discernibleinc.com/beyond-breach-response/ Last updated: 2026-07-29T21:53:29.000Z #### *Mastering Cross-Functional Privacy Communications* Last week, our team facilitated a privacy incident communications scenario for [Discernible Experience](https://discernibleinc.com/experience?ref=discernibleinc.com) subscribers, where security practitioners tackled a scenario many face but few are prepared for – a legally compliant privacy implementation that utterly fails user expectations. This simulation placed participants in the murky waters of ethical privacy communications — where doing the legally permissible thing might still devastate user trust and business relationships. "We spend so much time preparing for breaches, but almost no time practicing these more nuanced privacy communication scenarios that happen far more frequently," observed one participant. ## Bridging Organizational Divides The most eye-opening moments came during our cross-functional alignment exercise. When data was shared with third parties without explicit consent, participants initially struggled to find common ground between security, product, legal, and business perspectives. "I was struck by how differently each department viewed the same situation," noted one participant. "Engineering immediately focused on technical fixes, while the product manager worried about feature timelines, and the business lead calculated potential partnership revenue loss – all while legal counsel continued to give the green light." This tension mirrors real-world challenges. One CISO in attendance reflected, "In my organization, we've historically approached privacy as a legal compliance issue. This experience showed me we need to reframe it as a business trust issue that requires alignment across all departments." ## Speaking Different Languages The incident debrief revealed that many privacy communication failures stem not from technical ignorance but from translation failures between organizational "languages." During our discussion, we uncovered how different teams operate with distinct priorities, metrics, and terminologies that create invisible barriers to effective privacy communication. Legal teams speak in terms of regulatory compliance and liability. Product managers focus on user experience and feature adoption. Engineering teams prioritize technical implementation and resource constraints. Meanwhile, executives track business metrics and competitive positioning. What looks like resistance to privacy best practices is often miscommunication across these departmental dialects. One security leader described spending weeks trying to convince product teams to change a data collection practice using technical risk arguments, only to gain immediate traction when reframing the same issue regarding user trust metrics and competitive differentiation. We touched on this in a previous [blog post](https://www.discernibleinc.com/exercising-influence-as-the-security-team-look-for-friction-not-just-fuel/) about not just pushing harder to persuade cross-functional teams but instead, making security outcomes possible by helping teams reduce or eliminate friction. In our recent scenario, one team demonstrated creative problem-solving by creating a shared vocabulary that connected privacy concepts to business outcomes. Rather than focusing exclusively on technical implementations, they first focused on building consensus around user expectations and brand trust. ## Building Privacy Communication Muscle Like any skill, effective communication across organizational boundaries requires practice. Our subscription experiences provide a safe environment to develop these muscles before facing real-world challenges. As privacy regulations continue to twitch and thrash – and consumer expectations rise – organizations that excel at cross-functional privacy communication gain a competitive advantage. They’re better positioned to avoid the headlines, maintain user trust, and build stronger internal collaboration. The most valuable takeaway? As one participant put it: "Good incident communication isn't about having all the answers — it's about asking the right questions across departmental boundaries before it's too late." This reinforced what I explored in my previous [blog post](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/), where I outlined critical questions privacy professionals should ask during product development. As our Discernible Experience participants discovered, asking questions like “What is the customer benefit?” and “Are there relevant settings/controls that users can choose to exercise different privacy preferences?” can prevent privacy incidents before they occur. --- *To join future incident communications experiences and develop critical communication skills for yourself, subscribe to Discernible Experience* [*here*](https://discernibleinc.com/experience?ref=discernibleinc.com)*.* ### Sharks in Engineering Waters URL: https://www.discernibleinc.com/sharks-in-engineering-waters/ Last updated: 2026-07-29T21:51:30.000Z ## *How Conflict Contributes to Healthy Tech Teams* Many engineers initially perceive visible conflict as an uncomfortable state to be eliminated or avoided – a sign that something is wrong. However, this perspective misses a crucial insight. Conflict is not a symptom of a problem but a necessary component for achieving excellence together. What we call "conflict" in organizational communication doesn't mean hostility or dysfunction; it implies a difference of opinion, priorities, or agendas. The need for different perspectives is precisely why we are all here. You're in the room for your perspective and have a professional obligation to provide it. ## **A Misunderstood Indicator of Health** Sharks have acquired a fearsome reputation among various populations as apex predators. Yet, marine biologists recognize that the presence of sharks is one of the most reliable indicators of a healthy ocean ecosystem. Their absence typically signals a disturbing imbalance in the underwater environment. This understanding has led to a paradigm shift in marine conservation, where protecting sharks is increasingly viewed not just as species conservation but as ecosystem management. Similarly, conflict in engineering teams has earned an undeserved negative reputation (of course, there are situations where a toxic culture weeps the reputation is sows). Many leaders mistakenly work to eliminate visible disagreement, creating an artificial peace that masks deeper problems. But just as shark populations indicate thriving oceans, visible conflict often signals a healthy engineering culture where team members care deeply about outcomes and feel safe enough to voice dissenting opinions. Forward-thinking engineering organizations don’t simply tolerate disagreement or manage it as a necessary nuisance. Instead, they recognize that healthy conflict is central to creating environments where technical innovation thrives. Just as marine conservation has evolved to protect sharks for their ecosystem-wide benefits rather than only the species itself, good engineering leadership nurtures productive conflict for its organization-wide benefits rather than resolving individual disagreements. ## **Our Professional Obligation** When you withhold your perspective during technical discussions, you're not just being passive—you're actively depriving your team of your expertise and insights. [Research](https://hbr.org/1997/07/how-management-teams-can-have-a-good-fight?ref=discernibleinc.com) by Kathleen Eisenhardt and her colleagues at Stanford University suggests that high-performing technical teams engage in what they call "cognitive conflict" - substantive, issue-oriented differences in perspectives and opinions. Their studies found that teams engaging in frequent but constructive disagreement made better decisions and developed more innovative solutions than teams that avoided conflict. Silent teams might appear harmonious on the surface, but this harmony often masks deeper issues: fear of speaking up, disengagement from outcomes, or lack of diverse perspectives. As organizational psychologist Amy Edmondson notes in her [research](https://web.mit.edu/curhan/www/docs/Articles/15341%5FReadings/Group%5FPerformance/Edmondson%20Psychological%20safety.pdf?ref=discernibleinc.com) on psychological safety, "The absence of conflict is not harmony, it's apathy." There's an important reciprocal relationship here: while individuals have a professional obligation to contribute their perspectives, organizations have an equal responsibility to create environments where it's safe to do so. If you're in an organization where speaking up is punished or ignored, the problem isn't your reluctance to contribute—it's the toxic ecosystem. The obligation to speak up exists within the context of psychological safety. Fix the environment first, then expect the voices to follow. ## **The Real Problem: Underdeveloped Communication Skills** What technical organizations typically lack isn't the creative tension that drives innovation but the communication skills necessary to harness this tension productively. Engineers are trained to solve technical problems, not necessarily to navigate the nuanced interpersonal dynamics that emerge when strong-minded individuals collaborate. Conflict resolution expert Robert Bales' [Interaction Process Analysis](https://psycnet.apa.org/record/1950-04553-000?ref=discernibleinc.com) states that teams need both task-oriented and socio-emotional communication skills to function effectively. While engineering education emphasizes the former, it often neglects the latter. ## **Creating Conditions for Healthy Conflict** Just as ocean ecosystems require specific conditions to support shark populations and overall marine health, engineering organizations need an intentionally cultivated environment where productive conflict can thrive. Psychological safety is at the core of this ecosystem – the foundation upon which all other elements depend. ### **Psychological Safety** Psychological safety, extensively researched by Edmondson at Harvard Business School, creates the essential bedrock for productive conflict. In psychologically safe environments, team members believe they won't be punished or humiliated for speaking up with ideas, questions, concerns, or mistakes. [Google's Project Aristotle](https://www.nytimes.com/2016/02/28/magazine/what-google-learned-from-its-quest-to-build-the-perfect-team.html?ref=discernibleinc.com) confirmed this, finding psychological safety the most important factor in effective teams – more important than technical expertise or project clarity. Within this secure environment, four interconnected elements work together to nurture and channel productive conflict: ### **Leadership** Leaders establish the flow and direction of conflict by creating clear "rules of engagement." An organization’s leadership shapes how conflict moves through the organization. If you’re not the official leader, you can still drive change in how your team experiences conflict. Drawing on Deborah Tannen's [work](https://hbr.org/1995/09/the-power-of-talk-who-gets-heard-and-why?ref=discernibleinc.com) on conversational styles, here are some initial strategic communication steps that teams can take to encourage and protect healthy conflict: - Define what productive conflict looks like for your team. Here are some examples from Discernible clients: - **Team A:** Productive conflict means challenging technical approaches with specific concerns backed by data or experience. When disagreeing with a proposed solution, we articulate the risks we're worried about or the constraints we're considering rather than simply rejecting ideas. We focus our disagreements on the work product's alignment with our reliability standards and user needs, not on preferences or style. - **Team B:** Productive conflict looks like rigorous questioning of assumptions behind models and analyses. We expect team members to ask 'How did you arrive at that conclusion?' and 'What alternative interpretations might explain these results?' Constructive disagreement involves suggesting additional tests or controls rather than simply criticizing work. - **Team C:** Productive conflict in our design reviews means bringing up potential failure modes, integration challenges, or maintenance concerns early in the process. We differentiate between 'must fix' issues that violate requirements or create safety concerns versus 'could improve' suggestions. When raising issues, we articulate the specific impact on system performance, user experience, or manufacturing costs. - **Team D:** Productive conflict means proactively challenging security assumptions and threat models rather than waiting until after implementation. When questioning a security approach, we articulate specific vulnerabilities or attack vectors we're concerned about, rather than making vague statements about 'bad security.' We distinguish between high-priority issues that create immediate risk exposure versus security debt that should be addressed in future iterations. - Establish frameworks for raising and addressing disagreements (provide team members with concrete steps to get started since not everyone comes equipped with these skills, which sets clear expectations and removes uncertainty about how others will respond when concerns are raised). - Articulate what success means in conflict resolution for your team (collective advancement, not individual victory). Here are examples from the same clients as above: - **Team A:** Success in our conflicts means we've thoroughly examined multiple approaches before choosing a direction, with everyone having had the opportunity to raise genuinely considered concerns. - **Team B**: We know our conflict is healthy when it leads to more robust findings, documented limitations, and clearer communication of uncertainties in our analyses. - **Team C:** Our conflicts are working well when previously unseen problems are caught early and when critiques lead to measurable improvements in the final design rather than just changes for the sake of change. - **Team D:** Our conflicts are constructive when they lead to stronger security postures and maintainable solutions that don't unnecessarily impede business operations. Success means we've thoroughly evaluated the security/usability tradeoffs and can clearly explain our risk-based decisions to both technical and non-technical stakeholders. - Model healthy conflict behaviors, demonstrating that disagreement is valued and expected – showing where you draw boundaries around unproductive conflict so team members understand both the importance of speaking up and the guardrails that keep discussions constructive. ### **Communication Frameworks** Communication frameworks provide the structural support where conflict interactions can safely occur. These frameworks give team members concrete tools to navigate difficult conversations productively. Two powerful frameworks to consider include: - [**Nonviolent Communication (NVC)**](https://ccpgc.usmf.md/sites/default/files/inline-files/Nonviolent%20Communication%5F%20A%20Language%20of%20Life%5F%20Life-Changing%20Tools%20for%20Healthy%20Relationships%20%28%20PDFDrive%20%29.pdf?ref=discernibleinc.com) by Marshall Rosenberg, which builds interactions around: - Observing without evaluating - Identifying and expressing feelings - Connecting feelings to needs - Making clear, actionable requests - [**Crucial Conversations**](https://www.accessengineeringlibrary.com/content/book/9780071771320?ref=discernibleinc.com) by Patterson, Grenny, McMillan, and Switzler, which offers structured approaches for high-stakes discussions where opinions vary and emotions run strong ### **Reward Systems** Reward systems determine what behaviors flourish or diminish within the organization. Traditional reward systems often inadvertently nourish conflict avoidance while starving productive disagreement. The result is a culture where problems remain hidden, diverse perspectives are suppressed, and teams produce mediocre solutions that nobody strongly opposed rather than excellent solutions that were thoroughly vetted and improved through constructive challenge. You can redirect these flows to recognize and reward behavior that: - Identifies important disagreements early - Navigates technical conflicts with respect and professionalism - Reaches decisions that incorporate diverse perspectives - Learns collectively from conflicts and improves your conflict resolution processes ### **Implementation** Finally, implementing this ecosystem requires systematic, adaptive approaches. Here are a few suggestions for organizations who want to ensure productive conflict can thrive within their team: - Assess current conflict patterns using tools like the [Thomas-Kilmann Conflict Mode Instrument](https://psycnet.apa.org/doiLanding?doi=10.1037%2Ft02326-000&ref=discernibleinc.com), a five-category scheme for classifying interpersonal conflict-handling modes: competing, collaborating, compromising, avoiding, and accommodating. - Train teams in specific communication frameworks like NVC or Crucial Conversations - Create explicit norms around constructive disagreement (you can use the steps outlined in the “leadership” section above) - Institute regular retrospectives focused on conflict processes (All good communication is deliberate. You will not be effective accidently.) - Recognize and celebrate examples of well-managed conflict ## **Your Perspective** Remember that you weren't hired despite your unique perspective – you were hired because of it. You're not fulfilling your professional responsibility when you remain silent in the face of potential issues or alternative approaches. The most successful technical organizations don't eliminate conflict; they cultivate environments where conflict is a catalyst for improvement rather than a source of division. In doing so, they unlock their teams' diverse perspectives and expertise, driving both technical excellence and organizational health. Just as sharks are essential to ocean ecosystems, professional disagreements are vital to your organization's health. Your perspective isn't just welcome; it's necessary. --- *If your interested in strengthening your team’s skills in communicating and navigating conflict, ask about Discernible’s customized programs, team workshops, and individual coaching* [*here*](https://discernibleinc.com/contact?ref=discernibleinc.com)*.* ### Top Communication Assets to Build Before Your Next Security Incident URL: https://www.discernibleinc.com/5-communication-assets-to-build-before-your-next-security-incident/ Last updated: 2026-08-22T18:57:17.000Z Imagine a fire department that only pays attention to equipment once the alarm sounds. Firefighters struggle to untangle unchecked hoses, radio batteries are dead when communication is critical, and trucks run out of gas en route to an emergency. The outcome would be disastrous. Yet, this is how many companies navigate incident response in cybersecurity. The most effective emergency responders invest heavily in preparation and equipment maintenance during quiet periods because they know that upkeep done before a crisis determines success during one. They don't merely practice scenarios; they continually improve their tools, processes, and decision-making procedures when there's time to experiment. They don’t hastily assemble equipment and protocols in the midst of an emergency. Instead, they thoughtfully develop, test, and refine their tools over time. Competent responders prevent chaos; they don’t create it. Security incident response follows the same principle. Just as firefighters can't afford to learn new equipment while the building burns, security teams can't create effective communication strategies and decision-making procedures during an active breach. The organizational infrastructure, relationships, and trust you build between incidents become the foundation supporting you when every second counts. Security incidents test your technical defenses and your ability to communicate effectively under pressure. In my years working with organizations of all sizes, I've found that companies that invest in proactive communication assets fare significantly better during incidents than those that try to create them on the fly. These assets represent a much more sophisticated approach than the ill-advised templates many companies create to turn incident communications into a fill-in-the-blank exercise. Mad-lib style templates might seem efficient if that’s all you know, but they’re often insufficient in supporting dynamic environments and stakeholder relationships when it matters most. Rather than generic templates, organizations need foundational assets that provide structure while allowing for the nuance each unique incident requires. Here are four communication assets you should develop before you need them: ## **1\. Service Status Page: Your Single Source of Truth** A well-designed and maintained status page is the cornerstone of reliable incident communications. Beyond displaying incident updates, it conditions stakeholders about where to go for authoritative information when things go wrong. During incidents, rumors and misinformation spread quickly. Having an established destination that both internal teams and external customers trust saves precious time and reduces confusion. Your status page should be simple, accessible, and regularly referenced even during normal operations so people develop the habit of checking it first. Regularly using a status page for all service incidents (not only security) trains your internal stakeholders to embrace transparency as a core value. Engineers and product teams who become comfortable providing clear, honest updates about system outages develop the muscle memory needed for security incident communications. This practice establishes credibility with external stakeholders who learn to trust your organization's commitment to timely updates, making them more likely to wait for official information rather than speculate during security events. The most effective status pages function as centralized incident hubs with links to additional resources in your Help Center or technical blogs (more on that below). ## **2\. Security Help Center: Empowering Users While Showcasing Controls** Your help center should guide users through security features like MFA options and educate them about your behind-the-scenes security controls, serving two crucial purposes. First, it increases adoption of user-facing protections, creating a more resilient customer base. But just as important, it demonstrates that you've implemented technical controls that protect users even in a successful attack – like tokenizing credit card data or encrypting passwords and usernames. During incidents, these articles become ready-made resources you can reference to reassure stakeholders about your security fundamentals and the layers of protection you've implemented. They show you weren't merely reactive but had thoughtfully designed your systems with security in mind. ## **3\. Peer Network: To Phone a Friend, You Have to Have One First** Security doesn't happen in isolation. Establishing relationships with security teams across your industry and supply chain provides invaluable intel, support, and visibility during incidents. Your CISO might initiate these connections with counterparts if a relationship doesn’t exist, eventually delegating to appropriate team members for ongoing collaboration. These relationships help technical teams determine root causes and impact scope while giving communications teams broader context about industry-wide patterns. Check-in with your contacts regularly to ensure your list is current and to build the trust necessary for sensitive information-sharing during investigations. When an incident occurs, the ability to quickly reach peers to understand if you're facing a targeted attack or part of a broader campaign can completely change your response strategy. ## **4\. Security Content: Speaking to Different Audiences** Regularly publishing technical and user-friendly security content establishes your security priorities and expertise before incidents occur. This content shows your security competency, maturity, and commitment to transparency. During incidents, these existing resources become references you can link to in communications where space is limited (such as on your status page). Rather than explaining complex concepts from scratch under pressure, you can point to established content that demonstrates your security approach and improvements over time. When creating this content, don't just announce your achievements. Document the journey, challenges, and investments required to reach them. Many stakeholders don't inherently understand how difficult it is to implement proper encryption at scale or restructure authentication systems. You build credibility around your security team's capabilities and cross-functional influence by explicitly detailing the months of planning, substantial resources allocated, and complex technical hurdles overcome. This documented history of solving difficult security problems becomes crucial during incidents when stakeholders need reassurance that your team has the technical depth and perseverance to address the issues. This historical record helps counter skepticism about your security commitment. When stakeholders can see the full picture of your security journey, they're more likely to give you the benefit of the doubt regarding your ability to respond to and recover from serious incidents. This established pattern of transparency about achievements and challenges builds a reservoir of trust that becomes invaluable for security communications. ## **Building Nimbleness Through Preparation** This kind of preparation makes incidents less chaotic and creates remarkable nimbleness in your response. When you've already built these assets, your team can focus on the unique aspects of each incident rather than scrambling to create basic communication procedures and infrastructure. This agility allows you to respond faster, pivot as situations evolve, and address stakeholder concerns more precisely than with generalities. The investment pays off during emergencies and builds lasting trust with your stakeholders, extending well beyond any event. ### CISO Communication Playbook URL: https://www.discernibleinc.com/ciso-communication-playbook/ Last updated: 2026-07-14T21:35:49.000Z #### How Psychology and Communication Research Can Transform Frustration into Influence Cybersecurity has transformed from a technical specialty into a strategic business function. What separates exceptional security leaders from the rest? Communication expertise. CISOs who apply what we’ve learned from communication scholarship don't merely draft requirements — they shape behaviors, influence decisions, and transform organizational norms that determine security outcomes. Successful CISOs develop communication competence throughout their entire security organization by elevating cross-functional collaboration, influencing without authority, and adopting soft skills as core competencies. They understand that technical controls and human behavior are two sides of the same coin, and CISOs who master both domains build more resilient security programs that withstand evolving threats and organizational pressures. ## The Communication Gap in Cybersecurity Board-level visibility for cybersecurity continues to increase, but many CISOs still struggle to translate technical concepts into language that resonates with business leaders. At the same time, security teams face persistent challenges influencing business decisions and organizational behavior. Behind these challenges lies a fundamental misunderstanding of how effective communication actually works. Most security communication efforts rest on three *flawed* assumptions: - Providing information leads to understanding - Understanding produces agreement - Agreement generates action Contemporary communication research and scholarship dismantle these assumptions and offer better approaches. In our monthly newsletter, we explore contemporary communication theories specifically for security professionals. Let's examine a few of those frameworks that can transform your security program's effectiveness. ## Risk Communication: Why Your Security Messages Fail Have you ever meticulously crafted security guidance only to watch executives or employees ignore it? Risk communication research explains why. The [Extended Parallel Process Model (EPPM](https://www.tandfonline.com/doi/abs/10.1080/03637759209376276?ref=discernibleinc.com)), developed by Kim Witte, demonstrates that effective risk messages must balance two key elements: - **Threat messaging**: Communicating the severity of and susceptibility to a threat - **Efficacy messaging**: Providing clear, actionable steps that individuals can take to mitigate the risk When security communications emphasize threats without providing adequate efficacy information, they trigger what researchers call "fear control" rather than "danger control." Instead of taking protective action, recipients focus on managing their emotional response—often through denial, minimization, or avoidance. This explains why fear-based security communication programs frequently backfire. People don't ignore security guidance because they're lazy or uncaring; they ignore it because the communication approach triggers psychological defense mechanisms. Smart CISOs apply this research by: - Balancing messages about cyber threats with clear, achievable security actions - Ensuring people feel empowered rather than overwhelmed - Testing messages to verify they produce the intended response ## Diffusion of Innovations: A Roadmap for Security Adoption Introducing new security technologies or processes often feels like pushing a boulder uphill. [Diffusion of Innovations theory](https://www.techtarget.com/whatis/feature/Diffusion-of-innovations-theory-Definition-and-examples?ref=discernibleinc.com)**,** pioneered by Everett Rogers, explains why and offers a framework for success. This theory identifies five characteristics that determine adoption rates: - **Relative advantage**: How improved the innovation is over what it’s replacing - **Compatibility**: How consistent the innovation is with the values, experiences, and needs of potential adopters - **Complexity**: How difficult the innovation is to understand and use - **Trialability**: The extent to which the innovation can be experimented with on a limited basis - **Observability**: How visible the results of the innovation are to others When security teams focus exclusively on technical capabilities without considering these factors, they virtually guarantee resistance. By contrast, CISOs who leverage diffusion theory can strategically position security initiatives for success. For example, when implementing single sign-on (SSO), effective security communication looks like this: - Demonstrate clear advantages by highlighting both security benefits and user convenience - Ensure compatibility by selecting solutions that integrate with existing applications and identity stores - Reduce complexity through carefully constructed information hubs, employee communications, and intuitive login experiences - Enable trialability through controlled rollouts to specific groups - Increase observability by showcasing metrics on reduced login times and helpdesk ticket volume ## Organizational Rhetoric: Speaking the Language of Business One of the most common complaints about security leaders is that they struggle to communicate in business terms. Organizational rhetoric studies provide insights into how to frame security needs in language that resonates with executives and boards. Research by scholars like [George Cheney](https://www.tandfonline.com/doi/abs/10.1080/00335638309383643?ref=discernibleinc.com) and [Cynthia Stohl](https://books.google.com/books?id=qW45DQAAQBAJ&lpg=PP1&ots=tzND6-9Jjm&dq=Cynthia%20Stohl%20organizational%20communication&lr&pg=PP1&ref=discernibleinc.com#v=onepage&q=Cynthia%20Stohl%20organizational%20communication&f=false) shows that successful organizational communication requires alignment with dominant value systems and discourse patterns. For security leaders, this means translating security concepts into the frameworks that drive business decisions. Effective CISOs leverage this research by: - Mapping security initiatives to strategic business objectives - Quantifying security risks in financial terms - Using narrative structures that mirror how other business cases are presented - Adopting the linguistic patterns and metaphors common in executive communications When security is positioned as an enabler of business goals rather than a cost center or obstacle, it receives greater support and resources. Essentially, we’re translating between different professional languages. ## Media Richness Theory: Choosing the Right Channel In the digital age, security leaders have countless communication channels at their disposal: email, Slack, video conferences, in-person meetings, team collaboration platforms, and more. [Media Richness Theory](https://journals.aom.org/doi/10.5465/ame.1988.4277259?ref=discernibleinc.com), developed by Richard Daft and Robert Lengel, provides guidance on which channels work best for different types of security messages. The theory posits that communication channels vary in their capacity to handle ambiguity and facilitate understanding — this is referred to as their "richness." Richer media provide more immediate feedback, support multiple communication cues, allow for personal focus, and permit language variety. Security communications often fail when there's a mismatch between the message's complexity and the medium's richness. For example, explaining a nuanced security policy change via email (a relatively lean medium) may lead to confusion and misinterpretation. Savvy CISOs apply this theory by: - Using richer media (in-person or video meetings) for complex or potentially controversial security messages - Selecting leaner media (email, documentation) for straightforward, unambiguous information - Considering the emotional implications of security communications when choosing channels - Creating deliberate communication cascades that use multiple channels for critical security initiatives ## Psychological Reactance: Understanding Resistance When users circumvent security controls or ignore security policies, they're often exhibiting what communication researchers call psychological reactance, a negative reaction to messages or mandates that threaten their sense of freedom and autonomy. Developed by Jack Brehm, the [Reactance Theory](https://www.sciencedirect.com/book/9780121298401/psychological-reactance?ref=discernibleinc.com)explains why heavy-handed security measures often backfire, leading to greater risk-taking rather than compliance. When individuals feel their choices are being restricted, they become motivated to reassert their freedom even if doing so is counter to their own interests. Forward-thinking security leaders mitigate reactance by: - Providing clear rationales for security requirements - Offering meaningful choices within security constraints - Using autonomy-supportive language ("you might consider" vs. "you must") - Acknowledging the legitimacy of concerns about security friction This approach doesn't mean compromising on security standards. Rather, it means implementing those standards in ways that respect user agency and minimize psychological resistance. ### CUSTOMER CASE STUDY: Building CISO Resilience with Strategic Communications URL: https://www.discernibleinc.com/customer-case-study-building-ciso-resilience-with-strategic-communications/ Last updated: 2026-07-29T21:49:40.000Z --- As cybersecurity increasingly demands board-level attention and public scrutiny, CISOs find themselves in high-stakes communication scenarios that extend far beyond technical expertise. Specialized communications coaching from Discernible helped [Amy Bogac](https://www.linkedin.com/in/abogac/?ref=discernibleinc.com), a senior Chief Information Security Officer (CISO), navigate career transitions, strengthen reputation management skills, and build a stronger executive presence. Through targeted coaching sessions with Discernible CEO Melanie Ensign, Amy successfully transformed a challenging situation into an opportunity for professional growth and leadership development. CISOs today face unprecedented communication challenges, including: - Rising frequency of board presentations and executive interactions - Increased media and customer scrutiny following security incidents - Growing need to translate technical concepts for non-technical stakeholders - Expanding responsibility for organizational risk communication - Regular public speaking requirements through press engagements and industry events - Complex stakeholder management across business units Today’s CISOs spend a growing proportion of their time on communication and stakeholder management. Despite this shift, many security leaders lack formal training in executive communication, crisis management, and public relations, critical skills for modern security leadership. ## Client Challenges Amy is a seasoned security executive with 20+ years of experience in information security, IT governance, and compliance. She is known for developing effective strategies that bring cyber resilience to the boardroom and elevate the CISO role to senior leadership with business influence. She has led security teams across the manufacturing industry, from the Kellogg Company to Walgreens, and Clorox. Amy currently serves as the CISO at the international consulting and public accounting firm Baker Tilly. When Amy first came to Discernible, she faced several concurrent challenges: - Navigating the aftermath of a high-profile security incident and associated media coverage - Needing to reclaim her professional narrative with a structured approach - Desire to transition to a new executive role meeting specific criteria > “Never did I ever think that I would need a personal incident response plan and public relations expert to help manage media inquiries or questions. What you did at one company isn’t going to translate 100% to another. What worked for you before might not be the secret sauce at the next place.” — Amy Bogac, CISO, Baker Tilly ## Discernible’s Approach Discernible CEO Melanie Ensign designed an engagement for Amy focused on developing a comprehensive communications strategy with: - Clear, intentional messaging and practical application through podcasts and speaking opportunities - Engaging presentation materials - A strategic narrative for professional transitions - Coaching for crisis communications and reputation-building Melanie brought a unique combination of corporate communications, IT security, and crisis management expertise, creating the perfect environment for achieving Amy’s goals. ## Key Outcomes According to Amy, her engagement with Discernible delivered significant results across multiple areas, including: **Professional Development** - Successfully secured a CISO position at a privately held organization with $1B+ in revenue - Enhanced board and executive interactions through improved messaging - Developed confidence in handling vulnerable topics in public speaking **Communications Capabilities** - Established a foundation for delivering audience-centric presentations - Built "muscle memory" for key messaging points - Established clear, consistent narrative for professional experiences > “Working with Melanie at this point in my career journey was transformative. With years of professional leadership development and an undergraduate degree in Communications, I did not realize how much I would gain from this engagement.” — Amy Bogac, CISO, Baker Tilly ## Recommendations for CISOs Specialized communications coaching is increasingly important for senior technology executives, particularly in high-stakes situations. Discernible’s combination of industry-specific knowledge and communications expertise was essential for Amy to achieve her immediate crisis management goals and longer-term career objectives. The evolution of the CISO role from technical expert to business leader requires a corresponding evolution in communication capabilities. Amy’s experience reflects the growing recognition among security leaders that executive presence and strategic communication skills are no longer optional – they are critical competencies for modern security leadership. ![](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/15a48d0f-e69e-4a0b-8146-038394bda39f/Discernible_CISO_case+study.jpg) > *“Even experienced leaders and presenters can evolve and grow our personal presentation skills as we move through different phases and stages of our careers. If you are lucky enough to have this level of internal support, take advantage of it. If you are working on what's next for you and your career, a partner like Melanie at Discernible, is a great personal investment.”* > > \- Amy Bogac, CISO, Baker Tilly --- To learn more about Discernible’s executive communications coaching for security leaders, contact us [here](https://discernibleinc.com/contact?ref=discernibleinc.com). ### When Less Is More: The Argument Dilution Effect URL: https://www.discernibleinc.com/when-less-is-more-the-argument-dilution-effect/ Last updated: 2026-07-29T21:48:50.000Z ## *Psychology Behind Effective CISO Board Communications* In 1969, Fred Rogers successfully convinced Congress to fund public broadcasting with a focused, emotional appeal despite previous presenters using overwhelming data. This was when the Corporation for Public Broadcasting (CPB) was on the chopping block as President Richard Nixon wanted to slash its proposed budget. Fred Rogers testified before Senator John Pastore's Congressional Committee to advocate for the $20 million funding for public broadcasting. His testimony stood out because instead of presenting numerous data points like previous speakers had done, he focused on a single, emotionally powerful argument about what his program meant to children, even reciting the words to a song from his show about self-esteem and emotional regulation. When the Hidden Brain podcast [interviewed](https://hiddenbrain.org/podcast/less-is-more/?ref=discernibleinc.com) Niro Sivanathan, a professor of Organizational Behavior at the London Business School, they discussed the "argument dilution effect"— a phenomenon that weakens the persuasion of strong arguments when they’re mixed with weaker ones because our brains average rather than add information quality. Essentially, you can undermine your case by adding too many points. Think of it this way: When trying to convince someone of something, your brain naturally wants to give every possible reason why you're right. But the listener's brain doesn't add up all those points—it averages them. If you have two strong reasons (let's say they're 9/10 in strength) and add two mediocre reasons (6/10 in strength), your overall argument doesn't become stronger. Instead of adding up to 30 points (9+9+6+6), the listener's brain averages them to 7.5/10\. You would have been better off sticking with your two 9/10 arguments, which would average to 9/10. This happens because: 1. Our brains take mental shortcuts when processing information 2. We tend to balance or average information rather than carefully weighing each point 3. When weak points are mixed with strong ones, they drag down the perceived strength of the entire argument Effective communicators focus on their one or two strongest points rather than overwhelming their audience with every possible argument. While the recommendations below apply to anyone trying to persuade someone else to agree with their viewpoints, I often discuss these principles with CISOs when we need to convince their board of directors to trust, support, and fund their priorities. ## Focus on your strongest arguments. CISOs often make the mistake of presenting a comprehensive list of security concerns, mixing critical vulnerabilities with minor issues. Instead, concentrate on the highest-impact security threats and vulnerabilities, as adding weaker security concerns will dilute the perceived severity of the major threats through the averaging effect. To illustrate the difference, here’s a hypothetical example of a CISO communicating to the board about resources needed to mitigate critical vulnerabilities: **Approach #1:** "Our security assessment found 27 vulnerabilities including three critical remote code execution flaws, eight medium-severity authentication issues, 12 low-risk cookie handling problems, and four minor SSL configuration warnings. We need $500,000 to address these issues." **Approach #2:** "Our security assessment identified three critical vulnerabilities that could allow attackers to execute malicious code on our customer data servers. These flaws would let attackers bypass all existing controls and potentially access millions of customer records. We need $500,000 to address these specific high-impact issues." **The difference:** By focusing solely on the most severe vulnerabilities in approach #2, the CISO makes the threat concrete and avoids diluting the seriousness with minor issues that the board might average together. ## Use appropriate emphasis for different severity levels. When presenting security findings to business leaders, CISOs can be more effective by visually distinguishing between critical and minor issues (similar to Niro's experiment with red vs. black text from the *Hidden Brain* interview). This helps stakeholders properly weigh information while maintaining comprehensive reporting, making it more likely that resources will be allocated to address the most serious security concerns. Here’s another hypothetical scenario: **Approach #1:** "Here's our quarterly security report with all 46 findings chronologically. Our team has been working through them as resources permit." **Approach #2:** "Here's our quarterly security report. The three findings highlighted in red represent critical business risks that require immediate attention and board approval. The others are being managed through our normal operations. I'd like to focus our limited time today on these three critical items." **The difference**: By visually distinguishing the severity tiers and explicitly directing attention to the most critical issues, the CISO helps the board properly weight the information rather than averaging everything together. # Balance security information without creating anxiety. CISOs must provide enough security information to drive action without triggering a harmful "[security news consumption](https://pubmed.ncbi.nlm.nih.gov/35999665/?ref=discernibleinc.com)" pattern that creates anxiety without productive outcomes. Focus on actionable intelligence rather than overwhelming stakeholders with every threat, helping business leaders make informed decisions without constant security fear. **Approach #1:** "Here's a daily security briefing with all threat intelligence we've gathered. There are 17 new threat actor groups targeting our industry, 34 new malware variants detected globally, and nine zero-day vulnerabilities announced yesterday. Our team is monitoring all of these developments." **Approach #2:** "Based on our threat intelligence, we've identified two specific attack methods being used against companies like ours. Here's our concrete plan to address these threats and what success will look like. We'll continue monitoring other developments but are focusing our resources on these verified high-probability threats." **The difference**: The more effective approach #2 filters the flood of security information down to actionable intelligence tied to specific outcomes. ## When Less Is More in Security Communication Remember, *how* we communicate can be just as important as what we’re saying. The argument dilution effect teaches us a powerful lesson: When it comes to persuasion, less truly is more. Security leaders can dramatically increase their influence by focusing on their strongest security points rather than overwhelming audiences with comprehensive lists, visually distinguishing between severity levels, and providing actionable intelligence rather than constant threat updates. The most successful CISOs aren't necessarily those with the most technical knowledge but those who understand the psychology of communication. Mastering these communication principles is essential for organizations in a field where gaining buy-in for critical security initiatives can mean the difference between a manageable and catastrophic incident. After all, the most important security vulnerability isn't in your systems—it might be in how you talk about them. ### Introducing Discernible Experience: The Power of Persistent Practice URL: https://www.discernibleinc.com/introducing-discernible-experience-the-power-of-persistent-practice/ Last updated: 2026-06-26T21:10:03.000Z *Join industry peers for weekly bite-sized drills that prepare your communication skills for any incident.* Security teams juggle a variety of daily challenges: coordinating with external researchers, triaging product vulnerabilities, mitigating insider threats, and managing regulatory requirements. Each scenario needs a reliable communication strategy for effective stakeholder management and cross-functional alignment every day of the week. When you’re experiencing an active or potential incident, the stakes are even higher, and cracks in your communication flows can impact your team’s ability to respond quickly and effectively — or worse, ineffective communication can be the thing that turns a potential incident into an actual crisis. Today, we're launching Discernible Experience, a subscription-based service that runs weekly simulation drills in a dedicated Slack channel where security professionals from different organizations learn and practice together. This collaborative environment creates a unique opportunity to gain diverse perspectives and approaches you wouldn't encounter in traditional internal training. These drills, informed by two decades of frontline incident response experience across various organizations, provide unparalleled exposure to realistic communication challenges and critical decision-making scenarios while building a network of peers facing similar challenges. Discernible Experience is designed for seasoned incident responders who want to maintain peak communication performance and rising professionals eager to accelerate their expertise beyond what organic incidents provide. ## From Reactive to Ready Weekly security drills transform incident response from a conscious effort into an instinctive reaction. Just as experienced technical responders can execute complex protocols without conscious thought, regular practice embeds communication workflows deep into your team's muscle memory. This frees up critical mental bandwidth during actual incidents. So, instead of spending precious cognitive resources remembering who to contact or which protocol to follow, your mind stays clear to analyze emerging threats, spot subtle anomalies, and adapt to the unique challenges each incident presents. When communication becomes second nature, creative problem-solving becomes possible. Discernible’s weekly drills cover an initial 12 categories of security and privacy incidents, focusing on universal communication challenges and unique ones introduced by the nuance of a particular situation: - Bug bounty / external researcher escalation - Web3 / smart contract attacks - Ransomware - Insider threats - Product development / SDLC - Third-party incidents - Open source vulnerabilities - Outages - Rumors / Industry drama - Media inquiries - Privacy violations - Network compromise The most effective security teams communicate clearly and boldly when it matters most – and this takes practice. When communications articulate technical complexities, align stakeholders, and ensure accurate public communication, they elevate the entire organization's security posture, reputation, and customer satisfaction. These critical skills need constant refinement and exercise. Our concise 60-minute weekly scenarios fit into demanding schedules to help you strengthen your skills in: - Strategic communication planning in high-stakes scenarios - Rapid assessment and prioritization of stakeholder communication needs - Precise message crafting and delivery under tight deadlines - Orchestrating seamless cross-functional coordination and information flow ## Removing Friction, Maximizing Impact We designed Discernible Experience to make it quick and easy for you to participate without working longer hours: - **No new software**: Scenarios are conducted inside Slack, eliminating the need for additional vendors or new third-party app approvals from IT. - **Practical time commitment**: Our drills can fit your busy schedule without overwhelming it. They provide focused, high-impact learning opportunities without disrupting your core work responsibilities. - **No purchase order or vendor contract required**: Security and privacy practitioners can participate independently, enabling personal skill development and providing a low-friction pathway to bolster expertise, regardless of team-wide training initiatives. ## Subscription Benefits *Benefits and costs are per person.* **Discernible Experience** ($50/month) - Weekly 60-minute security communication drills in Slack - Access to an expanding library of detailed scenarios and postmortem reports **Discernible Experience Pro** ($100/month) - All membership benefits above - The option to request scenarios for future weekly scenarios that focus on your interests or challenges - Exclusive access to live, in-depth, 30-minute post-mortem sessions with Discernible CEO [Melanie Ensign](https://www.linkedin.com/in/melanieensign/?ref=discernibleinc.com) after each drill, providing expert-level analysis - Three guest passes per year to share a unique learning experience with colleagues ## Beyond Traditional Tabletops Traditional tabletop exercises have limitations. They often demand significant preparation and disrupt regular workflows. While valuable for validating high-level response plans, they lack the frequency and adaptability needed for continuous skill development in communication. Additionally, organizations often focus their tabletop exercises on catastrophic scenarios, creating a critical gap in organizational preparedness. The time and resources required to orchestrate a full-scale TTX means teams rarely practice handling the more frequent, seemingly minor incidents that can spiral into crises without proper management. Individual practitioners get little opportunity to sharpen their skills at catching early warning signs, like a newly discovered product vulnerability, or containing small incidents before they escalate. This leaves teams underprepared for the day-to-day vigilance and quick action that often prevents disasters from happening in the first place. Discernible Experience complements, not replaces, comprehensive tabletop exercises (which we continue to offer separately). This new service delivers frequent, focused practice for honing communication strategies and skills at the individual level. Our meticulously designed scenarios reflect the most relevant security and privacy threats and communication challenges, enabling practitioners to build and strengthen muscle memory for incident communication. The goal is to free up a team’s cognitive resources so they can focus on intricate technical problems during real-world events. This approach also fosters cross-organizational learning, allowing security and privacy professionals to share insights and best practices with peers from other organizations who also subscribe to Discernible Experience. As a result, participants benefit from diverse perspectives and experiences not available through internal-only training. ### The Myth of Shared Responsibility URL: https://www.discernibleinc.com/the-myth-of-shared-responsibility/ Last updated: 2026-07-29T21:46:37.000Z "Security is everyone's responsibility" - this well-intentioned mantra echoes through corporate hallways, yet organizations continue to struggle with security breaches and vulnerabilities. The uncomfortable truth is that shared responsibility often means no responsibility at all, especially when it comes to cybersecurity. The fundamental problem lies in misaligned incentives. While security teams are measured by incident rates, compliance metrics, and risk reduction, other departments focus on speed to market, feature delivery, and revenue growth. When these priorities clash, security typically loses. A product team racing to meet a launch target is unlikely to prioritize anything that could delay release dates. Business units under pressure to improve productivity might bypass company policies and share regulated data through unauthorized cloud services. Marketing teams might deploy leaky tools to meet campaign deadlines. This misalignment creates a dangerous asymmetry of consequences. When a security breach occurs, the security team bears the brunt of the fallout - late nights, incident reports, and challenging questions from leadership. Meanwhile, the departments whose actions contributed to the vulnerability often face no direct repercussions. Their performance metrics remain unaffected while security cleans up the mess. The solution isn't more security awareness training or stern emails about compliance. Instead, organizations need to fundamentally rewire how security impact flows across departmental boundaries. Here are a few ways that security teams can drive meaningful change: ## **Make Security Impact Visible** Security metrics are most effective when they’re integrated into departmental KPIs and performance reviews. If an engineering or product team's metrics don't account for security debt, they'll continue to prioritize speed over safety. If procurement's vendor assessment process ignores security risks, they'll likely choose the cheapest option regardless of vulnerabilities. ## **Transform Budget Conversations** A good percentage of security professionals allow other departments to treat them like a cost center that can be ignored. This perception is difficult to change if other departments don’t know or feel the cost of their security risks. How would you persuade a team who wants to deploy a new tool that they should factor in security assessment and ongoing monitoring costs? This creates natural incentives to choose secure solutions and follow security protocols. ## **Reframe Security as Business Enablement** Help other departments understand how good security practices can accelerate their objectives - from faster deployment pipelines with built-in security to improved customer trust driving sales. Track and measure your impact, then report it up the chain. ## **Measure What Matters** Move beyond traditional security metrics to track business impact. Instead of reporting on vulnerability counts, show how security improvements reduce deployment delays, increase customer satisfaction, or improve sales win rates. This helps other departments see security as a valuable opportunity rather than a burden. The myth of shared responsibility persists because it's comfortable - it allows organizations to talk about security without making consequential changes to incentives and accountability structures. Productive security (rather than performative or checkbox security) requires moving beyond this myth to create tangible consequences and rewards that align departmental behaviors with security objectives that extend beyond the security team's boundaries. ## What Do You Think? Join my friends at [Credible Security](https://credible-security.com/?ref=discernibleinc.com) and me on Tuesday, February 25, for a livestream that challenges the popular corporate mantra "security is everyone's responsibility" and reveals why this well-intentioned approach often leads to security failures. We'll explore approaches that go beyond awareness training, including integrating security metrics into departmental KPIs, transforming budget conversations, and measuring what truly matters for your business. Don't miss this candid discussion about creating meaningful security accountability. Perfect for security professionals, department leaders, and executives who want to move beyond performative security to build truly resilient organizations. **Location**: [youtube.com/@CredibleSecurity](https://youtube.com/@CredibleSecurity?ref=discernibleinc.com) **Date**: Tuesday, February 25, 2025 **Time**: 11:30am-12:30pm ET ### How Data Ethics Makes Incident Response More Effective URL: https://www.discernibleinc.com/how-data-ethics-makes-incident-response-more-effective/ Last updated: 2026-07-01T18:04:46.000Z In 2022, McKinsey published a [report](https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/data-ethics-what-it-means-and-what-it-takes?ref=discernibleinc.com) on establishing durable data ethics practices. According to the report’s authors, organizations with such practices benefit from several advantages, such as increased stakeholder trust and faster decision-making through clear risk thresholds for employees and standard criteria for determining acceptable data ventures. The report suggests these benefits are both defensive (preventing problems) and proactive (creating opportunities). It emphasizes that data ethics requires organization-wide commitment, clear governance structures, and integration into daily operations. It also highlights how establishing, strengthening, and maintaining stakeholder trust requires companies to go beyond regulatory compliance. There’s no reputational reward for meeting the bare minimum. However, the report also identifies several challenges preventing organizations from adopting data ethics practices, including: 1. Assuming data ethics doesn't apply to their organization 2. Relegating data ethics solely to legal/compliance teams 3. Prioritizing short-term ROI over long-term considerations 4. Focusing only on data utility without considering sources and implications These challenges are even more critical when considering their impact on incident response capabilities because while organizations often treat ethics and incident response as separate domains, the reality is that they're deeply interconnected. An organization's ethical framework - or lack thereof - directly shapes its ability to respond how it wants to when incidents occur. A company that has already grappled with ethical data usage and established clear principles is better positioned to make difficult decisions during an active incident. This natural connection between ethics and incident response deserves closer examination. # The Data Ethics-Incident Response Connection After 20 years in the field, I can’t ignore the intersection of data ethics and incident response readiness. I’ve seen how an organization's functioning values and principles can either strengthen or undermine its resilience. Below are several ways data ethics and incident resilience connect and reinforce each other. - **Transparency and Trust** — Ethical data practices foster transparency and build confidence in an organization’s ability to handle incidents and recover for the better. Generally speaking, organizations prioritizing data ethics also maintain meticulous documentation and well-defined data flows, enabling them to assess and respond to incidents quickly and decisively. Moreover, establishing a history of transparent practices supports the credibility of your incident communications because your past actions align with your message. Without alignment between actions and communication, trust and understanding is difficult to earn from stakeholders, making them less likely to accept your explanations. - **Data Governance and Incident Response** — Clear governance structures – supported by strong, articulated, and exercised data ethics – can significantly enhance incident response capabilities. If better monitoring and controls help organizations detect and contain incidents faster, consider how a clear understanding of data assets and their criticality — proven with accurate data maps — allows for quicker impact assessments and informed decision-making, resulting in a more efficient and effective response. - **Policy and Procedure Alignment** — Several key aspects can help you seamlessly integrate ethical data decisions into incident response procedures, such as clear data classification guidelines which can inform and streamline priorities during an incident. Well-defined roles and responsibilities for making and implementing data ethics decisions can also be used for incident response. When working with Discernible clients on their RACI models for incident response communications, we find that the roles and responsibilities often mirror those related to data practices outside of incidents. Formally acknowledging and documenting that alignment is valuable because predetermined communication protocols can facilitate timely and transparent communication when under pressure. Misalignment in practice or understanding is a big red flag for folks tasked with explaining decisions to stakeholders. One of these reasons we believe incident response procedures should reflect daily operations as much as possible is that we’ve found that *frequent,* not only *regular* testing and validation processes are fundamental to ethical data practices and incident response preparedness. Finally, consider how post-incident analysis can improve both incident response effectiveness and ethical data practices to prevent or reduce the impact of various security and privacy events. I previously [published](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/) a list of sample questions I’ve used with engineering and product teams to evaluate whether a change in the company’s data practices was likely to create what I call “privacy outrage.” Not all incidents are inevitable; and we do ourselves, our organizations, and our stakeholders a grave disservice by ignoring these considerations until an incident is triggered. - **Stakeholder Management**— Proactive ethical data practices foster strong relationships across stakeholders, from customers and regulators to employees, investors, and industry partners. Having a reputation for data ethics and open communication is an invaluable source of goodwill and benefit of the doubt when you need it the most. If you don’t already have clear and established communication channels for every audience (including backups), doing so now will enable swift and effective engagement when things go south. Maintaining ethical data practices also helps build trust with media contacts, helping incident communications land with credibility and understanding. Your ethical behavior extends to vendor and partner relationships (an often overlooked audience in traditional incident communications), fostering a network of trust and collaboration you can leverage during an incident. A strong foundation of ethical behavior also cultivates a more engaged employee base, who are more likely to be supportive and cooperative during incident response efforts. # Integrating Data Ethics into Incident Response Planning Below are some initial steps organizations can take to proactively weave data ethics into their incident response framework to respond effectively to maintain stakeholder trust and uphold their core values. - **Planning for Principled Response** —Start by integrating ethical decision-making frameworks directly into your incident response plans. Then, create scenario plans that specifically address potential ethical dilemmas to help teams prepare for navigating complex situations. Again, the more often you follow this framework in your day-to-day operations, the more familiar it will be when running it during an incident. For example, clear ethical guidelines for incident disclosure, from bug bounty reports to third-party supply chain attacks, promote transparency and accountability. They also help establish protocols for protecting impacted populations during incidents, which is not only the right thing to do ethically, but also demonstrates a commitment to your stakeholders. Incident response plans can also prioritize actions that align with organizational values and minimize harm by building ethical considerations into triage, mitigation, and communication processes. - **Strengthen Documentation and Training** — Robust documentation and comprehensive training are vital for integrating ethical considerations into incident response, not simply in theory but in practice. Integrated training programs covering ethics and incident response together help all team members understand their roles and responsibilities in helping the organization make ethical decisions. Maintaining updated stakeholder maps and communication plans ensures that relevant parties are informed and engaged throughout the incident – and beyond. Furthermore, documenting ethical decision-making processes for high-pressure situations provides guidance when time is of the essence. Regular testing and simulation of ethically complex scenarios allow teams to practice their responses and refine their decision-making skills. - **Build Cross-functional Capabilities** — We run many messaging focus groups at Discernible, and almost universally, security practitioners respond poorly to the term “collaboration” because it sounds much more complicated and challenging than doing something yourself. We’re telling on ourselves here, fam. We can’t simultaneously hope for “shared responsibility” and refuse to develop the necessary skills and relationships to achieve that outcome. Effective incident response requires collaboration across multiple functions and should include ethics expertise across functions, ensuring that ethical concerns are considered at every stage of your response. Don’t forget to include clear escalation paths for ethical concerns to promptly resolve complex issues that might pop up during an incident. Shared metrics for success are another essential element because they foster a culture of collective accountability and allow for ongoing performance evaluation as an organization. The goal here is continuous coordination to simultaneously consider privacy, security, and ethical concerns and promote a holistic approach to both data management and incident response. - **Enhance Monitoring and Assessment** — It’s no secret that continuous monitoring and assessment are essential for maintaining both ethical data practices and effective incident response because we can’t manage what we don’t measure. Moreover, policies are only as good as their enforcement. Implementing monitoring systems that cover security and ethical concerns allows organizations to proactively identify and address potential risks before they become or exacerbate an incident. Regularly evaluate whether the ethical risks in your incident response procedures reflect your organizational values. When working with clients on incident readiness, our team starts with the values and attributes the organization wants to exemplify in their response behavior. This approach puts everyone on the same page regarding tone, language, and transparency of their communications before a single word is written or said. - **Strengthen External Relationships** — Most traditional incident communications plans don’t consider connections with peer organizations or advocacy groups. I believe this is a missed opportunity for information sharing and learning from each other’s experiences. Creating a network of mutual support provides a safety net during incidents and allows organizations to leverage the collective expertise and credibility of the community. The key to effective integration is recognizing that strong data ethics create a foundation for more effective incident response, while good incident response practices help maintain ethical standards under pressure. Each reinforces and strengthens the other, creating a more resilient organization overall. We must understand this intersection as our organizations face dramatically complex incidents that require balancing multiple stakeholder interests while maintaining public trust. Organizations proactively addressing this intersection are better positioned to handle future challenges effectively. ### 📬 Mailbag: What are the elements of a successful post-mortem? URL: https://www.discernibleinc.com/mailbag-what-are-the-elements-of-a-successful-post-mortem/ Last updated: 2026-07-01T04:42:10.000Z *Mailbag questions are submitted by our readers. Submit your own question for our team at discernibleinc.com/contact.* --- *It’s not about closing out incidents – it’s about opening up opportunities for continuous improvement.* Post-mortem analysis is fundamental to incident response, yet many organizations struggle to translate these exercises into meaningful operational improvements. After participating in hundreds of post-mortems across various organizations, I've observed that the most impactful sessions often succeed or fail based on elements not covered in standard playbooks. # Critical Yet Often Overlooked Elements The timing of a post-mortem itself can dramatically influence its effectiveness. Conventional wisdom suggests conducting them immediately after resolution, but the most successful organizations actually conduct at least two separate sessions: an immediate technical debrief focused on tactical improvements, followed by a broader strategic post-mortem 2-3 weeks later when emotions have cooled, and broader patterns become visible. In fact, the root cause identified in the immediate aftermath of an incident often differs from the systemic issues revealed during the extended analysis. Information and data uncovered between the two sessions can also help identify patterns that weren't apparent during the initial investigation. Additionally, I believe findings from subsequent sessions are invaluable for communication efforts to strengthen trust across stakeholders by demonstrating ongoing concern, commitment, and credibility. ## Cultural Integration: The Hidden Multiplier In my experience, the most successful post-mortems aren't treated as isolated events but are integrated into the organization's operational rhythm. Rather than creating separate action items, effective teams weave post-mortem findings into existing workflows and meetings. For example, instead of creating a new vulnerability scanning procedure, they might incorporate the incident's key detection points into existing CI/CD pipeline checks or developer code review checklists. One particularly effective approach we’ve worked on with Discernible clients is the "post-mortem ambassador" model, where IR team members are assigned to specific business units as ongoing consultants rather than just incident responders. This continuous engagement helps translate security insights into language and actions that resonate with different departments' priorities and workflows. Our specialized workshops and 1x1 coaching help security teams develop the communication and negotiation skills needed to excel in these embedded roles. ## Surprising Impact Points Our most notable observation is that truly impactful post-mortems must dig deep into prevention and recovery as interconnected elements, with equal focus on how decisions are made in each context. Organizations that expand their analysis beyond technical controls to examine how teams make decisions under pressure - both in implementing preventative measures and during incident response - see the best long-term results. While perfect prevention may be impossible, understanding the human and organizational factors influencing preventative and recovery actions helps build true resilience. Teams that can map out not just what technical controls failed or succeeded but also how and why key decisions were made at each step are best positioned to improve their protective and responsive capabilities. Another surprising element is the power of positive reinforcement in post-mortems. Teams that explicitly document and celebrate what went right – even during serious incidents – tend to see better engagement and more honest reporting in future incidents. This doesn't mean downplaying problems but rather creating a balanced narrative that acknowledges areas for improvement and behavior you want to see again. ## Behavior Change: Beyond Documentation The hardest part of any post-mortem is driving actual organizational behavior change. The most successful teams have learned to treat post-mortem recommendations as product features that must be "sold" to their users. This includes: - Understanding the audience's existing workflows and pain points. - Packaging improvements in ways that solve multiple problems simultaneously. - Creating straightforward success metrics that matter to affected teams. - Building feedback loops to measure the adoption and impact of your recommendations. One effective technique we’ve used is to work backward from the proposed changes to identify potential barriers to adoption. This process helps our clients shape recommendations that are more likely to be implemented and identify the necessary support structures. ## Data Integration and Metrics The most sophisticated organizations treat post-mortem findings as data points in a larger analytical framework. They tag and categorize findings across incidents, creating a searchable knowledge base that helps identify systemic patterns and measure the effectiveness of previous recommendations. BreachRX is a great tool for this. Successful teams also move beyond traditional metrics like time-to-resolve or number of incidents to measure the effectiveness of post-mortem programs. Instead, they track metrics like: - The percentage of recommendations actually implemented after 90 days - The rate of similar incidents in teams that have adopted recommendations versus those that haven't - The time saved in future incident response due to improvements from previous post-mortems ## Influence and Communication The art of the post-mortem lies in influence rather than authority. The most effective IR teams have learned to frame their findings in terms of business enablement rather than security requirements. They show how security improvements can accelerate feature delivery, improve customer satisfaction, or reduce operational overhead. They've also learned to tailor their communication style to different audiences. While engineers might appreciate detailed technical analyses, executive stakeholders need clear business impacts and ROI calculations. Middle managers often respond best to peer comparisons and competitive advantages. # Building for the Future The most mature organizations use post-mortems to drive strategic changes in their approach to security in addition to tactical improvements. They use the findings to inform architecture reviews, guide hiring decisions, and shape vendor relationships. As organizations get better at integrating security thinking into their daily operations, the nature of incidents shifts from major crises to routine course corrections. The full measure of post-mortem success isn't in the quality of the analysis or the comprehensiveness of the recommendations – it's in the gradual but persistent improvement in organizational security posture and response capabilities. The best programs create a culture where learning from incidents becomes as natural as any other business process. Take advantage of each post-mortem as an opportunity for growth rather than just technical problem-solving by focusing on these often overlooked elements. Remember that post-mortems aren’t about closing out incidents – they're about opening up opportunities for continuous improvement. ### Beyond Damage Control: The Science Behind Apologies URL: https://www.discernibleinc.com/beyond-damage-control-the-science-behind-apologies/ Last updated: 2026-07-01T18:02:13.000Z *This shift in mindset – from defending organizational pride to rebuilding stakeholder trust – can help guide more effective incident response.* When your organization suffers a cybersecurity incident, your first instinct might be to minimize the impact, shift blame, or stay quiet. After all, admitting fault can feel like painting a target on your back for regulators, plaintiffs' attorneys, and competitors. However, recent research on the psychology of apologies suggests this defensive stance may do more harm than good – and an excellent corporate communications team that measures the impact of their company’s incident response can tell you the same thing. In a fascinating Hidden Brain [episode](https://hiddenbrain.org/podcast/the-power-of-apologies/?ref=discernibleinc.com), psychologist Tyler Okimoto reveals how our instinct to avoid apologizing often backfires, while thoughtful apologies can help repair damaged relationships and rebuild trust. His findings on why apologies work and fail and how to craft them effectively offer valuable lessons for security leaders and communications professionals navigating an incident. Let's explore how understanding the psychology of "I'm sorry" can help your organization maintain stakeholder trust even during security incidents. ## Understanding Resistance to Apologizing In a previous Discernible [blog post](https://www.discernibleinc.com/meeting-the-moment-the-art-of-apologizing-after-a-cybersecurity-incident/), [Dennis Fisher](https://bsky.app/profile/dennisf.bsky.social?ref=discernibleinc.com) spoke with [Michelle Finneran Dennedy](https://www.linkedin.com/in/michelledennedy/?ref=discernibleinc.com), former Chief Privacy Officer for Cisco and McAfee (now Chief Data Strategy Officer at [Abaxx Technologies](https://www.abaxx.tech/?ref=discernibleinc.com)), [Nick Selby](https://www.linkedin.com/in/nickselby/?ref=discernibleinc.com), former Chief Security Officer at Paxos and former Director of Cyber Intelligence and Investigations at the NYPD (now EVP at [Evertas](https://evertas.com/?ref=discernibleinc.com)), and Discernible CEO Melanie Ensign about some of the primary obstacles organizations face when considering apologizing. Their insights align with psychological research on why both individuals and organizations struggle with genuine apologies. Research shows that our reluctance to apologize stems from deep psychological needs. When we refuse to apologize, we get a short-term boost to our self-esteem and sense of control. For organizations, this often manifests as defensive statements like, "No sensitive data was accessed" or "Our security practices exceed industry standards." Ironically, a strong organizational identity as a security leader can make it even harder to acknowledge vulnerabilities – after all, how could a company that prioritizes security let this happen? But this protective instinct often backfires. Just as BP's CEO Tony Hayward damaged public trust by saying, "I want my life back," during the [Deepwater Horizon crisis](https://www.youtube.com/watch?v=O5treUQL-o0&ref=discernibleinc.com), many executives' instinct to view stakeholder concerns as opposition to their desired reputation often makes the situation worse and works against their credibility. When organizations try to minimize incidents or fumble their response, they risk being perceived as uncaring, untrustworthy, and incompetent. ## Crafting Effective Apologies Okimoto's research also reveals several elements of effective apologies that business leaders and communicators should consider: - **Timing Matters**: While immediate response is important, rushing to apologize before understanding the situation can seem insincere. Instead, acknowledge the incident promptly while explaining that your investigation is ongoing. If you need time to investigate, be transparent about why and how/where you will share updates once available. Also, consider whether there is anything people impacted can do now in the meantime to reduce their risk. Action absorbs anxiety, so if you don’t immediately have all the information people need, give them a productive outlet to work through the uncertainty. - **Focus on the Future**: Emphasize concrete steps you’re taking to support affected parties. Research shows that apologies that focus on future commitments are more effective than those dwelling on past explanations. Your organization’s technical credibility makes promises about future improvements believable rather than empty words. Think of it like a doctor explaining a treatment plan - you're more likely to trust their recommendations when they first demonstrate a deep technical understanding of your condition. Similarly, when an organization shows they thoroughly understand the technical aspects of a security incident, their commitment to prevent future incidents carries more weight. The research on forward-looking apologies becomes especially powerful when paired with technical substance. - **Show Genuine Remorse**: Expressions of authentic concern for affected parties are also crucial for credibility. This means moving beyond formulaic statements to demonstrate a genuine understanding of the incident's impact on stakeholders regardless of fault or root cause. - **Remember Different Audiences**: Different stakeholders – customers, employees, regulators – may need a different type of response. What reassures customers might not address employee concerns, and vice versa. While messages should be tailored to each audience's needs and concerns, they must all align with a single source of truth managed through centralized incident communications. This coordination ensures no stakeholder group receives conflicting information that could damage credibility or create confusion. ## The Bigger Picture Security incidents often symbolize more significant issues around data privacy and corporate responsibility. Organizations must recognize this broader context while managing their response and remember that stakeholders may see the incident as part of systemic issues rather than an isolated event. This "appraisal gap" between how organizations and stakeholders view incidents can complicate your response because stakeholders often want assurance about broader commitments to privacy and security in addition to technical details and specific mitigations. An organization's preexisting reputation acts as a lens through which stakeholders interpret both the incident and the response. Companies with strong track records of transparency and responsible practices typically face less skepticism about their commitments to improve, while those with previous issues may need to work harder to demonstrate credibility and rebuild trust. This is one reason we advocate strongly for proactive security communication programs that can withstand the public scrutiny of an incident. Effective incident response communications are ongoing, knowing that there’s always another incident around the corner. ## Making Apologies Work The most important insight from Okimoto's research might be that effective apologies are not about soliciting forgiveness or even protecting your reputation. Instead, they are the beginning of a process to rebuild trust and demonstrate ongoing improvement. In the context of a security incident, this means: - Starting communication early while being clear about what is known and unknown - Making specific, measurable commitments for improvements - Following through with transparent implementation of those improvements - Maintaining ongoing communication as new information emerges - Demonstrating changed behavior through improved security practices Leaders worried about the business impact of security incidents should approach apologies as relationship repair tools rather than only as a reputation management exercise. This shift in mindset—from defending organizational pride to rebuilding stakeholder trust—can help guide a more effective incident response. It’s not a solo journey, though; coaching cross-functional teams to operate this way—from legal to PR to the C-suite—is one of the most challenging aspects of security communication and a core reason why Discernible exists. ## Looking Forward As security threats and privacy concerns continue to grow, incidents are unfortunately inevitable. What distinguishes organizations is not whether they experience incidents but how they respond when incidents occur. Understanding the psychology of apologies can help business leaders navigate these challenging situations more effectively. Organizations can maintain stakeholder trust in the face of security challenges by acknowledging incidents appropriately, communicating transparently, and focusing on the well-being of their most valuable relationships. The key is remembering that an apology is not a sign of weakness or an admission of complete failure. Instead, it's an opportunity to demonstrate organizational values, rebuild relationships, and emerge stronger through improved security practices. Mastering the art of apologies is now an essential skill for security leadership. --- *Read our customer case study, “*[*Collaborating to Design a Holistic Incident Response Communications Plan*](https://www.discernibleinc.com/customer-case-study-incident-response-comms-plan/)*.”* ### Meeting the Moment: The Art of Apologizing After a Cybersecurity Incident URL: https://www.discernibleinc.com/meeting-the-moment-the-art-of-apologizing-after-a-cybersecurity-incident/ Last updated: 2026-07-01T16:56:34.000Z *By* [*Dennis Fisher*](https://www.linkedin.com/in/dennis-fisher-b027621/?ref=discernibleinc.com) Dealing with a data breach or other cybersecurity incident can be a complex, emotional, and volatile situation. There’s typically lots of finger-pointing and heated conversations, and stress levels go through the roof. Everyone is trying to do their jobs while also being very worried about having a job in the future. None of it is remotely easy. And in a lot of cases, these things play out in public. If the incident becomes public knowledge through a legally required disclosure, a news report, or some other mechanism, the response and remediation processes instantly become much more complex and fraught with potential pitfalls and obstacles. Having customers, regulators, the media, and investors watching every move is not necessarily conducive to calm, measured decision-making, especially when time is of the essence. But while the road to recovery from a security incident can be long and rocky, one part of the process is pretty simple: apologizing. Or at least it should be. But history has shown us that sincere public apologies from breached organizations are vanishingly rare. You’re far more likely to see phrases such as “highly sophisticated attack,” “no evidence this issue has been exploited,” or “we take your security very seriously” than a simple “We’re sorry.” Why is that? Let’s look at some of the main obstacles and see if we can’t figure out how to get around them. ## **Resistance to admitting mistakes** Humans are not good at admitting when we’ve done something wrong. From an early age, we’re conditioned to understand that mistakes (or intentional misbehavior) have consequences and we quickly learn that one way to avoid those consequences is not to admit we did anything wrong. Point the finger at a sibling or the dog or your imaginary friend and maybe you won’t have to sit on the stairs in a time out. Every five-year-old knows this innately, and it can take a long time to unlearn this behavior. But corporations (and government agencies) aren’t five-year-olds, even though they sometimes act like they are, and the people who are responsible for dealing with a security incident often fall back on the old instinct to act publicly as if nothing happened. Getting out of that mindset requires an understanding of what the consequences of admitting a mistake might be. In an enterprise setting, that means doing the homework ahead of time and understanding how your customers, employees, and other stakeholders might react in the event of a breach. ## **Fear of bad publicity** One of the nearly universal short-term effects of a public security incident is negative headlines and online discourse. Cybersecurity in general and data breaches specifically have become major topics not just in the tech press but in the mainstream media, as well, thanks in large part to the ransomware epidemic and a steady stream of massive incidents such as the Office of Personnel Management breach, the SolarWinds intrusion, and the CrowdStrike incident. Though there are many knowledgeable journalists who cover cybersecurity incidents with nuance and context, you don’t have to look very hard to find breathless, apocalyptic headlines about relatively minor incidents. PR teams are paid to avoid or limit negative headlines, and issuing a public apology is too often seen as an express route to bad publicity. But a security incident will generate news stories regardless of whether the organization issues an apology. That’s how news works. However, the public’s attention span grows shorter by the day, and the sheer volume of security incidents virtually guarantees that there will be another one to replace yours in the news in a matter of days, if not hours. Making a public apology won’t prevent the media from covering a breach, but it can show stakeholders that the organization understands the gravity of the situation and is trying to remedy it. Ideally, communications teams should measure the effects of the statements they put out on the way that customers and other constituencies perceive their brand. “I would think based on my experience that the fact that it's going to be publicized is exactly when you want to be seen telling the truth and doing the right thing, but that is not how it works,” says [Nick Selby](https://www.linkedin.com/in/nickselby/?ref=discernibleinc.com), a longtime security executive currently Executive Vice President at [Evertas](https://evertas.com/?ref=discernibleinc.com). Discernible CEO Melanie Ensign also reminds organizations that security incidents are “an opportunity to demonstrate what you’re truly made of and actually *build* trust with stakeholders.” ## **Legal liability** This is the big one. If you think PR teams are paranoid, lawyers make them look positively carefree. The advent of state data breach notification laws in the 2000s provided the public--and plaintiffs’ attorneys--with the first real ammunition for what has become an ever-growing wave of lawsuits against companies hit by data breaches and other incidents. Those suits can be quite expensive, as can government investigations. In 2019, Equifax agreed to a $575 million settlement with the FTC and other government agencies related to a massive data breach in 2017 that affected 147 million people. That’s obviously an outlier, but legal action follows data breaches as day follows night. But the potential for a lawsuit should not be a deciding factor in whether an organization formally apologizes for an incident. The lawsuits will likely come either way, and customers are more apt to feel positively about a company that communicates its remorse and intentions going forward rather than one that deflects, denies, and dissembles. “It’s not always easy to quantifiably prove that people feel better when they get an apology,” says Selby, “but it’s anecdotally clear that they do. And there is research from other fields like healthcare suggesting the ultimate outcome of serious mistakes is improved with apologies,” says Selby, citing a 2023 article published in the [Amsterdam Law Forum](https://amsterdamlawforum.org/articles/10.37974/ALF.475?ref=discernibleinc.com). “In at least one[ incident](https://www.timehop.com/security?ref=discernibleinc.com) I’ve spoken about before, the apology absolutely helped, the users accepted it, and the company thrived post-incident.“ Ultimately, lawyers and government regulators are going to do what they’re paid or legally required to do, and being sorry in public isn’t going to suddenly spur any of them into an action they weren’t already contemplating. To paraphrase a legendary security paper, if the Department of Justice (or FTC or SEC) is your adversary, you’re gonna get got and there’s nothing you can do about it. Ensign says many companies who approach security and incident communications as a purely CYA exercise or crisis management often miss the ongoing relationship between regulators’ opinions of a company’s security and non-security issues. Having led security communications programs at global regulators’ favorite targets, including Uber and Facebook, she says, “The way external stakeholders perceive your response to security incidents is absolutely influenced by their overall feelings about your brand. So, building a resilient reputation with effective and compassionate security communications starts long before an incident occurs.” From a litigation perspective, [Michelle Finneran Dennedy](https://www.linkedin.com/in/michelledennedy/?ref=discernibleinc.com), Chief Data Strategy Officer at [Abaxx Technologies](https://www.abaxx.tech/?ref=discernibleinc.com) and former Chief Privacy Officer at Cisco and McAfee, says the indicators of success have changed. “Do we get sued? That measurement needs to come off the table. The metric is now how quickly can I make this end at summary judgment? That's a very specific thing,” she says. “If you're afraid of discovery in a fictitious lawsuit, then you don't have reliable data with which to operate and manage your business.” And if that’s the case, you have many other problems, and hiding behind a legal team won’t solve them. Be honest, forthright, and contrite; good things will follow. Or don’t, and see how that works out for you. ### CUSTOMER CASE STUDY: Cisco Secure URL: https://www.discernibleinc.com/customer-case-study-cisco-secure/ Last updated: 2026-07-01T00:39:15.000Z ## How Discernible Enabled Cisco’s Emerging Security Leaders to Level Up Organizational Communications If you ask 100 people what a CISO prioritizes most when hiring new talent, you might hear them say technical skills or experience in a specific security domain. However, increasingly, there is another top priority on that list: communication skills, often called “soft skills,” which now ranks high on a CISO’s priority list. This trend is particularly prevalent in large, complex enterprises where security teams must work across, up, down, and sideways across organizations to do their job and gain support and influence for security within the company. Experienced CISO Josh Yavor knows this firsthand. “There is an intersectionality between getting stuff done in a corporation and communication and trust. To get people to trust you, you must communicate effectively. It's a huge part of getting things done!” However, finding talent with these subtle yet impactful communications skills isn’t always easy. “It's usually easier to find the technical skills your team needs compared to finding folks who have the communication skills that are increasingly necessary, especially in a large, global organization,” he told Discernible. ## The Challenge In his former role as the Chief Information Security Officer for Cisco Secure, Yavor was responsible for a large, growing team. With a balance of established and newer leaders in this group, he understood that effective communication skills would be vital to ensure his direct reports were successful as they navigated significant organizational change. He’d seen the difference a proactive communication program makes while working with Discernible CEO Melanie Ensign in her previous security communications role at Facebook, where Yavor led the corporate security team. So, rather than wait for the inevitable stumbling blocks to present themselves, Yavor proactively engaged with Discernible to provide strategic communications analysis, training, and professional development for his new and expanding leadership team. Like many security leaders, the leaders on Yavor’s team faced an aggressive schedule of deliverables across a large and complex set of stakeholders within the business group. The team needed to deliver on requirements to improve the security of the Cisco Secure products while also enabling accelerated global growth. “I realized that what my team needed was more than I could deliver individually through personal coaching on its own,” he recalls. “We were a globally distributed team with folks working in an office while others worked remotely. We had people in large established Cisco offices and others in much smaller offices tied to previous acquisitions.” Yavor’s team included the security team from Duo Security and was growing to expand service offerings to all business groups within Cisco Secure. They focused on strengthening their leadership team’s communication strategies and methods with customers and internal Cisco stakeholders to meet this goal. The varying cultures, locations, skill sets, and appetite for professional development meant that an objective expert with deep experience in security was essential to uplevel communications skills across these disparate employees in a manner that meets them where they are. “Thegoal was quite simple: to level up everyone individually to where they needed to be,” he said. After evaluating numerous consultants, Yavor selected Discernible because of Melanie’s experience in security communications and her flexible approach. “I knew Melanie could be a partner in assessing each individual’s needs and doing that in a way that removed biases on my part,” Yavor said. “That and she is a security professional who knows how to uncover and prioritize areas of opportunity for development.” ## Solution Discernible took a multi-phased approach with the Cisco team, beginning with creating a needs assessment with Yavor and his Chief of Staff to identify key communication challenges within the team. Then, they developed a plan for prioritizing, disrupting, and replacing unproductive communication patterns. The plan included tactical details for managers and ICs, program timelines and milestones, and a methodology for measuring progress and impact. Discernible also analyzed communication styles and information processing methods across the team, then coached team leads to develop individualized communication plans tailored to their business goals. Yavor recalls a particular aspect of Discernible’s work that was helpful, given how busy his team was**.** “Melanie sought out those opportunities to say, ‘Hey, what are you working on right now? What communication do you need to get out? What is working well, what are you struggling with?’ And she would engage with coaching on specific, real-world deliverables to make the whole process effective.” Before working with Discernible, some team members struggled with how to prioritize and effectively use the myriad of communication channels that had been growing over time through numerous acquisitions and the accumulation of various IT collaboration systems. Assumptions had been made at the individual level about which tools were best for which kind of communication, and almost everyone reported feeling anxious about choosing the right tool and the expectation that they frequently check at least half a dozen different communication platforms daily. Discernible worked with one of Yavor’s teams to develop a playbook for effectively using various communication tools, including a list of platforms they were no longer expected to rely on and SLAs and best practices for the handful of tools the team continued to rely on. Additionally, Discernible developed a customized playbook for CISO and Chief of Staff communications to help the leadership team participate in, socialize, and support future communication plans across the organization. Through listening sessions and private coaching, Discernible created a roadmap for team leads to articulate and recognize how IC contributions connected to the team’s charter. ## Results Yavor’s objective with the Discernible engagement was to increase the quality and consistency of achieving their security goals by ensuring his leaders had the best skill set possible to work with their teams and stakeholders. “Melanie provided the right balance of structure for predictability with an expectation of customization and tailoring as appropriate for the individual goals we wanted to achieve.” Yavor points out that most security leaders have a budget for annual professional development training, but often these funds are used for “canned solutions” or conference fees. “What Discernible offered made it easy for me to communicate the benefits of this type of customized solution to the parties I was accountable to,” he notes. Yavor believes that by working with Discernible, he himself learned a great deal about “how to best support the organization and my leaders, who were accountable for delivering against strategic goals across the company on a day-to-day basis.” Yavor recently ran into one of his former direct reports who received communications coaching from Melanie. He recalled, “She shared that she still uses those skills in her career today and that it was one of the best professional development experiences she ever had.” ### Maintaining Composure: Effective Emotional Regulation in Security Incident Response URL: https://www.discernibleinc.com/maintaining-composure-effective-emotional-regulation-in-security-incident-response/ Last updated: 2026-07-01T16:53:32.000Z Emotional regulation, a crucial skill in the cybersecurity field, is the ability to manage and respond to emotional experiences in a healthy and effective manner. It involves recognizing emotions, understanding their triggers, and employing strategies to cope with and express these feelings constructively. This skill enables individuals to maintain a balanced emotional state, even in challenging situations, and empowers us to exercise discipline and self-restraint in pursuing our goals. The ability to remain calm and composed during an incident response is critical to a successful recovery. Yet, it’s challenging to do in practice if you’re unprepared. Written plans and procedures are great (and necessary for compliance). Still, execution is the hardest part, where human emotions often get the better of security teams and their partners across the business. Allowing organizations to accept all security incidents as “crises” by default excuses chaos. Are they stressful? Sure. Embarrassing? Sometimes. But in my experience, it’s not a crisis until or unless you mess up the response. Our network engineering, SRE, and infrastructure colleagues don’t panic every time something goes wrong – they plan for it in staffing, tooling, and failsafe procedures under the daily pressure of keeping services online. They understand most of the internet is held together with duct tact and chewing gum, and they’re under no delusion that a month of games and guest speakers once a year will change company culture. Perhaps this is why many of them are excellent security and privacy engineers. Imagine a scuba diver at depth, exploring a colorful reef, abandoned shipwreck, or underwater cave. Suddenly, equipment failure occurs, or they lose sight of their dive buddy. Panic can lead to rapid breathing, increased air consumption, and potentially fatal mistakes. The diver must instead rely on training, regulate their emotions, and execute a well-rehearsed plan to safely resolve the situation, often when ascending to the surface is not an option. Even at the most fundamental levels of training, we teach new divers how to safely navigate situations that might appear quite serious to an untrained observer – things like running out of breathing air or experiencing [nitrogen narcosis](https://en.wikipedia.org/wiki/Nitrogen%5Fnarcosis?ref=discernibleinc.com). If you know how to handle these situations properly, they never escalate to a crisis level. Similarly, the immediate response can dictate the overall impact when a cybersecurity incident occurs—whether it's an accidental data leak, responsible disclosure debate, crypto heist, or supply chain attack. A panicked engineer or executive is equally capable of making hasty decisions that exacerbate the issue. Conversely, one who remains calm can methodically assess the situation, coordinate with the incident response team, and implement an effective strategy to minimize impact. In many cases, incidents are valuable opportunities to reinforce company values and build stakeholder trust. The principles for incident response in cybersecurity are strikingly similar to the lessons taught in scuba diving. Executives must manage their stress and emotions to lead their teams effectively. Here are some recommendations for cultivating emotional regulation and self-restraint during cybersecurity incidents: 1. **Preparation and Training**: Conduct incident response drills to ensure that all team members, including executives, are familiar with protocols and can perform under pressure. Decide as an organization in advance the values and characteristics you want to exemplify during an incident. This helps eliminate conflicts between functions and individuals about the level of transparency, empathy, and accountability expected during decision-making. Training should also include stress management techniques. The best way to ensure everyone practices the procedures frequently is to align your IR plans with daily operations. For example, the process for developing and publishing security content on your website should include the same technical, communications, business, and legal experts who would review public statements about an incident because it impacts the same stakeholders. Form the cross-functional relationships and use the appropriate tooling now so that everyday operations reinforce your IR procedures. Familiarity also reduces emotional and cognitive pressure when it matters most. 2. **Mindfulness and Stress Management**: Incorporate mindfulness practices such as meditation, deep breathing exercises, or even physical activity into your routine. These practices can enhance your ability to stay calm and focused during high-stress situations. It’s not uncommon for me to ask someone to walk around the block before joining a call or meeting to help them focus on the task at hand. In scuba diving, avoiding panic is critical for conserving breathing air, but also to help you think clearly when you’re (literally) under pressure. Likewise, in security, if your hair is on fire, it’s easy to misuse resources or make mistakes in judgment. I’m a big fan of 1-3 minute meditations before crucial conversations to ensure my emotions don’t hijack my goals. 3. **Clear Communication**: Develop a communication plan that outlines how information is disseminated during an incident – not just publicly but also inside your organization. If your lead attorney or customer support director is on vacation, does the security team know who to contact next? Does that individual already know the plan because it’s detailed and not a generic checkbox for compliance, or do we have to get them up to speed while also hoping their unfamiliarity with the process and subject matter doesn’t throw a wrench in the organization’s ability to respond quickly and inline with its values? Clear, composed communication about roles and responsibilities and the state of an investigation can prevent misinformation and ensure everyone is on the same page. 4. **Support System**: Build a support network of trusted colleagues, mentors, and mental health professionals. Having someone to talk to can help process emotions and maintain perspective. You don’t need to disclose nitty-gritty details of an incident to find understanding from someone who cares about you, who can help lighten the mood, or cover other responsibilities while you temporarily focus on the incident. I wrote previously about [relational sources of resilience](https://www.discernibleinc.com/resilience-is-a-team-sport-chief-security-officers-must-learn-how-to-coach/) based on an excellent article from *Harvard Business Review.* Paying attention to these relationships now is an investment in your mental health and professional development — don’t wait for an employer to do this for you, or you’ll be waiting forever. 5. **After-Action Reviews**: Conduct thorough reviews after each incident to identify what went well and what could be improved. Use these insights to refine your incident response plan, enhance your team's preparedness, and improve your daily operations. If something isn’t working in your IR procedures, it likely isn’t working when you’re not under pressure, either. The relationships, tools, and protocols we can use during an incident are shaped by the ones we exercise daily. The ability to regulate emotions and exercise self-restraint is crucial for incident response. Just as scuba divers rely on these qualities to navigate emergencies, cybersecurity professionals must do the same to protect their organizations from unforced errors. By fostering these skills, executives can lead their teams with confidence and resilience, ensuring a robust and effective response – and recovery. ### Empowering Business Leaders to be Savable Victims: Drawing Incident Response Insights from Rescue Scuba Diving URL: https://www.discernibleinc.com/empowering-business-leaders-to-be-savable-victims-drawing-incident-response-insights-from-rescue-scuba-diving/ Last updated: 2026-07-01T16:45:53.000Z Training to become a rescue scuba diver is not just about learning how to save others; it’s also about understanding how to be a “savable victim.” In the context of cybersecurity, a savable victim is someone who, in the event of a security incident, understands their role and responsibilities, communicates effectively, and remains calm under pressure. As a victim, trusting your rescuer and following their instructions can make the difference between a successful rescue and a dire outcome. My experience in cybersecurity incident response and rescue scuba diving taught me the importance of proficient rescuers and cooperative victims. One of the first lessons taught in rescue diver training courses is the importance of self-awareness. As a diver, recognizing your own limits is essential for preventing accidents. By understanding your physical and mental boundaries, you can avoid putting yourself in situations that may require someone to rescue you. Accurate self-awareness also makes you a more reliable victim because you can communicate your state and needs to your rescuer. In the same way, business executives experiencing a cybersecurity incident should have a keen sense of self-awareness. Understanding the extent of their knowledge and expertise in handling such situations can help them make informed decisions based on technical realities. CISOs often need help articulating this, but many of their executive leadership teams make it difficult for the organization to respond well to security incidents. Essentially, they’re uncooperative victims. Poor planning (if at all), underinvestment, and real-time disruptions during an investigation, such as changing the course of action without consulting the CISO or interfering with the work of the response team, are symptoms that your executive team doesn’t understand how they can be most effective during an incident (or why they should). At Discernible, we don’t just include executives in tabletops — we strengthen the relationships between security and business leaders so that when sh\*t hits the fan, senior management has enough confidence in their CISO to not get in the way of response or recovery. They need to know what to do, when to do it, and when to stop – and most importantly, they must commit to their role and responsibilities in advance. ## What does a savable victim look like? Below are several common characteristics and traits that, when missing in executives, make it difficult for security teams to provide the necessary support and intervention. #### **Effective Communication** Effective communication underwater can be challenging, but it is a vital skill taught in every diving course, no matter how advanced your training. By mastering hand signals, body language, and communication devices, divers in trouble can convey critical information to their dive buddy or rescuer. When a diver can signal distress or provide details about your condition, it can significantly improve the chances of a successful rescue. In cybersecurity, effective communication among team members, including senior management, is crucial for a prompt response and resolution of incidents. Business executives must foster a culture of open communication about security within their organizations, ensuring everyone – including themselves – knows how to speak about risk without fear-mongering, denial, or contempt. #### **Calmness Under Pressure** Panic is one of the most dangerous reactions in an emergency, both for the victim and the rescuer. It can exacerbate the problem and put the rescuer and the victim at greater risk. Rescue diver training emphasizes the importance of staying calm under pressure because we need to think clearly to assess the situation and regulate our physiological reactions. By practicing simulated rescue scenarios, you learn to manage your anxiety and maintain composure. As a victim, staying calm allows rescuers to assist you more effectively and reduces the risk of further complications. Similarly, executives must maintain their composure during a security incident to lead their teams through the incident response process. A common source of panic during security incidents is well-intentioned leaders who either don’t know their roles and responsibilities before a security incident occurs or lack the discipline to follow through on the plan. Executives who fly by the seat of their pants or create disruptions during an investigation, even if they intend to be helpful, create chaos for the response team and external stakeholders. Because most executives don’t advance into leadership roles by sitting still and respecting boundaries, doing so during a security incident can feel foreign and uncomfortable. They need to be trained, like the U.S. Navy SEALs, to “embrace the suck" with predetermined and practiced actions that are helpful to the process. Giving executives something productive to do helps keep them calm, which allows everyone to think strategically, prioritize actions, and communicate effectively, thereby minimizing the impact and steering the organization toward recovery. #### **Insight into Rescue Techniques** Understanding rescue techniques from a rescuer’s perspective gives you valuable insight into the most helpful actions for your rescue. In scuba diving, you learn how to position your body to assist in a lift or conserve energy while waiting for help. This knowledge makes you a more cooperative and manageable victim, facilitating a smoother rescue process. Rescue divers repeatedly practice emergency scenarios to build muscle memory and ensure our responses are automatic and efficient. Just as important is diving frequently without a scenario to keep our observation skills sharp and to practice executing safe dives. Ironically, routine non-emergency protocols are missing in many security incident response plans, and it is as if we don’t expect executives or cross-functional partners to know how things work when there isn’t an incident. Indeed, regular cybersecurity training and simulated attack exercises can significantly enhance an organization’s readiness to handle actual incidents. Still, the best thing an organization can do to prepare for a security incident is to establish and document decision-making procedures for day-to-day risk acceptance, mitigation, and communication so that everyone you will need to make these decisions during an emergency will already know each other, trust each other, and be proficient in acting quickly together. A non-incident can become an incident in the blink of an eye, so the more your day-to-day operations incorporate the same people/teams from your incident response plan, the better your chance of a successful rescue. Training as a rescue scuba diver goes beyond the skills of saving others; it equips you with the knowledge and composure to be a savable and helpful victim. By understanding the intricacies of rescue operations, maintaining calmness, and communicating effectively, you enhance your safety and those around you. Whether you’re the rescuer or the one needing rescue, these skills ensure that every dive is a safe and enjoyable experience. Imagine if CISOs knew how to teach their executive team to be more helpful, cooperative, and savable victims. That’s why we’re here! ### 📬 Mailbag: How do you regain trust after an initial communications misstep? URL: https://www.discernibleinc.com/mailbag-how-do-you-regain-trust-after-an-initial-communications-misstep/ Last updated: 2026-07-01T04:40:41.000Z *Mailbag questions are submitted by our readers. You can submit questions for our team to address in a future post at discernibleinc.com/contact.* Whether it's a poorly timed announcement, an ill-considered tweet, or a misinterpreted internal message, the key to recovery lies in how you handle the aftermath. Here are a few recommendations on how to navigate your way back from a communications misstep. **1\. Acknowledge the Mistake** The first and most crucial step is to acknowledge what you got wrong—and be specific. You are responsible for gaps between your intended message and the one your audience hears. Did you miss something in your evaluation of the wording, timing, messenger, channel, or other context impacting how your audience interpreted your message? Own up to the mistake immediately to prevent further damage and commit to realistic improvements. Show you are aware of your mistake and are taking it seriously. Vague promises will not help you here. A sincere apology can go a long way in mending trust. Remember, honesty fosters credibility. **2\. Consider Whether You Have the Right Messenger** Once the mistake is acknowledged, it's important to consider who will deliver the follow-up message. The right messenger can significantly affect how different audiences receive your apology and subsequent communications. Choose someone who is trustworthy, empathetic, and has a good rapport with your audience. This person should be able to convey sincerity and take responsibility on behalf of the organization. If the communication misstep occurred in a 1:1 interaction, you should apologize directly using language and tone that demonstrate these values. **3\. Get Closer to Your Audience** Understanding your audience's concerns and perspectives is essential, including actively participating in conversations on issues that matter to them. Corporate statements issued through mass media persuade few people. They appreciate it when leaders speak directly to them using channels they already trust, like giving an interview to their favorite podcast or newsletter–the niche audience is what gives it credibility. The closer you get to your audience, the more authentic your message comes across and the stronger your connection with the audience. When you need to apologize, people need to feel like you’re talking to them, not simply issuing a blanket statement. **4\. Be Humble and Helpful** Approach the situation with humility. Avoid being defensive or dismissive. Instead, show empathy and a genuine willingness to learn from the mistake (this is why specificity in your acknowledgment is critical). Offer solutions or actions that you are taking to prevent similar errors in the future. Providing helpful information or resources can also demonstrate your commitment to improvement and that you trust your audience with what you know. Trust is a two-way street. If your audience feels you’re holding back, they will, too. **5\. Don’t Stop Communicating** Continuous communication is vital. Don’t go silent after issuing an apology. Keep your audience informed about the steps you are taking to rectify the situation and transition from reactive to proactive communication. Regular and ongoing communication helps maintain trust and shows that you are actively working on improvements. Consistent, honest communication can turn a negative experience into an opportunity for growth and stronger connections. Recovering from a communications misstep is challenging but possible. You can restore trust and credibility by acknowledging the mistake, choosing the right messenger, getting closer to your audience, being humble and helpful, and maintaining open lines of communication. Mistakes are a part of growth, and how you handle them can define your organization’s integrity and resilience. ### Building Trust Between Security and its Peers URL: https://www.discernibleinc.com/building-trust-between-security-and-its-peers/ Last updated: 2026-07-29T21:38:54.000Z *Q&A with psychiatrist Dr. Ryan K. Louie, cybersecurity trust and compliance expert Kim Burton, and Discernible CEO Melanie Ensign* Trust is critical for collaboration. Effective cybersecurity programs rely on seamless communication and cooperation across the organization. Without trust, information sharing becomes limited, hindering the ability to detect and respond to security issues appropriately. Building trust between cybersecurity professionals and cross-functional colleagues ultimately leads to better security outcomes. We asked two trust experts, Dr. Ryan K. Louie and Kim Burton, to join CEO Melanie Ensign for a discussion on how security teams can develop deeper trust with their partners in the business. --- #### We often have to make quick decisions in cybersecurity. How does trust between security teams and our cross-functional partners impact how information and risk assessments are processed? How can we teach security practitioners to be trusted partners? **Kim:** Trust is necessary for security teams and cross-functional partners to make responsible quick decisions. Partners who do not trust the security team may believe their team’s priorities were not understood or that security’s analysis is suspect. They may ignore the information they receive from security teams entirely. Teams fail to communicate, falling into micromanaging, duplicate work, inefficiency, and distraction. Trust is built over time through competence, benevolence, and integrity. This starts with showing partners that you understand their unique pressures, how they operate, and why before we require them to make changes. Then, as we move into business conversations, assume that others are doing their best with the resources they have and their current understanding of business priorities. Take the time to learn another team’s workflow and role requirements – this will help you build trust as you teach the business about evaluating risk. If you’re interested in this topic, I suggest reading *Move Fast and Fix Things: The Trusted Leader's Guide to Solving Hard Problems* by Frances Frei and Anne Morris. **Ryan:** Trust takes a long time to build, and some of the most effective teams are the result of members who have known each other and worked with each other for quite a while. They are familiar with each other and importantly, can exchange thoughts, ideas, and viewpoints in a very open and candid manner. There is psychological safety, and people feel comfortable speaking up and expressing opposing viewpoints. This type of conversation and 2-way dialogue to evaluate situations when time, resources, and available information are limited is a key factor for teams to be successful. While trust over time would be ideal, there is not always that opportunity for time and team-building for all teams. In the shorter term, trust can be built by establishing a culture at the beginning of any project or endeavor that promotes listening, respect, and empathy. The focus is not just acceptance of different ideas and viewpoints, but for those elements to be treated as milestones and actual performance measures. That way, the culture becomes expected, and that helps pave the way for conversations and discussions during high-stress situations. Cross-functional partners and security teams will be able to understand, know about, and appreciate the work of one another. And team members will be base-level fluent in fundamental concepts of each field. **Melanie:** Both of your answers remind me of how important it is for leaders to build trust in the decision-making process, especially when the stakes are high or we don’t know each other well. I see security teams create charters or mission statements intended to describe the vision and expectations of the team – but they don’t provide any guidance to their team members about how to incorporate those values and responsibilities into their decision-making. For example, if you want your security team to have a reputation for being a trusted business advisor, then you better teach everyone what that looks like in how they interact and communicate with each other and their peers. How do we build tools and protocols as a team of trusted advisors? How do we plan our security roadmap as a trusted advisor to the business? How would a trusted advisor request things they need from the business? *(Spoiler: you offer to help them first!).* When people are under pressure and time is of the essence, a trusted process can unite different departments and perspectives because you’re already aligned on the values and principles that will be prioritized throughout. This is particularly important during incident response because arguments over whether or not honesty with customers supersedes potential litigation risk should be put to bed long before public statements are underway. Commit to your values in advance and help the business navigate the risk required to live them. #### Different ways of presenting information, such as visual maps vs textual data, can influence cognitive processing. Does this impact how trust is built between security teams and their colleagues? **Ryan:** Different people will be receptive to information presented in various ways. The trust built between security teams and their colleagues helps them understand the information. The trust will come from the generosity and kindness of people taking the time to explain and translate the meaning and significance of the information to those who might be used to seeing it presented differently. The result is a team fluent in multiple ways of sharing and receiving information. This builds strength and trust further by the team’s ability to see any pitfalls or if pieces are missing from the information set, and to look out for one another by sharing opinions and insights about it. **Kim:** Receiving information in multiple different ways can help people to process and understand the information. When we see something new it can be difficult for the learner to immediately apply the content – they need personal process time to identify how the material relates to them individually. Different people may prefer one kind of presentation over another and so they’ll pay more attention if they resonate with how something is presented *(This is distinct from “learning styles” which has no basis in research and is a troublesome myth about how learning works)*. We should not forget that our colleagues also have accessibility needs from dyslexia, auditory processing disorder (APD), and other differences in information ingestion, as well as different experiences and practical expertise. This means that presenting material multiple times in multiple ways gives team members the ability to ingest content that they can then process internally, coming to an early understanding of the material, and then they may re-encounter it in a different way to understand the nuances and further implications. To have these multiple forms available means people can bring all of their aptitudes to bear, fully integrating the content into their brains. This is called “multimodal learning” – a method that engages multiple sensory systems simultaneously for best absorption. Security teams that provide multiple ways of encountering important information increase trust through: 1. **Familiarity** – colleagues will see the security team and the names of its members more often in positive settings, and this familiarity opens the door to trust 2. **Empathy** – show your colleagues that the security team cares about them and the business. This is demonstrated by your continued effort to engage through different content formats and communication channels. As I mentioned above, empathy is a key pillar of building trust. 3. **Accessibility** – busy, distracted team members, neurodivergent teammates, and those with learning disabilities deserve to see themselves represented in the content’s presentation and to know that it’s “for them” – again, increasing the perception of the security teams’ altruism (“They care about me, they see me”) This kind of trust results in 1) partners believing that the security team has made the risk clear to them, 2) they understand what we’re telling/showing them, and 3) they believe in our competence to help them. A good resource for this topic is: *Make it Stick: The Science of Successful Learning* by Peter C. Brown. **Melanie:** It’s hard to build trust when people feel confused or excluded. Kim’s advice is important for avoiding those situations. I also like Ryan’s point about generosity and kindness as the message sender, particularly because trust encourages reciprocity. The message and its delivery are equally important in getting your point across and fostering relationships that can withstand occasional misunderstandings or mistakes. If you haven’t earned the benefit of the doubt, you haven’t truly earned trust. #### Security professionals sometimes need to tell a colleague that the product or feature they’re building is insecure and needs to be fixed. How can security teams use these conversations as opportunities to build trust with cross-functional colleagues? **Kim:** Ideally, security teams have a foundation of trusted partnerships before they begin to criticize or correct products and features. Of course, sometimes there is not enough time for this development to take place. So, in all circumstances, communicate the work that needs to be done respectfully, and in a way that does not personalize or blame specific teams or individuals. If someone perceives a feature as “their baby” – having invested their time, energy, and passion, and have become personally attached to it – they are more likely to perceive questions or criticisms as a threat. Ideally, one would learn to separate a project from themselves, to stop seeing comments on their work as comments on their value and self-worth. This separation allows people to be more open to collaborative projects and welcome what the security team brings to the project. The security team’s input was always going to be a natural part of what a project requires to become “done.” The security team can frame what they do (identify vulnerabilities or risks) as a natural part of the build process. **Ryan:** People can naturally feel threatened, anxious, or emotional when others point out things that need to be fixed, features that are not secure, or negative feedback. The key to building trust is to establish the culture and norms of an organization, at the very beginning of anything new that is started. The building of psychological safety into the foundation and framework of any new project, so that everyone knows that this is the standard, will help lessen the impact of negative feelings during hard conversations. If everyone across all levels of an organization routinely and genuinely practices the giving and the receiving of candid information and comments, then it becomes more accepted and ideally will be promoted and championed as the mindset that is honored. **Melanie:** *See my comments above regarding building trust in the decision-making process!* #### How does helping others accomplish their goals impact security’s ability to influence business decisions? **Ryan:** I think back to Professor Robert Cialdini’s 6 principles of influence. We often hear about these in the context of social engineering and the connotation is negative. However, if the principles of influence were applied positively and kindly, to uplift and support others, then this can be a very powerful method of change for both the provider and the receiver of influence. There will be a new level of understanding and trust between people, to know that they are being guided by people that they feel are important to them and in a way that feels right for them. Influence, like technology and innovations, has an upside and a downside. The key to navigating this is to be aware of when influence occurs, how it’s affecting someone, and how it makes them feel. Then they can decide the best course of action. **Kim:** Security professionals should consider understanding the motivations behind their own behavior before trying to influence others. I would not trust the motivation of the security team nor the outcomes before this personal work is done. A personal understanding of one’s motivations can reveal areas where challenging one’s assumptions or a change in relating to others is needed. The security profession often requires people to approach others when fear is at the forefront and psychological safety is challenged. Security teams must respect this reality and respond with compassion; no one wants to feel threatened by or afraid of the people who are supposed to protect and support them through a vulnerable time. People have many different motivations for what they do, but everyone has some kind of goal or desire or something they’re trying to avoid. Security teams frequently rely on negative motivators, like fear or punishment, which can be effective in the short term but come at the cost of trust. Trust naturally allows security teams to influence their peers and they can do this with positive motivators like connecting requirements to professional growth, providing recognition for exemplary work, demonstrating how security contributes to the business community, reminding people of values they hold that resonate with security concepts, or connecting security needs directly to the company’s vision. Using a variety of positive motivators will create a culture that influences many different kinds of people and lets them see themselves represented in the security team’s vision for the company. **Melanie:** Sometimes security professionals focus too much on why *they* do security things and expect everyone else to do it for the same reasons, instead of considering what’s already important to them and doing the work to show that certain security choices can help them accomplish those things. Religious conversions are not necessary to get people into a church. Sometimes a potluck will do. ### Is Your Security or Engineering Team ready for a Chief of Staff? URL: https://www.discernibleinc.com/is-your-security-or-engineering-team-ready-for-a-chief-of-staff/ Last updated: 2026-07-01T16:33:47.000Z *Advice from a CISO Chief of Staff on how to know when the time is right and how to find the right one.* By Jessica Walters, Discernible Advisory Board Member and former Chief of Staff to the CISO of Cisco’s Security Business Group --- Bringing on a Chief of Staff to help supercharge your team’s cross-organizational impact and influence is a trend that has picked up momentum in the last few years and isn’t slowing down anytime soon. And while I love the excitement surrounding the Chief of Staff role, there’s more to the decision of when to bring on an individual with these superpowers. It’s a decision that leaders often neglect until they can no longer ignore the symptoms of a dysfunctional working environment or their organization reaches what they think is the ideal size. To get the most out of this role, it should be a proactive decision rather than a reactive one. First and foremost, you can’t just throw anyone into the mix and have the magic work! Chiefs of Staff have different areas of expertise, strengths, and expectations of the leaders they work with. They should be someone you feel comfortable giving the reins of your most strategic programs and confident in covering for you in a pinch. Getting the right match for you and your organization is key, so take the time to understand what you need ahead of hiring! When the fit is right, the magic works, and I call this “well-matched.” Here are a few key indicators that your Security or Engineering organization might be ready for this critical investment: **You are getting ready to navigate a period of significant change or growth** With periods of significant change or hypergrowth come great amounts of ambiguity and uncertainty. A well-matched Chief of Staff can serve as a powerful stabilizer for your team through the waves of uncertainty that technical teams experience under these circumstances. Why, you ask? Chiefs of Staff should be catalysts for trust within your organization, building strong relationships with your individual contributors over time and opening up the door for transparency in communication. Sure, C-level leaders and strong first and second-line managers should also be a source of trusted support. But it’s the Chief of Staff role that is able to keep a pulse across the breadth of your entire organization from multiple angles if positioned correctly, including how those leaders you’re also relying on are *really* doing. It’s common for teams to realize a need for this stabilization only after significant changes or growth has started, making it a more challenging situation for a Chief of Staff to join and navigate (if there’s even any budget left for such a role in the team’s growth plan!). **Your team identity is unclear and needs attention** Creating a team culture that people are proud to be a part of should be at the top of the priority list for technical leaders, but quite often the roles critical to nurturing team cohesion are deprioritized to make way for technical talent. While that’s understandable, hiring great engineers and knowledgeable infosec team members is not enough. Building a cohesive and sustainable team identity requires a great deal of investment and time that only “glue roles” can provide to your organization (IE: Chiefs of Staff, Program Managers, Technical Program Managers, etc). Investing in a well-matched Chief of Staff can quite literally ‘glue’ your teams together by helping translate your vision into a powerful, motivating, and consistent message that is reflected throughout all facets of your organizational operations. How you talk about that vision, how you celebrate your work towards that vision, and how your team thinks about that vision when they’re doing their daily work are all influenced by the programs your Chief of Staff can build and lead for you. **You need to break down working silos within or across teams** The dreaded enemy of all teams…. information silos. All organizations experience some level of siloing, whether within a team or across teams. While there are hundreds of tactical ways to break down such silos, at the root of all effective approaches is the importance of intentional and strategic communications. Leveraging a Chief of Staff as your trusted air traffic controller for all things communication within your leadership team and across your organization can drive clarity and consistency. A well-matched Chief of Staff can ensure you build the most effective communication infrastructure by taking into account the many perspectives within your organization, where those most frequently intersect, and how to systematically unblock information in critical areas. Additionally, a strong Chief of Staff can leverage their relationship-building superpowers to unlock communication gaps with key partners across the business. When your critical partners have high confidence in your Chief of Staff they also develop trust in you as a leader and the guess work in how to engage with your organization effectively is removed. **You are building a team in an already-established organization** If your team is in startup mode, building from the ground up trying to catch up with the rest of your organization, bringing on a well-matched Chief of Staff can significantly multiply your ability to grow quickly and start making a meaningful impact. Your Chief of Staff should serve as an extension of you as an executive leader, allowing you to divide and conquer quickly as you set up new working patterns within your organization and develop and refine your priorities during information gathering. They can also ensure others fully understand your team vision and charter while just generally accelerating trust in the team you’re building through their intersection with other leaders and individuals. Bringing on this partner early to co-pilot this journey will allow them to be part of the strategy-building process where they can predict challenges, identify risks for you, and provide different perspectives based on their cross-organizational insight and relationships. In most of these scenarios, the decision to bring on a Chief of Staff earlier rather than later is the best way to set yourself and your team up for success. Their relationship-building superpowers are the ultimate key to building a smooth path for your team and your vision to grow. But, the stars don’t always align. Here’s what I would recommend if you’re not quite ready for a Chief of Staff or if there are immovable blockers in your way: - **Consider other ways to bring aboard pieces of the Chief of Staff superpower until you are ready!** Teams like the one at Discernible can work with you to build purposeful communication strategies and programs that enable trustworthiness within your organization and with key partners. - **Be curious about what your peers have learned in their team-building journeys!** The reality is that there are hundreds of approaches to building out successful teams and likely many others who have walked the path before you. Tap your trusted CISO or CTO communities and ask how they have personally navigated introducing a Chief of Staff role. What are the greatest lifts they have personally felt after bringing on a Chief of Staff? Do they have any learnings from the process that would have made it better? How have they gained buy-in from the rest of the organization to bring on the role? Understanding these different experiences will help you build the case to add this important role when the time is right. - **Connect with real-life Chiefs of Staff in your area of expertise and take steps to understand their philosophies.** There is a vibrant Chief of Staff presence on LinkedIn where many in-seat or advising Chiefs of Staff are actively sharing their perspectives. Seek them out and look for any contributors who may have experience working alongside roles similar to yours. It’s likely they will have some really valuable learnings to share that will set you up well to work with your future Chief of Staff! ### Why No One Listens to Cassandra URL: https://www.discernibleinc.com/why-no-one-listens-to-cassandra/ Last updated: 2026-07-29T21:36:31.000Z I recently spoke at[*BSides Charm*](https://bsidescharm.org/speakers/?ref=discernibleinc.com)on how to influence business decisions. One of the stories I told was that of Cassandra, a Trojan priestess, and daughter of the King, Priam. According to Greek mythology, Cassandra received a remarkable gift from the Greek god Apollo, giving her the ability to see into the future. However, when she later rejected his sexual advances, he punished her with a curse. He wanted credit for her work and felt entitled to her attention, her gratitude, and her body. He was a selfish creep who couldn’t regulate his emotions when rejected. When she called him out, he retaliated. My motivation for sharing this story isn’t to draw parallels between the Ancient Greek misogyny and modern infosec; they draw themselves. Apollo punishes Cassandra by preventing any of her prophecies from making a difference. No one will ever believe her even though she’s right, and this is the aspect of Cassandra’s story that security and privacy professionals obsess over. Like the cursed Trojan priestess, we can see all of the horrible things that will go wrong in the future, but no one listens. Ten years into a frustrating war with Troy, the Greeks came up with a new idea. They build a giant wooden horse, hide their best warriors inside, and leave it outside the walls of Troy as an olive branch. The Greeks then leave Troy, returning to their boats to sail away. Meanwhile, the Trojans are left to decide what to do with this giant wooden horse. *Editor’s note: It seems pretty clear to me that anyone who leaves a giant farm animal of any kind on your front lawn isn’t a true friend, but the Trojans were truly perplexed.* Now, Cassandra knows this horse isn’t a gift and she attempts to warn her fellow Trojans not to open the gates. Due to Apollo’s curse, no one listens to her. They wheel that giant flammable monstrosity into the middle of their city like the U.S. federal government bringing in Microsoft Exchange. That night as the Trojans slept, Greek warriors spring out of the horse and begin slaughtering the people of Troy. It was a disaster made even more tragic by the fact that it was completely avoidable. If Cassandra had been CISO of Troy, she might have tried to fake influence with an irritating mantra like, “Never waste a crisis,” while frantically updating her slide deck to advocate for more resources, further entrenching the executive team’s perceptions that security is only a wartime investment. I presented several pitfalls of “governing by crisis” at the Enigma 2021 conference. You can see a recording of that talk [here](https://www.usenix.org/conference/enigma2021/presentation/ensign?ref=discernibleinc.com). The fact remains that no one was persuaded by Cassandra’s prophecies. And that’s the point of the story I find most interesting — Apollo’s curse didn’t impact other people’s ability to understand each other. The curse changed how Cassandra communicated, burying the meaning of her advice in vague and opaque language. She confused everyone around her with symbols and metaphors they couldn’t relate to. Cassandra wasn’t believed because she was an ineffective communicator. She produced a lot of [outputs, but not outcomes](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/). Sadly for her, the City of Troy, and many professionals now raising the alarm about security and privacy risks, attention is no substitute for persuasion. Our ability to communicate effectively is the #1 indicator of our potential to influence the business. ### 📬 Mailbag: Where should security communications be on the organization chart? URL: https://www.discernibleinc.com/mailbag-where-should-security-communications-be-on-the-organization-chart/ Last updated: 2026-07-29T21:34:01.000Z *Mailbag questions are submitted by our readers. Submit your own question for our team at discernibleinc.com/contact.* The two most common options are inside corporate communications or the security organization. Although a lot of great security communications work can be done anywhere in the org chart, centralized oversight is important. When I worked in-house, I managed security communications from within the corporate communications department. There are two critical reasons for this: 1. **Authority** – Corporate communications professionals are usually authorized to speak on behalf of the company and have executive veto power (either through formal or informal influence) over a lot of external communications created by other teams. This can be a frustrating reality for a lot of security communications professionals who don’t report to this function. 2. **Visibility** – In addition to their experience managing external perceptions, corporate communications teams typically have more visibility into activities across the company, compared to security communications professionals within the security organization. Knowing what else is on the horizon for the business (or lurking in the shadows) provides a strategic advantage. That said, my role was always created at the behest of the CISO/CSO and in collaboration with the head of corporate communications to ensure I had access to the advantages above. My first responsibility was to the company at large, and I knew the best way to do that was to ensure security communications were proactive and worked to prevent or anticipate issues, rather than simply react to them. A depressingly large number of corporate communications teams are only concerned with media engagements, ignoring all other stakeholders. This is a disservice to themselves and their organization, which needs a responsible steward of the corporate brand across audiences. As explained by the Page Society (the world’s leading professional association for senior strategic communication leaders), a company’s brand isn’t just its product: > *“It’s the totality of what is experienced by all stakeholders through every touchpoint.” –* [*Page Society* ](https://paths.page.org/corporate-brand/?ref=discernibleinc.com) A limited scope of corporate communications–or public relations more generally–as solely a publicity role is a waste of potential influence, power, and effectiveness for the function! Unless your business sells to newsrooms, media is primarily a communication channel, not an audience. You may not always be able to choose the topic or timing (freedom of the press is important!), but the reason organizations invest in these relationships is because of their potential to influence stakeholder groups that can impact their business. An ideal security communications function aligns communications across all stakeholder groups, considering the needs and expectations of each one as it relates to cybersecurity. At best, misalignment across audiences is a missed opportunity to strengthen and amplify your security reputation through repetition and message enforcement; at worst, misalignment creates conflicting or incomplete messages. ![](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/365050f5-67e1-41c0-8aa6-10bb5aba9d63/Discernible_Security+Communications+.png) ## **The Scope of Strategic Security Communications** Because of the multitude of audiences in scope for security communications, we’ve seen aspects of this work in a variety of places inside organizations. Unfortunately, they’re usually isolated and not aligned with any particular high-level business goal that the company is measuring. This leads to a lot of work that exists only for its own sake; and although you might be busy, there’s not much impact. When teams and individuals measure [outputs instead of outcomes](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/), it’s usually because they lack the visibility to connect with priorities from across the entire organization. Names and titles within organizations vary, so the exact role or team might be different at your company, but here are some of the folks we work with most often to ensure accurate, consistent, and timely security communications: - **Security**: Including the CISO, their [Chief of Staff](https://www.discernibleinc.com/is-your-security-or-engineering-team-ready-for-a-chief-of-staff/), training staff, GRC/Assurance (especially what they share publicly & through procurement portals), incident response (external comms reflect the level of internal chaos), bug bounty teams (an often overlooked but very public-facing program), and individual team members to ensure everyone knows what’s expected of them in regards to building relationships and influence across the organization and the outside community – and have the communication skills to meet those expectations. It’s useful to sit in on security reviews for new products or engineering projects, and ask [questions](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/) that will help teams think critically about the public perceptions of their decisions. - **Corporate Communications**: Internal/employee communications, investor relations, and product PR all intersect with security communications, but they usually don’t see it themselves until something bad happens and suddenly they’re asking for reactive talking points to address inbound questions. These are incredibly valuable colleagues to collaborate with in advance, to educate critical audiences while setting realistic expectations. For example, when you launch a new product or feature, consider how you will communicate security choices made on the backend or within the user experience to increase or protect current levels of security. Get ahead of anticipated concerns while demonstrating transparency and technical competence. - **Trust & Safety:** Fake or compromised accounts are involved in a lot of online abuse, and external audiences rarely differentiate your safety brand from your security brand. To them, it’s all connected to how safe they feel using your products. How you communicate about cybersecurity issues to people who use your products impacts their overall perception of brand and product safety. Your organization may not have this exact team; perhaps for your company, the function is more along the lines of platform integrity, anti-fraud, or spam fighting. - **LERT**: Collaboration with law enforcement agencies is increasing across a wider range of security incidents, in part because more and more attacks are cross-platform or industry-wide, making them prime targets/opportunities for government intervention. Law enforcement requests for data related to crime are also increasing since most crime now includes some kind of digital footprint. What does your company say to and about law enforcement before, during, and after an engagement? How does your account of an incident compare to law enforcement’s? Should they align or should they be intentionally different? Spoiler: it depends. - **Marketing**: A lot of security and privacy-related FTC investigations start with a misleading marketing statement or promise on a company website. If you said something in the past that is now clearly not true because of a publicized incident, that’s tasty bait for regulators, including the FTC….and increasingly the SEC, not to mention plaintiff attorneys. If your company hires a creative agency to create your website, get a security subject matter expert to write or review all the copy. - **Social Media**: Often the front line of customer and public concerns about security issues, social media comments are an unfortunate way to realize your security communications are not aligned across the organization. If you must use prepared responses to scale your ability to address concerns, then social media teams need to be empowered with timely, updated, and technically accurate information that they can share publicly. You might not know if the online persona you’re talking to is a security expert or not, but someone watching certainly is – and as it turns out, a lot of security professionals love to point out anytime something wrong is said on the internet, especially by brands–and especially by their overworked, underpaid social media team members because infosec has no idea how these organizations operate internally. - **Customer Support**: Working with customer support is about more than having prepared statements when a serious incident occurs or notifying customers if they’re affected; it’s about educating customers about what you’re doing to protect them in advance of an issue as well as demonstrating your ability to respond and recover quickly. It’s also about following through on promises of transparency and positioning your brand as a helpful resource whenever security questions arise. It’s also about helping to drive down the volume and cost of support tickets that reference security issues, especially those where you’ve made strong investments. Additionally, working with these teams gives you good insight into what kind of security concerns are top-of-mind for your customers, so you can potentially preempt them with proactive communications – and accurately predict which type of security incidents will have the greatest impact on customer trust. - **Community Managers** (e.g. Discord servers and Slack channels): Not every company has these teams, but we work with a lot of developer-first companies where user communities are even bigger than their customer base and have an oversized impact on how customers and beat reporters perceive the organization’s security posture. Similar to bug bounty programs, this is a public-facing organization with a lot of potential to help or hurt a company’s credibility on security issues, and it’s often overlooked by corporate communications teams. - **Legal**: Their job (and yours!) is infinitely harder if they don’t have a working relationship and workflow with the security team. Fearful lawyers write apathetic, robotic statements that hurt brand sentiment and customer trust. I’ve seen amazing relationships flourish between security and legal teams, leading to public statements and security reputations the company deserves to be proud of. And if you, as a security communications professional, want to be able to share helpful details about a security incident or proactively (& accurately) discuss your company’s commitment to security, it’s in your best interest to ensure a strong partnership between security and legal. CISOs should also prioritize nurturing this relationship, so working together as allies to bring your legal partners along is also a great way to strengthen your relationship with security leadership - **Sales**: Sales get a bad rap (usually for good reason), but they’re often operating in an information vacuum that commonly exists between marketing materials and a successful proof of concept. Even if they know the product *and* know the prospect well, they’re usually not subject matter experts in security – this is one reason why sales engineers became so popular at tech vendors over the past several years. It’s in everyone’s best interest to remove security concerns as a reason for prospects not to buy. If you work with sales to identify the most common and most difficult questions they get about security, you can empower them with credible resources to share during sales conversations and a path for how to address concerns they didn’t anticipate. Moreover, if there are questions that make you squeamish for sales to answer directly, work with the appropriate security colleagues to escalate these issues to business leaders to get resolutions prioritized. Otherwise, these weaknesses will come back to haunt you at the worst time. - **Product:** Not all security incidents involve a breach or intrusion; sometimes they’re product design, policy, or UX decisions that spark a backlash among important stakeholder groups. They require significant resources to mitigate and almost always have a significant impact on brand trust. For example, collecting phone numbers for 2FA and then using that information for targeted advertising despite years of public promises that you weren’t. Product teams have tremendous influence over brand trust and are an important ally in communicating your security commitments and competency. Making security the easy path includes effective communication within the product experience. - **HR**: If your internal/employee communications function isn’t part of corporate communications, it could be under HR, making them a key partner during incident communications and proactive employee engagements like training and workshops. By pooling resources, you can create greater impact together. - **Recruiting**: If you’re not yet aware of how your incident history impacts hiring potential or how uninformed recruiters impact your ability to hire security talent, check out this previous [post](https://www.discernibleinc.com/how-security-communications-gives-recruiting-an-edge/) from a senior technical recruiter who hired security teams at Uber, Paypal, Lime, and more. > *“Often recruiters aren’t in the loop or armed with the right messaging and talking points about a company’s security posture – or if there has been a security incident or other reputation-affecting situation. Not all tech candidates will ask about these things, but security candidates often want to know.* > > *I want to be as honest and transparent as I can be with potential hires, so having accurate information from my security communications colleagues makes a big difference. Some companies are better at this than others and that impacts how they’re perceived by candidates even before they start interviewing.”* - **Public Policy:** Waiting until you get a letter from Congress is the wrong approach to security communications with the government. Coaching public policy colleagues in the areas of security where your organization is not only strong but also has a strong point of view is important to ensure your interests are heard at the appropriate levels of policy-making at the local, state, and federal levels (or applicable structures outside the U.S). Be ready to respond at a moment’s notice to basic as well as controversial questions about your security programs and technical controls. This is an area where industry allies can be really helpful and you can help public policy colleagues identify the appropriate folks to bring to the table in government discussions. - **Engineering & Data Science:** Usually these are different teams, but we engage with them for many of the same reasons — they love to talk about their work, and they’re not always aware of how various project names, descriptions, and design decisions interact with stakeholder expectations on security issues. These are some of the most common teams we work with, but the most important thing is that no matter where you sit in an organization, you find all the other people working on security communications across the company and create a cross-functional working group and tie your collaboration directly to the company’s core business objectives. By working together, you have more strategic alignment, more information, more resources, more justification, and ultimately, more impact. If you find yourself trying to scale your subject matter expertise and governance across cross-functional partners, let’s talk! There are proven strategies for empowering other teams with resources they can use on their own while setting guidelines and triggers to ensure direct oversight when needed. ### Powerful Expectations: Effective Communications for Bug Bounty Programs URL: https://www.discernibleinc.com/powerful-expectations-effective-communications-for-bug-bounty-programs/ Last updated: 2026-07-29T21:32:22.000Z *Q&A with Reginaldo Silva, security researcher and former security engineer at Facebook/Instagram* Clear, effective communication is essential for successful bug bounty programs for several reasons. It helps create a collaborative and transparent environment between security researchers and the organization running the program. When programs communicate well, researchers can easily understand the program's guidelines, scope, and expectations, leading to more focused and relevant submissions. Additionally, timely and precise communication can help prevent misunderstandings and conflicts, ensuring that both parties are on the same page throughout the process and protecting triage teams from burnout. Effective communication also fosters trust and builds a positive reputation for the organization, encouraging more researchers to participate and contribute to the program's success. Years ago, I had the pleasure of working closely with Reginaldo Silva on bug bounty communications at Facebook/Instagram (before it hallucinated into Meta). Among other things, we still keep in touch about various communication blunders across bug bounty programs as well as how researchers might do better. I’m honored and excited to share a slice of the wisdom he’s gained from two decades of independent bug hunting and managing bug bounty programs. ### As a researcher, what do you expect from bug bounty programs? **Reginaldo**: When I submit a report, my goal is to have the issue I report acknowledged, properly assessed for impact, and fixed as soon as possible–especially when there’s some sort of reward that depends on the issue involved being fixed, but even when there isn't any reward. A pending report feels like a to-do item you never get rid of. The worst case is when there is a log hiatus in communication for a complex report, and the company asks for more information months later. By that time, both sides may have lost the context that was necessary to understand what was originally reported. **Melanie:** Yes, a lack of documentation makes it more difficult to have a productive conversation. Not only documentation about technical investigations but also how and why decisions are made along the way, starting from the initial acknowledgment through payout and disclosure. Documentation is critical for both sides, especially when they disagree on the outcome. ### What are bug bounty programs expecting from researchers? **Reginaldo:** When managing a program, there are several things to balance. The goal of a bug bounty program is to reduce risk to the company. Ironically, some of the risks the company faces might come from the program itself, specifically when it comes to communications. Of course, the risk of not interacting with the research community is far greater, which is why bug bounty programs became so popular. When running a program, our ideal state is for high and critical risk issues to be fixed right away, and the lower risk issues dealt with accordingly. For example, a program might require that at least 90% of all high/critical be closed within a week of receiving the report and 90% of all issues are closed within 30 days after being triaged. **Melanie:** Yeah, the irony about communication risk is very familiar. Years ago, several bug bounty programs launched as PR stunts, but the companies weren’t truly ready to manage a program well and the resulting backlash from the research community also created negative press attention. Security, legal, communications, etc. individually, are but a single source of risk, and companies need to balance them all – and they all do it differently based on their business, culture, and tolerance for different kinds of risk. We advise clients to treat bug bounty programs first and foremost as a way to reduce security risk, and that means it has to be operationally honest, sustainable, and effective. The communication piece comes in to help support that goal by facilitating accurate information sharing and mutual understanding. ### Frequent or high-profile misunderstandings are one of the primary reasons bug bounty programs reach out to Discernible for communications support. What are some of the most common misunderstandings you’ve seen? **Reginaldo:** Expectations around urgency create a lot of confusion. For example, a lot of programs say they will respond in a “timely” manner, but the definition of “timely” varies by experience, culture, and perceived severity of the issue. This is a primary source of frustration for researchers. If there’s any consolation, it’s one of the big sources of frustration for the team running the bug bounty program, too. At the other end, there’s an engineering team that will be implementing the fix (that may or may not be the security team itself, it usually isn’t). And that engineering team has different priorities and incentives than the researcher who submitted the issue. That’s not necessarily bad. For example, some issues need to be addressed at a framework level, and those will take longer to implement but, for the lower-risk issues, the engineering team will not necessarily want to submit “one-off” fixes. This creates the potential for a tense dynamic: the security and engineering teams are aware of the issue, and what they consider to be a root cause. The researcher has confirmation that the report was valid and has an incentive to find similar issues. If the researcher (or a different researcher) finds new issues with the same root cause, the company might want to treat them as duplicates, even though the final solution is not yet ready. There are lots of opportunities for miscommunication and frustrated expectations in situations like that. Especially in newer relationships between researchers and bug bounty programs, there are communication challenges related to trust not yet having been established. The researcher might not have sent everything they know at once, and the company cannot be completely transparent about its internal processes, and always needs to be extra careful with their words, as the interactions might become public at any time without notice. Once trust has been established, things flow more naturally. **Melanie:** I’ve seen that duplication example so many times and in my experience, the reputation of a company’s overall brand often has as much impact as interactions with the bug bounty team on how much a program is trusted by researchers in the early stages of a new relationship. Fair or not, even the best security teams are judged by the decisions of the businesses they work for. Your comment about being careful with your words as a member of a bug bounty team is also something that comes up a lot in our work at Discernible. You need to understand the real and perceived power dynamics between companies and researchers. On the company side, you’re always expected to take the high road, so treating all your correspondence as something that could become public is a good approach for keeping your cool and demonstrating respect. Communicating with the expectation that everything will become public also helps when advocating for more disclosure of bug bounty reports. I am a big supporter of disclosing as much as you safely can to better position your communications strategy for incident response. However, I’ve seen that exposing the level of professionalism employees demonstrate in their correspondence can be even scarier than disclosing vulnerability details. ### What does a successful bug bounty relationship look like? **Reginaldo:** One of the most important things I learned from running a program is that the incentives for the company and the researcher are typically aligned. A well-run program will work as a feedback mechanism, part of a larger, more well-structured program. So, the company views the bug bounty program as one of the many activities the security teams do, along with, for instance, internal reviews, external reviews, vulnerability management, red teaming, detection, etc. A successful bounty relationship happens, then, when the company perceives the researcher as someone who will help the company take less risk, by pointing out vulnerabilities to be fixed and by not being a risk themselves. So, it looks about the same for both sides: the researcher might get some direct access to the engineering team, for instance, or might be one of the first to be able to test a certain area. Some companies have NDAs researchers can sign to get access to pre-release features. The best scenario includes mutual respect and admiration between the people who work at the company and the researcher. I’ve been part of this kind of relationship, was hired as a researcher, and then hired more researchers. **Melanie:** I love this! Relationships are so important in every aspect of our lives because productive relationships enable us to move forward in business and personal endeavors, while unproductive or toxic relationships hold us back or create more obstacles in our path. I’m starting to see more bug bounty hunters and programs adopt this way of thinking and come to the understanding that if we focus on the long-term outcomes we want to achieve, trying to “win” individual conversations feels trite. Once you’re committed to the relationship and establish trust, you have a lot more room for creative problem-solving. ### What are some effective communication techniques bug bounty teams need to use? **Reginaldo:** The basic is having some documentation to help manage researcher expectations. For instance, telling researchers how long it typically takes to triage an issue, how long it takes to close, what are some examples of low, medium, high, and critical impact issues the company expects to receive, as well as some issues it’s already aware of and/or are out of scope. A must-have, in my opinion, is to train the people who interact with researchers on how to communicate effectively, to evaluate the quality of the interactions themselves, and to remediate communication problems such as de-escalating, dealing with language barriers, and giving as much information as possible when requesting something from the researcher. This has to be run as a process, not as a one-time thing, and has to evolve with the program. **Melanie:** Completely agree. :) ### Can you share a few examples of common communication errors researchers make? **Reginaldo:** The most important thing is not being aware of what kinds of issues the company expects to receive, and what it perceives to be part of the threat model. A company that has to adhere to regulations, HIPAA, for instance, will have a very different threat model from an IoT device manufacturer. The second is a misunderstanding of how a bug bounty program works. Generally, the people working on large programs and who are the first point of contact with the researchers deal with a large scope and will not be able to know everything about the product(s) referenced in every researcher report. They might even be new to the program themselves. The researcher’s first goal is to help that person decide where to send their report. The person on triage has two questions they are trying to answer: 1. **Is this a privacy or security issue?** It might be fake, spam (a popular form right now is LLM output), expected behavior, or a bug that has no security or privacy implications. 2. **Where should it go next?** Should it go to the engineering team, a second level of triage, back to the researcher to request more information, or closed as a duplicate or known false positive? Researchers should write their reports thinking of the humans that will handle it, including how it would be handled, by whom, and in what order. Some mistakes signal a researcher is not acting in good faith, such as: - Trying to overstate the risk without backing it up in the report in the hopes of getting a better reward - Threatening, using extortion language, or making veiled threats - Behaving unprofessionally, using offensive language, or being sexist (really!) Other mistakes simply reveal a lack of experience: - Failing to be explicit about the report’s impact - Being too succinct or too verbose - Sending long video reports that meander around the point **Melanie:** *How* someone communicates can reveal a lot about them, and that’s easy to forget both as the sender and receiver of messages. This is why it’s so important to understand upfront what your communication goals are, setting program communication priorities like “demonstrate respect” or “preserve trust” enables bug bounty team members to make smarter decisions about their interactions with researchers. For example, if maintaining a reputation for fairness is important to your team, it should be clear in the way you communicate with all researchers that you will prioritize fairness. The same is true for researchers because, in addition to your reputation score from the platforms, bug bounty teams talk to each other. If you want to be known as both competent and professional, it’s a good idea to keep your emotions in check when things don’t go your way. There is absolutely a time, place, and manner for lodging complaints that have a real influence on programs – tantrums on social media are not it. It’s so easy for programs to dismiss someone behaving immaturely. **Reginaldo:** Researchers should also remember that more than one person will typically handle the report and, while everyone will have read it, not everyone will have the same context. Usually, the people who handle the request later know more about the system in the report, so it's ok to go deeper, technically, but always maintain common courtesy and professionalism, and understand you are talking to a person on the other side, not a company. ## Storytime! ### Can you share an example of when poor communication led to serious misunderstanding? **Reginaldo:** First, I want to note how the general public sees privacy and security issues, and that it’s a matter of perception as much as it is one of being technically correct. A common source of miscommunication is when the security team tells a researcher that "this is not an issue," when one of two things happened: 1) the security team didn't understand the report fully (and here, language barriers might play a role), or 2) what is being reported is an issue but it's not privacy or security related. Security teams handling bug bounty reports are usually aware that some reports have a potential risk of "exploding," becoming a public story, and many times for the wrong reasons. It was important to me having a communications expert to turn to when that happens. It not only saved the company a few times, but it turned some potentially negative stories into positive ones. Things have improved since I ran a bug bounty program, but even just a few years ago someone could send a non-issue to a security program, especially one at a widely recognized brand, collect some interesting responses from the security team, go to a journalist, and have a story published that would affect the general public's perception of the company, even if the security team was technically correct. **Melanie:** This relates to my earlier comments about how the reputation and brand trust of the parent company impacts how the bug bounty team should communicate – especially if you don’t have a dedicated communications advisor for your security organization. It’s really difficult when bug bounty situations explode for the average corporate communications team to get up to speed fast enough to respond in a way that acknowledges the nuance and context of the research community. **Reginaldo:** An example where miscommunication almost sent things awry but turned to one of the best bug bounty stories I have to share was when a researcher sent a report about an important and subtle issue that led to comments being deleted on Instagram. The initial report was difficult to understand and the researcher seemed to take a very direct and "in your face" approach to their communications. As a result, the triage team struggled to reproduce the findings in the report. I got the report, reproduced it, and was able to establish a rapport with the researcher through subsequent correspondence. We rewarded him with a $10,000 bounty and only then did we learn that we were communicating with a 10-year-old child in Finland! Knowing that information changed the whole way we perceived the interaction and it became clear that there was no malicious intent. It was a misunderstanding on our part. **Melanie:** I remember this report and it turned out to be a wonderful opportunity for the young hacker to publicly show off his achievement. This example illustrates why it’s so important to question our assumptions when speaking with people for the first time. A lot of the emotional labor involved in managing a bug bounty program comes from the stories we tell ourselves about what the other person is or isn’t trying to do instead of learning how to ask the right questions to clarify their intent and build mutual trust. I’ve talked to a lot of very upset security teams and researchers who simply forgot to focus on their long-term goals, which made every situation feel like an argument they had to win. Instead, we can communicate that a relationship is important to us by giving that person the benefit of the doubt and trying to meet them where they are. If we don’t, it’s common for the other person (and any subsequent journalist or third party) to interpret our behavior as apathetic. ### What is something you learned working with me at Facebook that you still apply to your communications today? **Reginaldo:** Oh, I learned so much from you! Being succinct, on point, transparent and thinking of the audience. Running away from jargon and clichés like, "security is very important to us." Instead, being inclusive and making sure that there's a factual message with meaning. Even though we started working together many years ago, I go through the mental exercise you taught me when we first met, thinking about what you would advise me to do, and I still ask for your advice often. But the most important thing I learned is how to evaluate whether what I'm saying is aligned with what I want to portray and perceived as such by everyone who will eventually read what I wrote. **Melanie:** Love it! Thank you for sharing your insight with us! --- *Connect with Reginaldo on* [*Twitter*](https://twitter.com/reginaldojsf?ref=discernibleinc.com) *or* [*LinkedIn*](https://linkedin.com/in/rjsfilho?ref=discernibleinc.com)*.* ### Takeaways from 2023 - and Resolutions for 2024 URL: https://www.discernibleinc.com/takeaways-from-2023-and-resolutions-for-2024/ Last updated: 2026-07-29T21:29:24.000Z People in the security industry love to make predictions, particularly at year-end. From security journalists to CICOs, everyone seems to have an opinion about what the top security trends will be in the coming year and are eager to publish them. Less common are reflections on the year that was - because that requires examining what may have gone wrong, or should have been done better, or even realizing that many previous predictions failed to materialize. Don’t get me wrong, prediction lists are fun and help fill digital space during a traditionally slow news cycle. However, for myself, I think it’s more useful to share what I’ve observed through my work with clients over the previous year. Although there are a lot of things I could highlight, I’ve identified three patterns I observed the most often in 2023, and why you should resolve to address them in 2024\. That’s right, I’ve made your New Year’s resolutions for you! You’re welcome. ## Most incident response communications need a makeover, stat. I’ve been surprised at how many organizations in 2023 were still executing incident response comms the same old way. Which is to say, by trying to put lipstick on a pig rather than being as clear and transparent as possible. It’s understandable - corporate communicators are often in charge of incident response crisis comms and they believe less is more in preventing panic and minimizing press attention. However, this inevitably comes back to bite you and hurts your credibility, often more than the impact of the original breach. So when an incident occurs, rather than saying something that tries to trivialize the event, like “only 1% of our customer base was affected,” (if you’re a medium to large organization this is still a lot of people, and journalists can do the math), put out an honest statement. The reason “silver lining” statements are a problem is that they often come across as apathetic and you will no doubt discover something later on that makes that statement untrue. So then you hurt your credibility and in turn generate another news cycle. To be honest, negative press stories are not the end of the world for most companies and sometimes the prudent choice for a business is not to fight. But high profile, drawn-out, and repetitive news cycles are distracting for your customers and your team – and they can lead to even more resources being diverted into regulatory or legal investigations. Sometimes not being popular with a specific journalist is simply the cost of business. Sometimes it’s the fastest way to a Congressional inquiry. What you say matters. I recommend organizations of all sizes do an inventory of their[ IR comms and process to identify where they can improve](https://www.discernibleinc.com/mailbag-how-do-you-manage-balance-truthful-communications-about-an-incident-breach-while-mitigating-legal-exposure/). Spoiler: approaching security incidents with the traditional expectations of crisis comms, namely that incidents are unexpected, and have a clear beginning and end, is going to cloud your decisions. [The most effective IR communications process is part of a long term strategic program](https://www.discernibleinc.com/turning-incident-response-communications-into-a-sustainable-security-communications-program/) focused on demonstrating empathy, competency, and collaboration. You can’t expect anyone in the security community to have your back if they don’t know what you’ve been working on. Good IR communications also help [reduce the impact of high profile incidents on your recruiting efforts](https://www.discernibleinc.com/how-security-communications-gives-recruiting-an-edge/). Remember that with any kind of IR communication whether it’s in response to a bug bounty report gone sour, a high profile breach, or a [third party 0day](https://www.discernibleinc.com/third-party-security-incident-response-communicating-even-when-youre-not-exposed/), you will have a finite amount of space and time to get your point across to the people who need to hear from you. So, consider strengthening high level statements with technical timelines and references to your trust center, where all the artifacts and evidence regarding your security posture and response reside. Don’t have one? Read on. ## Many companies don’t have a trust center. That’s a mistake. A lot of the stress and communication errors that occur when a security incident happens can be avoided or mitigated by having a trust center up and running before things go sideways. Yet, I observed far too often in 2023 that few organizations have one, or if they do, it’s incomplete or exists solely for the purposes of customer procurement. Sorry to say that certifications and attestations aren’t meaningful communication tools in the wake of an incident because we all know compliance != security. To be clear, a trust center isn’t going to prevent every incident (although it can help prevent avoidable incidents caused by gaps in what you say vs what you do, discussed [here](https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups/)), but it’s going to make it a lot less painful for you when you have an issue. By having essential information about how you protect customer or other data publicly available, you can point journalists, customers, regulators, and others to that information immediately, rather than having to bird dog it from different places in your org and pull it together in a cohesive package in the middle of a fire. If you don’t have this information readily accessible, reporters will fill in the gaps with their own imaginations, and they have very vivid imaginations (as do all the security professionals not on your payroll who consistently speculate in the press about everyone else’s incidents). By responding to inquiries with a clear and honest IR comms statement and appropriate links to existing resources on your trust center, you are proving that your company invested in security before the incident happened. It’s a timestamp that will serve you well. We build trust centers for clients often and would be happy to share more information with you about the elements that would be most valuable for your organization. At the very least, we recommend all trust centers include information about: - How you handle user account security - passwords, MFA, SSO, risk-based friction, marketplace monitoring, account recovery, etc. - How you protect data at rest and in transit - How you are using encryption in your product and infrastructure, and what those protocols are with explanations of any tradeoffs - Technical mechanisms that govern data practices (privacy policies are just words, prove you can build a respectful system) - Disclosure around access controls Another important benefit of a well-done trust center is that both customers and prospects will better understand what you’re doing to protect them *and* that you proactively shared this information. ## A lot of security marketing is homogenous, not reality-based, and everyone is tired of it. As part of our work with clients, we conduct focus groups to test messaging with a target audience. I believe going out with untested messaging is foolish, particularly today - when most security marketing sounds exactly the same. In 2023, I observed this in several ways, including through industry events, social media, and direct client work. But it really hits me when I do focus groups to test messaging. Whether the target is a CISO or some other buyer in the decision chain, I heard the same complaints over and over last year: - They hate it when a company claims their product will solve all of their security problems. This isn't credible because it just isn’t possible. There are a lot of very different and nuanced problems that different security teams deal with, across organizations and industries. When your message claims to address all of them, you lose credibility. No product will stop all breaches. Stop saying that. - A related complaint: security professionals can’t tell from your website messaging what your company or your product actually does do. Again, many look alike, and use the same descriptive words. Much of this is because security companies use vendors to build their messaging and website that have no security experience. They are viewing the copy through the lens of what they think sounds good, rather than what the prospect needs to know. And, they fail to test these messages before publishing web copy. So testing messaging doesn’t happen nearly enough, yet it pays for itself hundreds of times over in the long run. However, you need to test it with the right target, which leads me to a related observation from 2023: many security companies simply aren’t honest with themselves about who their buyer is. Most assume it’s the boss, the CISO - and sometimes it is, but many times it’s a director or line manager further down in the org. This person is who will actually use your product day to day and will advocate for budget from the CISO to buy it, so that’s who you need to convince. This means your messaging has to be more technical and more precise. Knowing your customer and testing your messaging with that target are two critical steps to take before you go to market. # 2024 Resolutions Instead of chasing trends and predictions, I recommend taking a close look at the elements I’ve outlined today. Perhaps you’re totally on top of your IR comms, your trust center, and your messaging. Great! But based on the last year and my experience, most companies have some work to do in one or more areas. So to recap, in 2024: - Commit to a through review of your IR comms, and resolve to make them clear and honest - Resolve to build a trust center! Or if you already have one, make sure it’s complete, easy to find, and routinely updated - Make a never ending resolution to test your messaging with the right target audience. This can be done for new product launches, a marketing campaign, or website copy and design. No more flying blind. As always, we’re here to help. Be sure to check out our mailbag questions, blogs, and case studies for insights and tips on these topics and more. Here’s to a great 2024! ### 📬 Mailbag: How do you manage/balance truthful communications about an incident/breach while mitigating legal exposure? URL: https://www.discernibleinc.com/mailbag-how-do-you-manage-balance-truthful-communications-about-an-incident-breach-while-mitigating-legal-exposure/ Last updated: 2026-07-01T04:36:40.000Z *Mailbag questions are submitted by our readers. Submit your own question for our team at discernibleinc.com/contact.* I’m not a lawyer, so I won’t be giving any legal advice. However, I have been fortunate to work with many brilliant cybersecurity attorneys throughout my career. I didn’t always agree with them on every aspect of incident or breach communications, but the one thing we always agreed on is that truthful communication is the only way forward. Fear of telling the truth is an indicator that you know you should have done more – so go do it now. ## Preparing for incidents means preparing for lawsuits. If you are a U.S. company then whenever you have a breach, expect lawsuits. Period. It will happen no matter what you say because a lot of people make a living off suing you. It’s not personal. And regardless of the outcome (most cases are dismissed, some are won, and some are lost), it will be expensive just to respond. There’s nothing you can say to prevent this from happening, so it shouldn’t be a dominant factor in communication decisions, except that both judges and juries tend to look unfavorably on evidence of dishonesty. In my experience, thinking you’ll be able to avoid costly litigation by hiding or withholding information is shortsided. Incidents are simply expensive – engineering time, outside counsel, external investigators, customer support, PR support, etc. – so we should try to avoid them by making smarter long term decisions about our systems, products, and organizations. This is one reason why Discernible approaches incident communications as proactive, not reactive. If we want to be proud of what our organizations say during an incident, we must make it true in advance. For example, if you work in B2C, account takeovers are typically a big part of your risk model. In part, because there is usually valuable information inside those user accounts, they’re often the most visible security issue for mainstream media, and they usually create a lot of customer support tickets ($$$). So when we consider what an organization would say in response to a legitimate or even rumored incident involving the exposure of user credentials or access to user accounts, the best answer isn’t PR spin, but rather – security engineering. Years ago it was popular for companies whose user login credentials were exposed to simultaneously launch two-factor authentication as part of their incident response communications – demonstrating that they could have done this before to protect users but didn’t. If what, instead, you could say something like, “our user accounts already support MFA by default to protect against credential stuffing or dictionary attacks.” One of our clients went a step further to double hash both usernames and passwords so that even if the company’s systems are compromised, user credentials aren’t exposed. They’re not afraid to tell the truth. > **A very wise cybersecurity attorney once told me, “there are worse things than getting sued for doing the right thing.”** Incidents will happen. Lawsuits will happen. The question is how do you want to show up in that moment? As a defensive, cowardly company embarrassed by your organization's disregard for your customers or will you be ready to own up to the truth because you’re proud of everything you did in advance to minimize the impact on others? ## Preparing for incidents means preparing to tell the truth to everyone. Additionally, lawsuits are only one type of legal risk involved in security incidents. Regulatory investigations and breach of contract with B2B customers are usually even more expensive than lawsuits with a potentially greater impact on your bottom line. In both cases, being able to demonstrate that you were as forthcoming as you possibly could be as quickly as you could be (including being honest about your level of confidence in various conclusions) could be the very thing that saves your company from millions of dollars in fines, multi-decade settlements, and customer churn. Lawyers and communication professionals want the same thing for our organizations: to thrive with as few distractions as possible. If you leave a vacuum of information for customers, journalists, and regulators to fill with their own imaginations, I promise it will cost you a lot more than showing up with your ready-made receipts proving how much you truly did care about your customers’ security before today. ### “The solution is not buying another server, it’s having better communications.” URL: https://www.discernibleinc.com/the-solution-is-not-buying-another-server-its-having-better-communications/ Last updated: 2026-07-01T03:42:25.000Z *A Q&A with DEF CON founder and CEO Jeff Moss on the value of security communications* ### You once said that, “80% of the problems we have as a security industry are communications problems. We can fix this. Communication is a soft skill that leads to better technical outcomes, period." Can you expand on that? With both DEF CON and Black Hat, it seemed like every time we ran into a problem, it was almost always a communication problem. There are so many moving parts and so many teams involved, if you weren’t really clear with your communications up front, it was like a game of telephone. People would take the last thing they heard and run with it. It was never malicious, but without deliberate communication and clarity, people were off to the races. And by the time you find out you have a problem, it’s expensive and harder to fix. It could be anything - from what to put on a conference badge to technical requirements for a product. When we would finally get to the bottom of the problem, it was usually because communications weren’t clear. I have looked at the costs of these types of problems and realized the solution is not buying another server, it’s having better communications. That would solve 80 percent of those issues. And that is a hard problem to solve, because you have to change both how people communicate and how you listen. And that means sometimes you have to dig deeper and ask a lot of questions to uncover what is really going on. ### How can this approach help security leaders? If you never spend the time to ask questions or understand the needs of your stakeholders, you’re not going to deliver the work they want, or you’re going to over report or underreport. One of my first jobs was to scope professional services for a security consulting company. And I learned that you could be a great pen tester, but ultimately what the client was paying for was the report - and if you weren’t clear or you didn’t understand what the client wanted, your report wouldn’t meet their expectations. And what is the report after all? It’s all communications. What did you find? Why is it important? Did you put it in the context of their business? I learned that the difference between a good pen testing company and a great one was the report writing. And it’s not a skill many of us were taught in school and it’s not an engineering discipline. When we tried to find people to write test reports, we ended up finding people from the humanities. They could learn the technical details. It’s harder to find technical people and then teach them to be good communicators, but somehow Melanie has figured out how to do it - and that’s what her team is doing at Discernible. ### You’ve been in the security world for a while. Have you seen greater awareness for the importance of communications? I’ve noticed that often when companies do table top exercises they don’t normally exercise communications in my experience. It’s focused on the technical response. It’s rarely asked, “How do we use this opportunity to demonstrate transparency and commitment?” I’ve advised governments and the question of what you reveal, and when, if an incident happens isn’t often asked. When something goes wrong, I’ve observed that people tend to either panic or twiddle. Even if you are legally mandated to report an incident, that doesn’t mean you’re necessarily good at it. Waiting until you’re in the thick of an incident is the worst time to try to learn on your own. When I was at ICANN, there was a problem with our rollout of new top level domain names. We had the technology in place to handle the issue, but we didn’t really have security or incident comms ready to deal with the fallout. That’s when I got firsthand experience watching news reports coming in and realizing these communications aren’t PR, or marketing - it’s different - and I remember thinking, “are we really going to hand this off to someone who doesn’t understand the industry or the issues?’” I think that recognizing the value of security comms, whether you're in a crisis or not, is still a rare skill. You have to recognize you need specialized comms support and then you need to have the right people to do it. I think that’s where Melanie was so helpful with DEF CON. She’s been close to the flame in a lot of security comms situations. If an incident or situation came up, the technologists in us would want to over-explain, and Melanie taught me that half the time, an issue burns itself out, and half the time you are misinterpreting what the core issue is. I’ve learned valuable lessons from her. ### What was it like working with Melanie on DEF CON over the last 10 years? First of all, I love how Melanie has pioneered incident and strategic security communications. She really is an expert in this space and one of the first to understand the specialized nature of it. And I’ve found Melanie to be a really great advocate for different audiences. You may be thinking you know what audience you need to address, but she will point out what audiences you’re overlooking. And she has a lot of experience dealing with the press and understanding the individual players, and how to gauge the impact of a news story and when it made strategic sense to engage with the press or not. That’s second nature for her. Internally, working with all the various players at DEF CON, she understood each of the players and their different sets of needs, from social media to the business leaders. She was really good at keeping us focused on what is important. The lessons we learned at DEF CON from Melanie are still with us today - her expertise is durable and not transactional. We have definitely leveled up from working with her. ### 📬 Mailbag: Are there any examples of good incident response communications? URL: https://www.discernibleinc.com/mailbag-are-there-any-examples-of-good-incident-response-communications/ Last updated: 2026-07-01T04:17:33.000Z *Mailbag questions are submitted by our readers. Submit your own question for our team at discernibleinc.com/contact.* Sadly, there are A LOT of examples of poor incident response communications. Nobody asks me for these. 😎 The tougher question, the one that takes experience and expertise to answer, is what does good incident response communications look like? Well, we have several client examples that I’m proud of — and even more NDAs protecting them. So, here are a few examples that I didn’t work on that I think have merit and are worth considering. I’ve listed several categories of communications here because, after all, good incident response communications is about more than a press statement or customer notification. Yes, the best responses I’ve seen include credible press statements and transparent notifications, but also so much more! #### Incident Disclosure There are several things I really like about [this blog post](https://www.twilio.com/blog/august-2022-social-engineering-attack?ref=discernibleinc.com) from Twilio about a 2022 phishing attack that stole employee credentials in order to gain access to customer data: 1. Twilio published continuous status updates all the way through the conclusion of their investigation. It’s all in one place, easy to find, and easy to read. 2. They apologized for the incident. Apologies go a long way in demonstrating that you actually give a sh\*t about the people behind the data – I love that Twilio’s lawyers are also human. 3. There are multiple updates involving communications with other parties including customers, partners, and service providers. I can tell from reading their updates that Twilio’s security team didn’t just lock their own door; they cared enough to try to eliminate future risk for other businesses and their customers. Industry collaboration is a strong signal of a mature security operation and long-term commitments. #### Status Report Years ago, Cloudflare effectively established a reputation for operational transparency with its ongoing timeline of [status reports](https://www.cloudflarestatus.com/?ref=discernibleinc.com). From network performance issues to security incidents, Cloudflare doesn’t shy away from telling the world what’s going on. It’s clear that disclosing incidents is second nature for this team and they’re comfortable disclosing technical details, especially when they can help other organizations. Additionally, security incidents are disclosed in the same timeline as other service issues. There’s no one-time URL that’s going to disappear in a few months or try to hide from online search results. One of the most common questions that comes up when preparing clients for incident response with a dedicated communication playbook is where the company’s official disclosure and updates should live online. Companies already in the habit of publishing and maintaining a status report page have a real advantage over those that don’t have an equivalent process in place. Consistency across stakeholder communications is critical in security incidents and a good status report page gives all stakeholders a shared, single source of truth with the ability to dig deeper to whatever level of technical detail they need. #### Media Strategy The #1 hype item in every vendor-led tabletop exercise is media engagement. Stop conditioning your teams to fear talking to the media about incidents – trust requires transparency. Sure, talking to the media effectively requires certain skill and know-how; but if it scares you, then you’re not prepared. Fear of journalists is not the desired state for transparency or public trust. In 2018, TimeHop disclosed a network intrusion that caused a breach of customer data. TimeHop was believed to be the first U.S company to suffer a security breach after GDPR went into effect with its 72 hour notification requirement. In addition to their public disclosure [statement](https://www.timehop.com/security?ref=discernibleinc.com), the company gave NBC NEWS an [exclusive play-by-play ](https://www.nbcnews.com/tech/tech-news/timehop-breach-u-s-company-navigates-europe-s-new-data-n890511?ref=discernibleinc.com)of what happened in the hours and days after the intrusion – and this is the piece of their response I want to commend. This level of press engagement is not necessary or appropriate for every organization; but if you’re afraid of what they might find out, you better fix those issues now. These skeletons are stressful, expensive, and impossible to keep buried forever. Here are a few key things I liked about TimeHop’s engagement with NBC News: 1. Senior executives, including the CEO and COO spoke about the incident on the record to take responsibility. 2. Zero attempts at throwing a CISO/CSO or the security team under the bus. 3. Their initial response wasn’t perfect and they were honest about it. 4. Industry collaboration and communication! #### No One Size Fits All There is no universal “crisis comms” plan that can adequately prepare an organization with the type of culture, process, and confidence needed for effective security incident communications. The best security communications come from teams who aren’t just thinking about what to say in the event of an incident, but what they’re already saying (or not) to prepare stakeholders in advance. Imagine if quarterly earnings calls were the only way publicly traded companies could communicate with investors. 😱 In my experience over the past 15 years, the frequency and comfort with which organizations proactively talk about their security incidents (big or small) has a significant impact on the credibility of their statements when they need it most. What are you waiting for? ### CUSTOMER CASE STUDY: Twilio URL: https://www.discernibleinc.com/customer-case-study-twilio/ Last updated: 2026-06-28T23:43:24.000Z ## A Creative Solution from Discernible Helps Twilio’s Security Team Increase Community Engagement The hiring market for cybersecurity talent remains extremely tight, with companies of all sizes competing for a limited pool of experienced security professionals. The current cybersecurity workforce gap is estimated to be 3.4 million globally, and it’s growing every year. This trend will only continue, which means companies must expand their reach to find potential new hires - which includes attracting people with non-security backgrounds or candidates who aren’t currently considering a career in cybersecurity. In a climate like this, one of the most effective ways to do this is through an organization's existing staff. Through speaking engagements, blogs, podcasts and other outreach, they can be a very effective megaphone for your company and help create a compelling case as to why security experts and other talented professionals should consider a position in your organization. ## The Challenge When she led the Security organization at Twilio, Coleen Coolidge understood the advantage of having current employees participate in speaking events, podcasts, blogging, and internal communications. This was part of her DNA - and the culture of the last company she worked at. She used this “security ambassador” strategy to great effect in her previous role as the CISO of the customer data platform company Segment. When Segment was acquired by Twilio, she wanted to replicate that approach to recruit high caliber cybersecurity staff to help protect Twllio’s sprawling businesses. However, at Twilio, the Security organization was larger, and external engagement from most of the teams wasn’t happening regularly. In addition, the organization included teams across the spectrum of security - including product and cloud security, risk and compliance, incident response, etc. So while there were a number of talented people solving a range of tough security problems, only a handful of them were sharing their expertise and experience externally. In turn, this made it even harder to find and connect with potential new hires. > “Security people care about who they work with and they want to work with smart people who challenge them,” according to Coolidge. She and her leadership team understood this was partly a cultural problem and partly a process challenge. Many were reluctant to get involved in external brand and community engagement because: - They didn’t feel they had the expertise or experience necessary to be “out there” publicly talking about how they were solving security problems - They were reluctant to ask for support or guidance to get more involved - There was no easy-to-find, single source of truth for what activities were happening, what opportunities were available and who was doing what, where, and on what topic, which made it difficult for leadership to consistently recognize and reward these efforts Coleen and her Program Lead, Lilah Knight, who spearheaded the effort to find a solution, knew that if they were to be able to share Twilio’s great work and engage with the broader security community - and potential candidates - they needed a frictionless solution to nurture a pipeline of advocates to get the word out. ## The Solution Discernible was brought in to find a creative and easily deployable solution to entice people from across the Security organization to speak, blog, and generally share the good work the teams were doing and engage more deeply with their cohort outside the company. At Discernible, we frequently see security teams and communications teams struggle to organize, assign, and track external - and even internal - engagement opportunities. If it happens at all, it often involves sifting through emails and spreadsheets, and requires hours of manual labor. Our approach to solving this challenge for Twilio was to “meet people where they are.” For their organization, that was on Slack. That’s where the security teams were already communicating with each other and their senior leadership on a regular basis. Rather than create yet another platform or deploy an out-of-band tool to post opportunities and track engagement, we wanted to leverage what already existed, both culturally and technologically. “Everyone was already on Slack and using it as an internal comms tool,” recalls Knight. “Discernible’s idea was to build a specialized Slack workflow and channel that could help automate the process end-to-end, from sharing the external engagement opportunities with the Security organization, all the way to automatically populating a tracker of completed engagements across all channels. We didn’t just want to make sure the team’s hard work was counted, we also wanted to understand trends among different teams, topics, and opportunities.” The solution needed to achieve several goals: - Automate the many steps involved in identifying, assigning, executing, and tracking external engagements - Incentivize participation and overcome the current reluctance to be involved - Leverage experienced and interested team members as mentors and coaches - Create a sustainable, single source of truth for existing and completed external engagements - Give team leads oversight of which projects were shared externally and provide supporting details for individual performance reviews To meet these goals, Discernible built and deployed a custom Slack workflow that automated the steps involved in Twilio’s external engagement process and included key elements to attract more participation. Specifically: - **Smart Sequencing:** To support team members at various stages of an engagement, Discernible built the Slack workflow to respond with customized actions based on the individual’s stated purpose. For example, team members with an upcoming engagement could trigger the company’s necessary content review process by responding to the channel’s pinned post with a particular emoji. Responding with different emojis would trigger a different sequence of actions for team members who needed to document manager approvals or who wanted to schedule a dry run with members of their team. - **Engaged Mentors**: A key blocker to greater participation was that often, employees weren’t confident that a topic they would like to speak about was valid or interesting. Or, if they selected an available topic, if they could speak to it appropriately. To overcome this, Discernible integrated a team of mentors into the process, who would sign up through the new Slack workflow to assist and guide fellow team members through the process. The new Slack workflow made engaging with a mentor to keep the momentum going easy. For example, an engagement opportunity would be posted, someone would express interest in the channel and that would automatically trigger an action in the mentor channel. A mentor would then sign up to assist and a message would automatically be sent to the team member who requested a mentor. 💡 Leif Dreizler, who was a security engineering manager at Twilio, was already acting as a reviewer/mentor when this solution was introduced. “It definitely made the whole process a lot easier because before, there was a lot of messaging back and forth, and people asking the same questions over and over. And, no easy way to track it all,” Dreizler said. “The Slack solution made the whole system much more efficient.” - **Automated tracking**: The Slack channel was connected to Google Sheets and would automatically populate it with existing and completed opportunities - including all of the key details around topic, channel, dates, content, etc. “It solved the pain of having all of this information living in random places,” recalls Knight. “And we could filter by team, topic, and other criteria to get an accurate picture of our outreach and engagement across the organization.” ## Results Coolidge’s goal was to increase participation across ALL teams within her organization. “We integrated a communications and leadership pillar into our OKRs,” she recalls. “The objective was to have current staff synthesize and talk about the types of security problems we were solving at Twilio, in order to attract the people we needed to help solve those problems.” Knight says there was a notable increase in external engagement as a result of the deployed solution. > “We saw an increase in people using external branding efforts and people started using the new workflow and channels right away,” she recalls. “It eliminated the fear that people had about going out and doing this on their own. People felt safe looking in the channel for opportunities because they knew they would get the support they needed.” For Coolidge, who was in a demanding leadership position with little time to spare, Discernible’s simple, yet powerful solution made a real difference. “I had never seen this process operationalized before. Discernible was able to take the whole process and build a sequential workflow, all the way from ‘I’m thinking about speaking or blogging’ to actually doing it,” she said. “It also ended up saving me and my team a lot of time, and for that, I’m incredibly thankful.” Coolidge, Knight, and Dreizler have since moved on from Twilio, each taking what they learned and experienced with Discernible into their new roles. We look forward to working with them on the next evolution of their journey. ### A CISOs right hand on how security communications can build credibility across the organization URL: https://www.discernibleinc.com/a-cisos-right-hand-on-how-security-communications-can-build-credibility-across-the-organization/ Last updated: 2026-07-29T21:11:21.000Z *Jessica Walters is Senior Security & IT Program Manager at Tessian, and former Chief of Staff to the CISO of Cisco’s Security Business Group. She is also a member of the Discernible Advisory Board. In this Q&A, she shares her perspective on how to use security communications proactively in building an effective security team.* #### **You have a strong background in the security industry. What attracted you to working in cybersecurity?** I actually landed in security by chance! Almost 10 years ago I was lucky to be located near Duo, a rapidly growing startup in Ann Arbor, MI. This was before remote work was so widely supported, so I was grateful for the vibrant tech scene that has long found a home in our midwest town. I had been learning as an executive assistant and Duo had an opening to support their founders and the executive team. I’m so glad they took a chance on someone with no security experience and very little tech background, because it led to many opportunities for me to jump into new roles in IT and security that I would not have been able to experience. It’s there that I first discovered security is a good match for my skills. #### **Within that realm, you’ve held a somewhat unique role: Chief of Staff to the CISO at tech giant Cisco. What was it like to be the right hand of a CISO?** It is by far one of the most fulfilling roles I’ve had the chance to define and occupy. As a Chief of Staff you are constantly in a state of learning and growth which I enjoy. You’re also a key component in enabling the efficiency, working relationships, and reputation of your CISO and entire team. I love the variety of hats you get to wear as you carry this type of torch for the team. However, it can also be challenging at times when you’re working hard to bring the rest of the organization along with the critical importance of security. #### **A Chief of Staff in any business unit has to wear many hats. What is different about supporting a CISO than say, a VP of Engineering?** Supporting a CISO is definitely different from supporting other C-Level roles because security is such a cross-functional discipline. It intersects with every single part of an organization. Not only do security teams have to focus on delivering against our team goals, we also have to influence and support the goal delivery of other teams against our security objectives. These goals aren’t always high priorities for them, compared to the work that drives profit for the business-such as feature development. It’s a balance between making sure we aren’t standing in the way of other teams progressing towards their goals while also ensuring that they understand why prioritizing security outcomes drives the business forward in an equally meaningful way. #### **You had a firsthand view of what CISOs struggle with as leaders. What did you observe/learn in that regard?** By far the biggest challenge I see facing CISOs is the constant state of “educating the business” or evangelism they have to live in. They are constantly walking uphill, bringing the business along to understand why security matters. At the same time, they are always putting out fires and often must walk the organization back from decisions that inadvertently open up the business to risk. This can be emotionally exhausting and I suspect is why many in this role fight burnout. I think the root of this problem stems from the second biggest challenge I see facing CISOs, which is not being included in critical conversation points. Some of the ways I’ve seen this manifest include: - The CISO is not considered an actual part of the executive team. This can be because of reporting structure (ie, the CISO reports to the CTO), or because of organizational hesitance to expand the size of their executive team. In this case, the CISO is unable to ensure that securing the business and its customer’s data stays at the forefront of strategy building conversations. And, in the case of companies building security software, an opportunity to have your in-house “voice of the customer” in early product strategy development is completely missed. - The CISO is not given an opportunity to interface with the board of directors. The board should understand and care about security investments and the best way to ensure that is to allow them to develop a healthy working relationship with their CISO. This is even more important in organizations that are building security software; your CISO is the best and most accessible asset the executive team and board of directors have in understanding the perspective of their customers. I have partnered with my CISO and others who are experts in this field, like Discernible, to develop content for the Board that is meaningful and builds trust in our CISO, and by extension with our entire executive leadership team. - The CISO and security team are not treated as an equally important pillar within the product development organization. I have worked in organizations where Engineering and Product have a very tight and well defined working relationship that was crafted without including the security organization. In this case, the security team is in a constant state of catch-up in the product planning and delivery processes. It’s inefficient and opens up the organization to unnecessary risk. #### **Tell me how strategic communications help a CISO get the outcomes they want, including budget, staffing, board support, etc.** Every communication coming from the CISO and security organization is incredibly important. You want the mission and goals of your security organization to be well understood and accessible by everyone so your partners in the business understand and appreciate how security intersects with their area of focus. Strategic, thoughtful communications really have the power to [reduce friction](https://www.discernibleinc.com/exercising-influence-as-the-security-team-look-for-friction-not-just-fuel/) and make the security evangelism process easier, which, as I mentioned, is a big part of every CISOs job. Clear, consistent security comms also have the power to make everyone in the organization feel empowered to contribute towards running a secure and trustworthy business. #### **As Chief of Staff, how were you able to use communications and comms experts to help your CISO be successful? Are there specific methods, tools, approaches you found worked particularly well?** Because the CISO is often incredibly busy with other parts of their role, communication efforts are likely to fall to their Chief of Staff or other team leaders. I’ve been lucky to work with Discernible in the past to help us refine and improve the communications coming out of our team. Some methods we’ve found important include: - A clearly defined security team mission and guidance for the team on how to actually live it. For example, what behaviors are expected from an organization with your mission and how should it be used by your team in decision-making? - A simple and easy to understand way to access your security team. - Meaningful reporting that captures the security team’s impact (not just [outputs](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/)). - A regular cadence of live opportunities for the CISO and security team to share learnings and provide transparency to the value their work delivers. - Communications coaching for team members transitioning into new roles or stuck in a cycle of ineffective communications with a colleague. Effective communication often requires individuals to master multiple communication styles and be able to switch between them at the right time. In my view, the most important part of all communications is transparency, wherever possible. Leading with transparency around what security actions you are taking - and why - is the best way to build trust with your security organization. #### **You also spent several years as a Security Program Management Lead at Duo. How did that experience help shape your approach to security communications and working with CISOs?** Duo was such a unique and special experience. I often say “I’m jaded!” because I’m not sure I’ll ever have the good fortune of experiencing such a genuine interest and care in always doing the right thing - for your people, for the business, and from a security perspective. I think this really was possible because the founders led by example and operated with this mindset from day one. They hired people who were passionate about security and understood the importance of securing the business and delivering a product that enabled our customers to do the same. It became part of the organizational DNA - everyone felt a part of our mission to “democratize security.” This strategic communication choice drove a sense of purpose in everything we were doing as an organization. I carry this mindset with me as I continue to think about building security programs and supporting CISOs. It’s not just about putting the right words on paper when building your organizational security plan…it’s about connecting your team and peers with a really important mission. #### **You say in your LinkedIn profile that you “feel strongly that we are humans before professionals, and I enjoy helping build teams that value this approach.” Given the stressful, often-chaotic nature of SecOps, how can teams create and maintain a human-centric approach to their work?** I’m SO passionate about taking care of people. This is true in general, but especially in SecOps and all security roles, you have to give people the space and support they need to show up as their full selves. Who we are at work is such a small part of the human experience and when we expect people to come in each day as only their work-selves we miss a really easy opportunity to build a trusting and safe team dynamic. We also have to give our teams the ability to recharge. This means holding each other accountable for taking time away and actually disconnecting when we do it. Leaders within your security organization play a huge role setting the tone within a team on this front. Managers have to trust their team enough to step away and also set healthy work boundaries every day (make scheduled messages in Slack your friend!) *To learn more about how Discernible can help you scale as Chief of Staff to the CISO, contact us* [*here*](https://discernibleinc.com/contact?ref=discernibleinc.com)*.* ### How Security Communications Gives Recruiting an Edge URL: https://www.discernibleinc.com/how-security-communications-gives-recruiting-an-edge/ Last updated: 2026-06-28T23:36:20.000Z *Lauren Bryant has worked as a senior technical recruiter at Uber, Paypal, Lime, and more. Here, she discusses the critical relationship between recruiting and communications teams when it comes to hiring the best and brightest in cybersecurity and technology today.* #### **What sets security recruiting apart from other tech disciplines?** What fascinates me about finding talent in the security space is that all of the candidates have such interesting backgrounds. They typically don’t have a traditional career path or educational background and that intrigues me. #### **How have the expectations of cybersecurity candidates changed over the last few years in terms of what they expect companies to share publicly before considering a role on their team?** Candidates are increasingly interested in a company's security stance and approach. These days, security breaches are highly publicized, and most informed candidates will research these things prior to interviewing, which may or may not form their opinion about a company and its security team. This research often includes how they handle data breaches and the company’s commitment to maintaining privacy. #### **How can communications colleagues can help you as a recruiter.** Security communications matter in every company. Often recruiters aren’t in the loop or armed with the right messaging and talking points about a company’s security posture – or if there has been a security incident or other reputation-affecting situation. Not all tech candidates will ask about these things, but security candidates often want to know. I want to be as honest and transparent as I can be with potential hires, so having accurate information from my security communications colleagues makes a big difference. Some companies are better at this than others and that impacts how they’re perceived by candidates even before they start interviewing. #### **How can companies demonstrate to potential new hires that they take security seriously?** It’s important for security leaders to be communicating externally and on a regular basis about the importance of security and what their teams are building. Security professionals are attending conferences, reading blogs and research - and security is a small industry - everyone knows everyone else, so people know each other and their reputations. All of this matters when it comes to attracting top talent, so I really appreciate security communications professionals who can provide a proactive and ongoing cadence of resources. #### **How can a company distinguish themselves when hiring for security?** A lot of people work in cybersecurity because they want to make an impact, so it’s important to be clear about the potential impact a candidate will make on the company or community overall. For instance, at a fintech company, security teams are critical in protecting the financial assets of your customers - I would stress that in your communications with candidates. I also think sharing as much as you can about budgets for training and possibilities for career growth is helpful, including offering communications training to help individuals succeed in cross functional roles and when transitioning from IC to management roles. It’s also good for security recruiters to meet with the CISO on a regular basis, to learn and understand their program and priorities so we can speak to that when talking to candidates. Additionally, stay in close collaboration with your security communications colleagues to ensure you have the materials you need to put your best foot forward on behalf of the security team. After all, recruiters may be the only person a candidate speaks to before deciding whether to apply to a particular role - we are the face and voice of the company, and in security, reputation matters. ### Not Just Security: CISOs are Business Executives URL: https://www.discernibleinc.com/not-just-security-cisos-are-business-executives/ Last updated: 2026-07-14T21:34:26.000Z *Earning legitimacy with your team and your board as a security leader* Years ago, Discernible was engaged by the CISO of a large security organization to repair the reputation of their team among both technical and non-technical partners, and restore their credibility and influence within the company. Unfortunately, the CISO’s predecessor took an adversarial approach to work with other business functions and soured relationships that the security team needed to succeed. Once we took inventory of how the security team and their partners felt about each other and their shared responsibilities, we got to work building a proactive communication program for teaching the security team the strategy and execution skills required for rebuilding trust with their peers at every level of the organization. Every member of the team had a role to play in turning aspirations of influence into a reality in order to move meaningful security work forward. Yet, the most important factor in their success was the commitment and credibility of the CISO who understood that their job wasn’t to dictate security policy or controls on the business, but to empower their team with the resources and relationships needed to effectively solve security problems that propelled the business. ## CISO: Chief Influencer for Security Outcomes Late last year, we published a [blog post](https://www.discernibleinc.com/knocking-on-the-boardroom-door/) from Dr. Anthony Vance, Director of Pamplin Integrated Security at the Pamplin College of Business at Virginia Tech, about his team’s research on behaviors that inhibit or facilitate a CISO’s legitimacy in the eyes of the board and C- suite executives. A few weeks ago, *Harvard Business Review* published an [article](https://hbr.org/2023/06/how-new-ceos-establish-legitimacy??ref=discernibleinc.com) from Harvard Business School professor Nitin Nohria entitled “How New CEOs Establish Legitimacy.” The article underscored some of the same themes and opportunities that Dr. Vance’s research uncovered related to how CISOs earn and keep legitimacy – and also emphasizes a point made by one of our advisors, Glenn Thorpe, in his recent [blog post](https://www.discernibleinc.com/every-security-decision-is-a-business-decision-communicate-accordingly/): security decisions are business decisions. It’s not surprising to see this convergence, but it is still exciting to see. As security becomes a bigger priority for business leaders (or if we want to make it one), the CISO role has to be performed as a business executive position, not a “smartest security expert in the room” position. In fact, establishing legitimacy is critical for any business leader because it’s the most sustainable and effective in the long run. > “Authority alone provides a limited license to lead. We listen to those in authority because we’re required to do so; authority motivates via a follow-the-rules mechanism that will never encourage someone to go above-and-beyond the call of duty.” - Nitin Nohria You may already be familiar with authority-based leadership, a formal power with decision-making rights (usually associated with a job title), or competence-based leadership, which is focused on performance. However, as Nohria explains in his article, legitimacy-based leadership is based on behaviors and actions that inspire others’ trust, respect, and commitment – which makes it more sustainable and effective in the long run. Both the *Harvard Business Review* article on CEO legitimacy and Dr. Vance’s research on CISO legitimacy emphasize the importance of an effective communication strategy and execution in earning and maintaining legitimacy as security leaders. ## Learn the Business Research findings from the team at Virginia Tech found that with increased legitimacy comes increased support and collaboration. Through hundreds of hours of interviews, they found this process requires CISOs to proactively engage with business leaders as the primary driver to demonstrate they are a legitimate partner. The researchers observed that proactive communication with board members is a common pattern among more successful CISOs. Dr. Vance’s team also discovered how important it is for CISO communications to show that they understand the company’s business priorities, a theme echoed by the research from Harvard. ## Teach the Business to Your Team Nohria’s research in business leadership aligns with decades of communication research showing that compelling narratives help employees understand where the organization is coming from and where it is going – and they’re drawn to leaders who can talk about that vision with accurate, honest, and clear direction. “It helps even more,” Nohria writes, “if the leader can clearly explain how the organization needs to adapt to critical external changes to win and each employee’s role in contributing to the organization's success.” Nohria is writing about CEOs here, but if there was ever an overarching vision for how a CISO should think about their personal communication and that of their team with everyone from board members to colleagues across all business functions, this is it. You might think this would already be a prerequisite for becoming a CISO. It’s not (yet), but it’s certainly a good indicator of how successful someone will be in the role. CISOs need to be able to influence people who don’t report to them. ### Every Security Decision is a Business Decision. Communicate Accordingly. URL: https://www.discernibleinc.com/every-security-decision-is-a-business-decision-communicate-accordingly/ Last updated: 2026-07-14T21:31:18.000Z *In this Q and A, Glenn shares his insights into why understanding business and how to communicate effectively is critical for anyone working in cybersecurity today.* --- **Your trajectory in the cybersecurity field has been a little non-conventional.** True - I started in the world of academia, focused on endpoint security. Cutting my teeth on cybersecurity in a university setting was both good and challenging. Higher education is a little bit of a mishmash of technology and data, and you have to be creative with how you solve problems because there is very little funding yet you’re responsible for a lot. And, there are an insane amount of regulations. Plus, you’re responsible for security for a whole array of people; from faculty working on research who want unfettered access to everything, to students living in dorms. So it’s a mix of regulated data and research data, and you get exposure to a lot of different attacks and incidences. You’re responsible for all of those access points and making sure they don’t get breached. **How did that experience prepare you for leadership roles in the private sector?** Because I had to communicate (as a then-young person) with PhD professors about why we need to do certain things to keep everyone secure, I had to really up-level how I communicated. That taught me the importance of communicating in the language and context of my audience. In academia, you don’t have a big stick - you have to persuade people why security matters, in contrast with a corporation that may have policies and controls and a broader understanding of the importance of security. These are critical communication skills for anyone working in security to develop, as early as possible. That’s why when I’m interviewing and hiring people, I am always willing to talk to someone with experience in academia. It’s a great foundation for learning the importance of looking at the big picture, including how to tie security to individual and organizational goals. **The need for security experts to understand the business they’re working on seems to come up a lot these days. Why is that?** I approach it this way: every security decision is a business decision. And getting your hands dirty in some of the fundamental aspects of business - things like budgeting, managing contractors, etc. is really important to succeed in security today. It helps you understand why decisions are made, often several levels above you. Sometimes security folks want to buy a $50k control to address a $5k risk. In my career, I’ve intentionally taken roles that exposed me to business strategy, to be the bean counter, and think about where we can align security with the business to be more efficient. **Why is it sometimes challenging for security experts to learn business communications and use it to grow their career in cybersecurity?** The industry tends to value strong technical skills, which can make it hard - because when you’re a technical person, it’s like “a pipe is leaking, we need to patch the pipe” - and then move on. They have a lot to do. Yet, we also need to give people the creative space to think strategically and learn about the business side so they can step back and think about the why of security: why isn’t this program or strategy working? Otherwise they can get stuck in a rut or they lose confidence because decisions are being made by the business that impact security and they don’t understand why. Then they can feel like, “I’m not going to try because they are not listening to me.” It boils down to giving people the ability to be creative, get more training, etc. At the same time, it’s the responsibility of security leadership to communicate the business rationale to their teams. I previously had a role that sat between customers and their 27/4 security monitoring teams. So I took all the business skills I’d learned up to that point to help partner with customers on their planning and strategy, help them mature their programs, and give them the ammunition they needed to present to their Boards and leaders. Learning and using these skills isn’t really rocket science, but the lack of business communication skills can have an outsized negative impact on your career. **What are three things you wish every security professional would remember as they try to grow in the industry and improve their communication skills?** 1. **Don’t assume people know what you know**. You need to figure out a way to communicate to business leaders in a way they will understand. And don’t assume a “no” today is a no tomorrow. Things change so much and so fast in our field - we really can be new employees forever. 2. **Complete the circle**. If something goes wrong or you hit a roadblock, don’t just move on. I know everyone is busy but it’s important to close the loop, especially if something didn’t end up the way you hoped. Do a retro and share with others what happened - what were the influencing factors here? What can we do better next time? 3. **Invest in communications and business training**. You need to learn to communicate succinctly across the organization, particularly to business partners and leaders. Maximize your elevator pitch to match their priorities. And that requires pre-work. Don’t just walk in with your idea for your one control and hope to get a green light. Tie it to the big picture of the overall business. Personally, I continue to learn and grow my communications and planning skills. I recently took Discernible’s “Decision Making as a Team” trainings and left with a matrix and a framework to document how decisions are made. It was cool because the mapping out and documentation is a great way to show people how you got to where you are. It is a kind of receipt. It closes the loop and keeps the trust. Getting expert training like that can really help, no matter how long you’ve been in the industry. I’m learning something new all the time. ### Keep Calm and Plan On: Expert Advice on Incident Response Communications URL: https://www.discernibleinc.com/keep-calm-and-plan-on-expert-advice-on-incident-response-communications/ Last updated: 2026-07-14T21:32:44.000Z *Q&A with* [*Brooke Pearson*](https://www.linkedin.com/in/brookepearson/?ref=discernibleinc.com)*, Senior Director, Technical Program Management at AlphaSense and a Discernible Inc advisor.* --- ## Q. What’s the difference between security communications and incident response communications? Or is there a difference? Ideally speaking, security awareness communications and internal incident communications should both be proactive. They need to be in place long before there's an incident, in order to build muscle for employees to be able to respond to an incident and know how to spot security vulnerabilities. So that’s what they have in common. However, there are some important differences for incident comms, there are more guardrails around what can be said publicly about a security incident. The incident could be related to an insider threat or there could be legal considerations that restrict how much can be communicated. Also, incident response communications usually follow a “playbook.” Not every company has one but it’s a really good idea to put one together. Usually these are targeted, based on the audience, type of incident, etc. That way you have a plan and [sustainable system](https://www.discernibleinc.com/turning-incident-response-communications-into-a-sustainable-security-communications-program/) in place for what you need to communicate and to whom - like to execs vs. external partners and so on - and you spell out how often you will be updating them. On the other hand, internal security comms are often designed to tell employees what they can do, and at a high level, what the company is doing to address risk. ## Q. What do companies sometimes overlook when putting together an incident response communications plan? The best companies involve their information security, IT or tech support teams, and their physical security teams in building playbooks and running drills. Often, IT and physical security teams are overlooked when creating a playbook, even though there are overlapping communications that need to happen during an incident. For instance, I mentioned earlier the example of insider threat - your playbook should include physical and information security guidelines to staff and also users affected during incident triage. While the teams may not use the same playbook per se, their plans should speak to one another and be consistent where possible. Another mistake I have seen is that playbooks are created, but when an incident happens, no one can find it. This one is tough because (particularly for highly sensitive information) some of the content may be confidential. So you don’t want to put it on a SharePoint or something like that. Ideally, it sits somewhere where anyone who is on-call or anyone who is a cross-functional partner of the security team should be able to access it at any point, usually with a short URL or a shortened link so that they know exactly where to go. A few other tips: Avoid using jargon and acronyms without defining them, no matter who the audience is, no matter how technical they are. It can cause confusion at a time when you need clarity. And avoid long emails for incident comms. Keep it brief, and include a short executive summary at the top with the most pertinent information, including mitigation status and an expectation of when the next update will be shared. ## Q. Beyond the obvious, how do Incident Response Communications plans help security teams within an organization? When done well, a good incident response communication plan inspires confidence in your leadership team; You need your security leaders to communicate well with each other and key stakeholders during a crisis. It’s also important not to overpromise and under deliver in your plan. You should set expectations around the cadence of communications - because in the beginning of an incident, there are always a lot of unknowns. Saying “we’re not sure what’s going on but we’ll keep you posted” is not a plan and it’s not what executives want to hear. Ideally, you are honest and brief, and commit to a timeline for keeping folks up to date. The best thing that a security team can do to build that credibility is to have a well-baked plan that includes cross functional partners; for instance your legal, public policy and external comms teams, etc. Their job is to communicate externally, and the more you’ve developed that relationship and incident response processes, the more they can help you when it matters. ## Q. What is something communications teams can do before an incident happens to help things go better when one arises, which it inevitably will? Be really proactive about getting time with executives and team leaders to educate them about the plan and playbook. These people are busy, but try to add it as an agenda item to an existing executive meeting. You want to build relationships with the people who will be impacted when an incident occurs. Even though incident response as a function or responsibility may report several levels down, they need to know you have a playbook and that it addresses the most significant business risks. I would also add that teams should invest in getting expert help from a resource like Discernible to build their communications plan process. So many companies - both large and small - do not have the internal resources to think through the various scenarios and put a workable plan in place. The best thing they can do is put in a little proactive effort now, so when that dark security incident day comes (and it will!) they are really, truly ready. ### Words with Impact: Communication Tips for Privacy Technologists URL: https://www.discernibleinc.com/words-with-impact-communication-tips-for-privacy-technologists/ Last updated: 2026-07-14T21:22:40.000Z I recently had the pleasure of speaking with Debra Farber on the [Shifting Privacy Left Podcast](https://shiftingprivacyleft.com/audio/8323/458099?ref=discernibleinc.com) to share some of my experiences as a communications strategist working with privacy engineering teams. *\[Disclosure: I’m blessed to consider Debra a good friend and we serve together as advisors to* [*The Rise of Privacy Tech*](https://www.riseofprivacytech.com/?ref=discernibleinc.com)*.\]* We covered a lot of ground in less than an hour, including how to use technical communication strategies to earn trust with external stakeholders. I’m digging deeper into that topic here. ## Earning Trust Through Technical Communications During my conversation with Debra, I touched on the prerequisite of authenticity for effective communication. While interviewing for my former role as head of security, privacy, and engineering communications at Uber, I reminded one of the panelists (with whom I had worked with previously at another company) that my approach had not changed — my priority would be to help the team become the organization it aspired to be so that our external messaging and engagements accurately reflected what we wanted to be known for. I’ve never been the right person to call for organizations hoping to spin or mislead public perception, and I built Discernible on the principles of telling the truth, proving it with action, and realizing that the true character of an enterprise is expressed by its people. A prospect once told me they were comfortable operating in the gray because of their experience in PsyOps for the US federal government. I made it clear that I was not comfortable operating in the gray, not only because of my personal values but because buried bodies are a costly tax on public trust. Every privacy organization experiences bumps in the road, and before we can expect to receive the benefit of the doubt for honest mistakes or unforeseen challenges, we need to introduce our stakeholders to our commitments and capabilities. If your stakeholders don’t already believe privacy is a priority for your business, you’ll face a steep uphill battle to convince them during an incident. I outline the reasons why in this previous [post](https://www.discernibleinc.com/communication-gaps-in-security-and-privacy/) and tips for how to avoid privacy outrage [here](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/). > “The job is not to tell a story to get people to believe something. The job is to get the enterprise to be worthy of trust... helping the enterprise to define itself and to actually become authentically who it aspires to be, so that the story that you tell about it is authentic and accurate.” - [Roger Bolton](https://www.ethicalvoices.com/2023/04/17/we-must-confront-the-uncomfortable-truths-roger-bolton/?ref=discernibleinc.com), President, Arthur W. Page Society Way back in 2009, Marc Andreesen predicted that software would eat the world. Now in 2023, there are few organizations without technical dependencies and investments, including how they protect corporate assets and treat personal information. Learning how to effectively articulate those programs proactively is critical to not only becoming the enterprise you aspire to be through partnership with cross-functional teams, but also to ensure that the stories you tell externally are accurate, enabling your stakeholders to consider giving you benefit of the doubt when you need it. That’s trust. ### Turning Incident Response Communications into a Sustainable Security Communications Program URL: https://www.discernibleinc.com/turning-incident-response-communications-into-a-sustainable-security-communications-program/ Last updated: 2026-07-14T21:15:42.000Z A recent piece in GitHub’s ReadME newsletter about moving from [incident response to resiliency](https://github.com/readme/guides/incident-response?ref=discernibleinc.com) got me thinking: shouldn't that also happen for incident response and security communications? In the GitHub article, the author Will Larson (CTO of Calm) does an excellent job of laying out, from an engineering perspective, how to get beyond the rinse and repeat cycle that occurs between incident notification to mitigation, and build a process that results in greater *reliability* so that there are fewer incidents to begin with. Wouldn’t that be nice? Much like the often-messy technical process of incident response, security communications are frequently created on the fly, by many cooks, with little forethought (due to time constraints) and even less afterthought. This results in a security and incident comms process that is anything but resilient and sustainable, and can leave everyone from external comms to executives annoyed at why something as simple as getting a message out always seems to be so hard. In short, the process feels unreliable, and the amount of work that goes into managing it is often unsustainable. I see this firsthand with a lot of our clients, which is why I think it’s important to focus on your incident comms program before you ever need it. And trust me, you will need it. The best incident response communications are built on a foundation of strong, ongoing security communications. Here are a few thoughts on how to do that. I’d be happy to share more specific tools and approaches you can try if you’d like - just reach out to me. ## **Do Your Homework** If you have the luxury of time (no one does, but still) it’s worth doing an inventory and analysis of how incident comms have been going. Look at the last six months to a year of messaging and engagement (internal and external) to see if there is consistency and clarity to the comms that have been sent. Make note of what seemed to land well as well as what added to or subtracted from your credibility. Talk to the receivers of these messages. What do they think? You may be surprised at what you hear. If you work in a mid-size to large org, find out who else might be “doing crisis comms” and will come out of the woodwork when you least expect it. They may send out duplicate messages, or almost worse, be responsible for a certain audience segment (ie, field sales) and not be sending incident alerts when they should be. Document all crisis/incident/security comms currently being developed so you’re not caught off guard and build their work into your program. ## **Build Your Bench** Relationships are one of the most critical - and most often overlooked - aspects to building a sustainable security comms program. The time to make friends with the folks you’re going to need on your side when the you-know-what hits the fan is *now* \- before it does. It’s much harder to make friends when things are already on fire. Identify who in your ecosystem is key to your success – people with the knowledge, credibility, and clout to either amplify or confuse your message. This can include external security experts, academics and researchers, advocates, business partners, law enforcement; oh, yes, and politicians (they have a history of getting real loud about anything that scares them or could be hijacked for media sound bites). Talk to these people often - don’t wait until you’re in a crisis. Keep them informed of what your security organization is up to, where you’re making investments, etc. You can also talk about the weather and buy them coffee (and you probably should). The point is to build and maintain these relationships, because you’re going to need them. ## **Bring Consistency to Decisions** This is all about scenario planning, and being prepared for all of them with pre-approved priorities, values, and principles for how you will communicate in those situations. The goal is to accelerate sound and fast decision-making by getting buy-in up front about roles, responsibilities, and expected responsiveness. In my experience the greatest source of friction and delay in incident communications is caused by seemingly arbitrary input from stakeholders about what to say and how to say it. I’m not talking about legal language required for certain situations, but rather things like how do we demonstrate empathy and avoid coming across as defensive? And who makes that decision? We worked with a client to help them define and secure stakeholder consensus on their principles for security communications – and thus, subsequently, also incident communications. A few of the principles we landed on were: - Be front-footed and transparent with employees - Prioritize communications that build customer trust Why are principles helpful? Because no matter who is writing or editing the communication – whether it’s PR, legal, customer support, or someone else – it’s already determined upfront that employees will get the whole story (and as a result, we should prepare for what this will mean for other audiences like customers, potential plaintiffs, and media). This client decided holding back from employees was simply not an option. Stating that communications that build customer trust is a priority for incident communications gives every function in the company permission to put aside content and messaging they may have planned for any given day in order to prioritize a security message. Securing cross-functional buy-in for this approach – and documenting what they would need from security in order to accomplish this during an incident – was also part of our process in defining the communication principles in the first place. ## **Make it true before you need it** This is where an ongoing and proactive security comms program really shines because not only does it serve as a mechanism through which you can nurture the relationships you need, it also gives you daily practice in applying your principles and engaging in your decision-making process. Not every incident is going to be a major breach – it might just be a negative news cycle about a product feature whose “creepiness” facture you underestimated, or a FUD-driven vendor whose most ingenious marketing strategy is to publish “research papers” with unverified claims against you for shock value and shallow press attention. Just like the major breaches, these incidents pull resources from other priorities, can incur costs even after the attention subsides, and are often resurrected by journalists, regulators, and the security community to fill holes left in your next incident communication. Regardless of the specific incident, there are things you will wish all these people knew about your security program in advance. Things like which authentication standards you use, user and employee account security controls, and your strategy for supply chain security (remember [3rd party incidents](https://www.discernibleinc.com/third-party-security-incident-response-communicating-even-when-youre-not-exposed/) impact you, too). These are all very common issues that come up in both small and big security incidents, but you won’t have enough real estate in any single communication to explain the technical details or the fact that your approach has been maturing for years. Those educational resources, for the stakeholders who want them, should be published yesterday and updated as needed. The worst time to try and convince someone that you prioritize security is after an incident. Do it now so it’s available as a link, leave behind, etc. when you need it. A best practice is to make it easy to find in an online Trust Center, and we’ve built dozens of these for our clients over the past few years. While the upfront (and ongoing) work in building a security comms playbook that contains runbooks, processes, contact information and more can take some time, it’s time well spent. Because it puts you in the driver’s seat when an incident occurs and you’re able to respond quickly with the right messaging to each unique audience. Over time, this builds trust between you and the people who count on you for immediate and accurate information.. ## **Do a Reality Check** Cybersecurity and corporate trust issues are ever-evolving. At the same time, internal organizational changes and fluctuating priorities are a permanent reality. So while you can put rigor and consistency around your incident communications program, it’s never really done. You need to constantly audit its impact and always conduct incident post-mortems that focus on comms. You’ll want to avoid frequent revisions and updates to your program of course - remember, this is about creating a sustainable and consistent process - but if the environment demands it then revise or update your approach. And remember that incident response comms are but one part of the overall security communications program. Internal messaging around security training, security strategy as a business advantage, privacy controls, and more are all important streams that shouldn’t be siloed from incident comms - they are all parts of a very important whole. ### Communication Measurement and AI URL: https://www.discernibleinc.com/communication-measurement-and-ai/ Last updated: 2026-06-28T20:10:45.000Z Last month, the Measurement Commission of the Institute for Public Relations [published](https://instituteforpr.org/measurement-roundtable-novel-ways-to-measure/?ref=discernibleinc.com) a summary of their recent discussion on new and innovative approaches to measurement. Many of their comments are likely familiar to most seasoned communication practitioners, e.g. “Aligning measurement objectives will help organizations measure what is meaningful for their decision-making.” Yep, of course. At the same time, I’m seeing a lot of industry commentary on the use of AI for doing communication work, e.g. creating written content like blog posts or emails. First, if the blog posts we’re writing can be replaced with ideas scrapped from existing sources, perhaps you could use a bit more originality in general — and if you’re a manager using ChatGPT to skip having to think about the messages you send to your team, we should talk. They deserve better. However, I believe there is a lot of promise for AI in making it easier and more cost-effective for organizations to adopt an outcomes-based approach to measurement instead of merely counting outputs. Imagine, for example, that we could use AI to quickly and more expansively track the impact of the specific content, language, and timing of incident response communications. Could we finally convince business leaders and lawyers that “your security is our top priority,” undermines the credibility of everything they’re about to say? What about whether specific characteristics of an incident are likely to impact a company's stock price or political climate? What kinds of engineering projects will be the most compelling for recruits over the next six months and do we already have a robust library of public content to attract them? We understand a lot of these considerations today based on qualitative research and measurement — which are invaluable for understanding the expectations of our stakeholders — but quantitative measurement is an area where I believe AI could help improve the effectiveness of our counsel. That said, data is only half of what we need for an effective communication measurement strategy. The other half is being able to break down that information into messages that our audience can understand. That’s why it’s so important for managers and individuals leading in unofficial capacities to understand that the empathy we put into communicating with our teams can’t be reproduced by anyone or anything other than you. Please do not use AI as an excuse not to improve your own communication skills. AI can help us refine our effectiveness and reduce inefficiency, but it’s still our responsibility to develop and care for others — human to human. ### CUSTOMER CASE STUDY: Trail of Bits URL: https://www.discernibleinc.com/customer-case-study-trail-of-bits/ Last updated: 2026-07-14T21:13:36.000Z ## How Discernible Helps Leaders Communicate with Impact --- Effective communication is the currency that enables leaders to build trust, credibility, and productive teams. *Ineffective* communication in the workplace can be costly. A business with 100 employees spends an average downtime of 17 hours per week clarifying communication. That amounts to a loss of $528,443 annually, according to Siemens. Often, miscommunication comes from the top – executives, senior leaders, and managers. It’s not like they aren’t trying, however. Studies show that leaders spend a whopping 80% of their time communicating. At the same time, 96% of executives say that ineffective communication leads to workplace failures. Recognizing the need to improve their communications is essential for any leader who wants to foster productivity, transparency, and a healthy culture. > **The Five Biggest Costs of Miscommunication** > > Inefficiency > > Employee turnover > > Impaired judgment > > Lower work quality > > Frustrated customers #### **The Challenge: Getting to the Point, Quickly** As the Vice-President of Software Assurance Practice at Trail of Bits, which secures some of the world's most targeted organizations and products, Nick Selby leads a large, geographically distributed team of software engineers and security researchers who audit and strengthen the security of various products and networks for large private enterprise and government customers. And that requires a lot of communicating – in all directions: to the senior leaders of the company, to his peers across the organization and to his direct reports, and their teams. And, to audiences at industry events, to customers, and even to the press. That’s many different audiences, each with different needs in terms of what they need to hear from him. However, he really had only one communication style: “Basically, I talk too much,” Selby said. “Being exuberant and passionate when I speak helps keep people engaged, but it’s easy to get so caught up in that energy and all the details that *I think* are interesting that sometimes the most important takeaways get buried or diluted.” Having previously worked with Melanie Ensign, Founder of Discernible, Selby knew she could help him improve his communications skills. “I noticed that Melanie has a rare ability to speak in headlines and get right to the point in a compelling way. Our CEO Dan Guido has that, too - these are people who can be brief without sounding abrupt. I wanted to learn how to do that,” Selby said. #### **The Solution: Succinctness Training with Discernible** To help Selby better focus on only what was necessary to make his point, Discernible held a focused 1-1, three hour “Succinctness Training” session. This practical, interactive approach focused on using real world communications from Selby’s daily responsibilities and then learning how to improve them. The session trained Nick on specific skills such as how to be strategic, yet brief, and how to “plan a path” for messages to land well. “Every conversation has a desired outcome,” notes Melanie Ensign. “Whether it’s demonstrating concern for a friend or collaborating with our teams at work in pursuit of specific business results. Learning how to be succinct and effective in our communications means understanding our communication goals upfront and enables us to achieve them.” #### **The Results: Greater Control Over Communications** “My training made an immediate impact,” Selby said. “I noticed when I gave an on-stage presentation that I was able to answer a complex question succinctly, using the skills I learned from Discernible’s training.” This foundational training gave Selby essential techniques to build on as he continues to work on his messaging. “Today, I’m more effective in my communications because I know how to prioritize what I want to say and plan an effective strategy for helping others understand the points I’m making.” Selby’s team has noticed - and even turned to him to learn how *they* can communicate better. “Open, trusted, and clear communications is really embedded in our team’s culture,” Selby adds. ### Communication Research Takes on the Myths of Privacy Compliance URL: https://www.discernibleinc.com/communication-research-takes-on-the-myths-of-privacy-compliance/ Last updated: 2026-07-14T21:12:25.000Z Last week, the *New York Times* published an [article](https://www-nytimes-com.cdn.ampproject.org/c/s/www.nytimes.com/2023/02/07/technology/online-privacy-tracking-report.amp.html?ref=discernibleinc.com) on low privacy literacy rates among consumers. The article is based on a recent [study](https://www.asc.upenn.edu/sites/default/files/2023-02/Americans%5FCan%27t%5FConsent.pdf?ref=discernibleinc.com) from the Annenberg School for Communication at the University of Pennsylvania that looked at Americans’ opinions about and understanding of privacy, surveillance, and technology. For a comprehensive overview of the report’s findings, I highly recommend reading the *New York Times* article. In this post, I will be focusing on the research itself and why I’m so excited to see communication researchers tackle important questions in privacy. ## **Communication Research Helps Identify Holes in Legal Outcomes** Not all laws are effective in the sense that they may not be written well enough to ensure adequate compliance or enforcement, they may further entrench social inequalities, or they simply miss the mark in achieving their objectives. I’ve observed privacy laws in the United States struggling with all three. I am not a lawyer and so I will not argue on statute or precedent, but I will argue on the basis of what I’m formally trained and experienced to evaluate: whether certain efforts in human communication result in intended or unanticipated behavior, to what extent, and with what impact. The research from the Annenberg School for Communication highlights at least two key communication failures in current privacy laws that rely on consent: 1. The definition of “consent” appears to be up for debate even in our laws – and that’s just silly to me as a communications professional because ill-defined terms essentially block mutual understanding. It’s impossible to consent to something you don’t understand and it’s possible for companies to prove compliance with consent-based laws if they’re not expected to measure whether people actually understand their data practices and what they can do about it (see my [previous post](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/) on outputs vs outcomes). A privacy policy or public statement is merely an communication output, not an outcome (e.g. genuine consent). 2. Americans lack “knowledge of commercial data-extraction practices as well as a belief they can do something about them.” I’ve seen this happen when organizations know consumers would make different choices if they had all available information. The FTC isn’t currently amped up on investigations of dark patterns for no reason. But this can also happen when organizations fail to research what consumers truly understand. Regulators fall short here too. There are plenty of legal provisions that require organizations to use incredibly ineffective communication tactics (more on privacy policies later). 🫠 Privacy counsel extraordinaire [Brandi Bennett](https://www.linkedin.com/in/brandibennett/?ref=discernibleinc.com) told the attendees at last month’s Enigma Conference that [“consent is the fiction at the center of our profession.”](https://youtu.be/%5FIvPS4o7b-w?ref=discernibleinc.com) I believe these communication failures are a big reason why consent has failed to provide effective privacy protection for consumers. Compliance with the legal requirements doesn't guarantee effective protections – something we learned the hard way with infosec – and it’s disappointing that so many privacy professionals still view the regulatory checklists as sufficient. Narrator: they’re not. ## **Communication Research Helps Improve Consumer Understanding of Laws** The covid pandemic catalyzed consumer interest in health data privacy – a right we still don’t have in the U.S. beyond the limited restrictions that apply to healthcare providers subject to the Health Insurance Portability and Accountability Act (HIPAA). Just search for HIPAA and COVID for thousands of examples of communication failures in helping consumers understand their rights. Moreover, 92% of Americans believe health care data privacy is a right we *do* have, according to [recent research](https://www.ama-assn.org/system/files/ama-patient-data-privacy-survey-results.pdf?ref=discernibleinc.com) from the American Medical Association. The research further shows that people are unclear about rules to protect their privacy and have concerns about who has access to it. Of course they do! Everyone from Congress to businesses and even activists have made the differentiation between rights we *should* have and the rights we *actually* have clear as mud. The correct answer is to bring reality closer to consumers’ expectations for privacy, because helping them understand their rights and how to exercise them doesn’t include fine print or disingenuous use of consent. OK — now, a word on privacy policies. They’re terrible. We know. If we could get rid of them completely, many of us would because they are piss-poor communication attempts. But we can’t get rid of them because they’re legally required in many jurisdictions – note, true “transparency” isn’t necessarily the requirement, the long lengthy legal document is, in fact, what the law mandates. So, we’re stuck with them for now. But don’t get comfortable – they’re still terribly inaccessible to most consumers – which makes them a terrible communication tool. Kashmir Hill has been covering their terribleness for more than a decade! Apparently to a lot of legal teams, “clarifying” their data practices involves breaking up the same drab paragraphs into shorter ones with (gasp!) bullet points. So far, our legally-mandated attempts at informing consumers about how their data is used and what they can do about it, have been colossal failures because the law only requires organizations to create a communication output (published words) rather than an outcome (genuine understanding), a standard that would require organizations to measure the effectiveness of their communications. ## **Communication Research Helps Organizations Build Trust with Consumers** What are we to do then when legal compliance fails to create meaningful communication outcomes? 1) Comply with the law anyway to the best of your ability. This is the moment where I remind all in-house privacy counsel that simply being a legal requirement won’t force most businesses to comply. There are plenty of laws that companies knowingly violate due to a lack of harmony with other laws, a desire to force changes in the law, or even willingful defiance (oh hey, Elon). If you want your organization to take you seriously and view you as a trusted business advisor, you need to find a better way than playing the role of Chicken Little to encourage, persuade, and drive change. And this, my friends, is why we added a panel about “what else can we do?” at the recent USENIX’s Enigma 2023 conference in Santa Clara, California. Officially titled “[Privacy Policies, by Lawyers, for Lawyers. What About Everyone Else](https://www.usenix.org/conference/enigma2023/presentation/panel-privacy-policies%5C?ref=discernibleinc.com),” the panel brought together legal and product experience experts to talk about other ways organizations can engage and educate customers in meaningful ways. There was discussion about how to improve privacy policies to make them accessible (a truly superfluous task in my opinion since no one ever reads them), but there were also a lot of examples of product and UX choices designed to give individuals information in context instead of pushing them to a wall of text or a laundry list of toggles isolated from the product experience. I encourage you to watch the full discussion [here](https://youtu.be/7yMFYLyh4H8?ref=discernibleinc.com). We can’t build trust without understanding and if people don’t understand how their data is used, the rights they have, and how to exercise them then all our efforts to build trust in our privacy programs are for naught. To do this, we need to measure the effectiveness of our communications, including the channels, language, and visuals we use – so that we can adjust as needed to ensure the people whose data we’re using never feel duped into sharing it. ### CUSTOMER CASE STUDY: Response Planning URL: https://www.discernibleinc.com/customer-case-study-incident-response-comms-plan/ Last updated: 2026-07-14T21:09:00.000Z ### Collaborating to Design a Holistic Incident Response Communications Plan --- ## **Background** The overall number of data compromises in 2021 jumped more than 68% compared to 2020, according to the [Identity Theft Resource Center,](https://www.idtheftcenter.org/post/identity-theft-resource-center-2021-annual-data-breach-report-sets-new-record-for-number-of-compromises/?ref=discernibleinc.com) continuing the upward trend of cyber threats against organizations. Yet,only 26% of organizations have a cybersecurity incident response plan applied consistently across the entire enterprise, a figure that has remained low over the years, according to the [Cyber Resilient Organization Study from IBM. ](https://www.ibm.com/resources/guides/cyber-resilient-organization-study/?ref=discernibleinc.com) And, amongst the small number that *do* have a plan, 74% of those organizations reported inconsistently applying it. ## **Situation** A leading collaborative design platform proactively decided they wanted to be in the category of companies that were fully prepared to communicate effectively for a range of situations, with an end to end incident and response communications plan. Here’s how they did it. The company has a robust and responsive cybersecurity program with an established response plan for its technical teams. They wanted to improve how they would communicate with internal and external stakeholders if an incident occurred – whether it was a breach, a vulnerability or other situation that required a quick, accurate and public response. In nearly every organization, communications professionals are on the front lines of managing the external response to a security incident. Security teams are in the trenches working hard to make sure they prevent an incident before it happens or reduce the potential damage if it does. Yet often, these two groups are siloed and only come together after a crisis has happened – and by then it’s usually too late. To avoid that all too common (and costly) scenario, the corporate communications team wanted to create a framework that empowered them to respond publicly to an incident in an informed and holistic way, “Knowing that security incidents can be relatively high profile and high stakes, we wanted to have a process and a framework in place that was inclusive and orderly, knowing that in those moments it can be chaotic. And we wanted it to not be chaotic,” said their Director of Communications. And given that collaboration is baked into their DNA – after all, their entire business is based on people connecting everyone in the design process – they knew they couldn’t do it alone. ## **Solution** To build their security incident communications framework, the company started with two basic principles: 1) it needed to be a collaborative effort and include stakeholders from across company disciplines, and 2) engaging an expert with experience in both security and communications was a must to help them get this right, the first time. Discernible was brought in to guide the team from start to finish on how to build a foundation for incident response that is both flexible and comprehensive. This required, in part: - Identifying stakeholders that go beyond just comms, legal, and security. “A good response process is inclusive,” notes Discernible CEO Melanie Ensign. Everyone from HR to customer support and even members of the Board of Directors and leadership team have a role to play because they all engage in critical stakeholder relationships. - Getting clear on exactly what they were trying to achieve for all their stakeholders including customers, employees, investors, and the security community. Even without knowing what the specific details of an incident might entail, Discernible worked with the team to identify individual principles they wanted reflected in security-related communication decisions and content. As a result of tackling this early, critical communication decisions could be made with cooler heads and long term judgment. - Making sure every stakeholder knew and agreed to what their specific role was if an incident occurred. This involved detailing exactly who was accountable for which communication tasks during an incident, from communications between security teams at peer companies and suppliers, to customer support and social media engagement. - Creating and pressure-testing a process and plan through table-top exercises and multiple instances of review, input and revisions. The hallmark of Discernible’s approach is that incident response plans are designed to address a variety of security-related incidents regardless of severity or impact. This allows security teams to align incident response communications to their day-to-day workflows, so even small low risk events present an opportunity to strengthen their response to major escalations "43% of plans do not fully designate internal incident response stakeholders” -- 2019 Verizon Incident Prepardness Response Report Through a series of working sessions and plan drafting facilitated by Discernible, a foundational plan and process was created, including: - A communications RACI that was “optimized for speed,” which documents each stakeholder’s role and responsibility in specific communication decisions and outputs. - A communications response plan and process that works with the existing company’s tools (software, communication platforms, etc.), technical response plans, and is customized to the way the business works. - A process for when the plan needs to change as the business needs change. **“I always admired Melanie’s ability to see through the clutter and diagnose the problem in a way that is very clear-eyed. When we needed to create something as no-nonsense as a process for how to respond to potential security incidents, we wanted to work with someone who was going to focus on the right path and give it to us straight – and that was Melanie.”* \-- Director of Corporate Communications ## Results Today, the company has a documented communications response plan and process that represents every stakeholder who would ultimately be involved should an incident happen. “We have been able to pressure test it with third party incidents and it has worked very well. It is a living document, and it includes a plan for what to do and how to do it if our needs change,” said the Director of Corporate Communications. After this experience, the company’s head of security said that “having a flexible, yet reliable communications framework that supports our technical response plan means our cross functional partners know in advance what to expect from our security team during an incident, how to best support our investigations, and how to quickly respond to external stakeholder needs.This significantly increases our efficiency in engaging with our partners to ensure they have the information they need as quickly as possible.” ## Key Takeaways If your organization is considering creating a security communications response plan or updating an existing one, here are some points to keep in mind: - A plan that only addresses security breaches is limiting. You need to prepare for a range of potential situations that will require coordination with other teams or third parties, not to mention an external response or a customer facing communication. - There is no “one size fits all” plan – so avoid the temptation to use one. Every company is unique, and your plan should fit the business needs today and be flexible enough to adapt as the company changes. - Look at the plan holistically – it should include stakeholders from every part of the organization, not just security, legal, or communications. ### A CISO’s Guide to “Negative Megaphoning” URL: https://www.discernibleinc.com/a-cisos-guide-to-negative-megaphoning/ Last updated: 2026-07-14T21:02:19.000Z *Principles for preventing employee comments that damage your organization’s reputation* “Negative megaphoning” is when employees speak negatively about their organizations to external audiences. Employee perspectives are often considered more credible than the organization’s official statements, and this scares companies. They create policies and surveillance systems to try and control employees. Moreover, large security teams typically have at least a few dedicated staff responsible for conducting investigations on vocal employees at the direction of executives and attorneys. To be clear, I’m not talking about employees who leak intellectual property or violate the law by exposing regulated personal data. I mean when someone gets pissed off and talks shit about their employer on social media, to journalists, in Slack groups, social events, etc. Negative megaphoning can have a significant impact on the reputation of your company as well as specific teams, like #infosec. It may seem obvious that organizations want to minimize negative news headlines, but how often do CISOs think about their reputation as an employer and how that affects their ability to hire and retain talent? In my experience, negative megaphoning can also occur inside organizations and have serious consequences on a security team’s influence with business partners and internal stakeholders. We’ve worked with several clients on this exact issue – repairing internal perceptions and relationships in order to remove political obstacles for the security team. So, it’s not irrational for leaders to want to prevent reputational damage from happening in the first place. It takes a lot of time and energy to fix it. Here’s the crazy thing though — we know how to prevent most of this from happening and it’s not rocket science. However, it is backed by science. 😎 ## **Research means we don’t have to guess** In April 2021, an article by Dr. Yeunjae Lee was published in the [*Journal of Business Ethics*](https://link.springer.com/article/10.1007/s10551-021-04804-5?ref=discernibleinc.com)*.* Dr. Lee is an assistant professor in the Department of Strategic Communication in the School of Communication at the University of Miami. She has done extensive research on employee behaviors within and outside of work in response to organizational crisis and the impacts of organizations’ strategic internal communication. Her article last April, summarized findings from a study she conducted showing how employees’ perception of a quality relationship with their organization reduced negative megaphoning while negative experiences promoted it. Makes sense, right? It’s fairly common for me to hear commentary from outside the field of communications referring to findings of such studies as “common sense” – but if that were true, Silicon Valley would stop worshiping and financing billionaires who delight in demonstrating how little common sense they have. In reality, simple principles can be easy to understand while still leaving leaders perplexed with how to implement them. Here are the key findings from Dr. Lee’s study: 1. Employees’ perception of quality relationships with the organization can effectively decrease employees’ negative megaphoning behaviors in anonymous online channels. 2. When employees experience negative emotions at work, such as anger, contempt, disgust, and fear, they are more likely to share bad aspects of their organization externally, internally, and on anonymous online channels (i.e., Glassdoor). 3. Employees’ negative experiences can undermine the relationship between employees and their organizations. 4. Employees’ perceptions of injustice can erode the employee-organization relationships and increase the likelihood of employees feeling anger, anxiety, or frustration. ## **It’s all about relationships** The relationship between individuals on your team and the organization makes a huge difference in how they react to negative experiences, while at the same time, negative experiences damage that relationship. Do you know what kind of a relationship your team members have with the organization? If some of this seems too simple for you, the study also identified several principles for organizations to implement to prevent or reduce negative megaphoning. At first glance, they seem pretty fundamental and perhaps even “common sense” – but then why isn’t everyone doing them? Why indeed. Here are the 3 principles for minimizing negative megaphoning by employees: 1. Treat employees with respect and dignity and offer rewards and benefits equal to their contributions 2. Identify and proactively prevent any issues that make employees feel that they are mistreated 3. Provide training interventions to help organizational leaders understand the importance of fair and just decision-making Putting these principles into practice requires ongoing, two-way communication between leaders and each team member, an accurate understanding of their expectations related to fairness and how decisions are made, and the simmering issues between each team member and the organization. Of course, all of this requires trust and effective communication. If this sounds like something you want to tackle with your team this year, drop us a note [here](https://discernibleinc.com/contact?ref=discernibleinc.com). ### Scrub these Phrases from Your Data Breach Statements URL: https://www.discernibleinc.com/scrub-these-phrases-from-your-data-breach-statements/ Last updated: 2026-07-07T21:57:41.000Z In the event of a security incident, it's critical that your response is both fast and accurate. Unfortunately, many organizations make the mistake of including one or more of the following three elements in their public statements, which impairs the credibility and trustworthiness of their response. By avoiding them, you can help ensure that your organization's response is taken seriously . **1\. Claiming Security or Privacy is Important to You** In the aftermath of a security incident, the last thing you want to do is come across as though you don't take security seriously. Unfortunately, that's exactly what happens when you make statements like "security is important to us" or "we take security very seriously." Not only are these statements clichéd, but they’re often counterproductive, as TechCrunch [reported](https://techcrunch.com/2019/02/17/we-take-your-privacy-and-security-seriously/?ref=discernibleinc.com) nearly 4 years ago. Using this phrase actually casts doubt about your commitment right away. Instead, focus on specific steps your organization is taking to mitigate both the current risk and future incidents. It’s not enough to say security or privacy are important to your organization, you have to prove it with action. What steps have you taken before, during, and after the breach to prioritize and protect the security and privacy of user data? What are you willing to leave on the table to maintain or repair trust in your organization? **2\. Citing a Lack of Evidence of a Malicious Thing Happening as Evidence That It Hasn’t Happen** Another big mistake often made in response statements is citing a lack of evidence of a specific action as evidence that the action didn’t occur. For example, as Bob Lord [wrote](https://www.rapid7.com/blog/post/2015/08/20/the-absence-of-evidence-in-breaches/?ref=discernibleinc.com) back as 2015: > “The phrase 'no evidence' could mean everything from 'we have tons of evidence and we're sifting through it, but the probability of the attackers accessing your data is very low,' all the way to 'we don't collect data for use by incident responders, so who knows?'" Just because you don't have evidence that something bad happened doesn't mean it didn't happen. By assuming responsibility and explaining how you’re proven various aspects of the situation and why you’re confident about specific findings of your investigation, you can help avoid further damage to your organization's reputation. **3\. Over-Emphasizing Insincere Details** One of the most common examples I see is the over-reliance on credit card information as an indicator of risk to consumers. It’s disingenuous to imply that the presence or absence of this data accurately represents the severity of an incident because other types of data can carry a far greater risk to consumers such as information about your location and travel patterns, and medical status. Rarely are consumers accountable for fraudulent charges when they report a stolen credit card, but a compromise of biometric information, for example, is much harder for end users to mitigate. Moreover, when companies do call out when specific information is not affected by an incident, they often miss the opportunity to explain *why.* Did you just get lucky or did you make a deliberate decision that reduced the potential damage? Maybe you’re following the privacy principle of data minimization and made the conscious decision not to collect or store certain information. These details matter and I believe we should be encouraging organizations to talk about their proactive efforts to reduce risk. As a reminder not all security or privacy incidents involve technical intrusions or a data breach, as we’ve discussed [here](https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups/). These more common mistakes are most often made when organizations approach stakeholder communication about security and privacy issues as reactive only, believing it only needs to happen to mitigate an incident. At Discernible, we work with clients to develop ongoing and proactive stakeholder communications to earn credibility and trust before incidents occur. Security and privacy incidents can cause anxiety for both businesses and consumers alike. In order to minimize the damage caused by an incident – or even better – to optimize the impact, it's critical that businesses get their security incident response statements right. By avoiding common mistakes like those described above, you can help ensure that your organization's response is taken seriously. ### Don’t Get Stuck in Conflict: Communication Techniques for InfoSec and Privacy Teams URL: https://www.discernibleinc.com/dont-get-stuck-in-conflict-communication-techniques-for-infosec-and-privacy-teams/ Last updated: 2026-07-07T21:56:40.000Z More than 20 years ago, [scholars developed](https://www.tandfonline.com/doi/abs/10.1080/01463379509369978?journalCode=rcqu20&ref=discernibleinc.com) a theory about why some people take conflict more personally than others. It’s creatively referred to as the “Take Conflict Personally Theory” and defines the phenomenon as “a negative emotional reaction to participating in conflict.” Underlying this communication trait is the belief that conflict is an “antagonistic, punishing interaction” in which the central goal is to purposely hurt the other person. This belief is often a self-fulfilling prophecy and leads to aggressive or avoidant behavior, while inspiring similar reactions from the people we’re communicating with. Communication scholars believe that the “take conflict personally” trait is a product of both the situation and a person’s predisposition. Research also suggests that taking conflict personally is also associated with rumination, or the consistent and repetitive thinking about negative experiences with others. Understanding and mitigating the degree to which someone takes conflict personality is increasingly important for security and privacy teams as organizations grow and business operations become more segmented. Historically, infosec and privacy teams have attempted to convert cross functional partners to agree with their perspective, beliefs, and values. Sometimes it works, but in many cases, people on opposite sides of a contentious issue, like data collection and privacy, might never change their minds. Nevertheless, they still need to work together on important issues. I’ve [written before](https://www.discernibleinc.com/exercising-influence-as-the-security-team-look-for-friction-not-just-fuel/) about the importance of infosec and privacy teams being able to influence behavior without requiring existential conversions from our peers. Especially, when they perceive conflict with their own goals and incentives. The more important an issue is to someone, the less likely they are to change their minds. So, how can infosec and privacy professionals influence engineering, product, and other business decisions in the presence of disagreement? **1\. Focus on the Next Conversation** The value of a relationship typically exceeds the benefit of “winning” a disagreement. This is an issue that comes up frequently for bug bounty teams engaging with external security researchers due to the intense emotions of anger and frustration caused by a variety of communication challenges including information inequity, language barriers, [naive realism](https://en.wikipedia.org/wiki/Na%C3%AFve%5Frealism%5F%28psychology%29?ref=discernibleinc.com) (the belief that our own perspective is an accurate and objective reflection of reality), and poor communication tools. A colleague once told me the de-escalation coaching I provided to their bug bounty team actually improved communication with their spouse as well because they now understood how to work through a disagreement while prioritizing the relationship and ensuring the other person saw how much they valued the relationship. **2\. Engage with the Other Point of View** The internet is flooded with advice on how to practice empathy and consider someone else’s perspective, but not how to ensure the other person knows we’re doing it. When we’re not transparent about what we’re doing in a visible and recognizable way, the other person is unable to consider that information during the conversation. For example, we recently developed communication guides for the infosec team at a large enterprise client to help improve their reputation (READ AS: influence) with business partners. After identifying the attributes and characteristics they wanted to be known for across the company, we developed specific guidelines for how to demonstrate and communicate those things during their formal and out-of-band engagements with partners. *You can’t get credit for things in your head.* ### Knocking on the Boardroom Door URL: https://www.discernibleinc.com/knocking-on-the-boardroom-door/ Last updated: 2026-06-28T17:56:52.000Z #### *New research examines CISOs and the Quest for Legitimacy* One of the most important aspects of my work is helping CISOs with what I like to call “the invisibility problem.” Many talented, hardworking CISOs try to do the right things to be seen: they present at quarterly board meetings and send their executive team regular updates about the security program. While these actions may check the boxes with their management and the Board, I don’t believe they are enough to build the credibility and visibility CISOs need to succeed - and obtain the resources required to protect an organization in a world of ever-expanding risk. So I was pretty excited when I learned that someone was studying this issue through the lens of academic research. Anthony Vance, the Director of Pamplin Integrated Security at the Pamplin College of Business at Virginia Tech, who specializes in cybersecurity*,* and his teamrecently conducted in-depth research into this topic. I sat down with Anthony to dig into his findings. > *You’re invited to join a virtual deep dive conversation with Anthony and ask him your own questions on December 8, 2022 at 4-5pm ET. Register at our events page:* [*discernibleinc.com/events/ciso-legitimacy-boardroom*](https://discernibleinc.com/events/ciso-legitimacy-boardroom?ref=discernibleinc.com) ## **Why did you want to focus your research on CISOs and legitimacy?** When I looked at security breaches over the years, I was interested in the fundamental causes of these incidents. One common element I discovered is the lack of attention paid to cybersecurity by the executive team and board of directors, and their interaction (or non-interaction) with the CISO. In my field, there is little-to-no research on this dynamic. There are a lot of platitudes like leadership setting the “tone at the top.” At the same time, we have the SEC saying in 2018 that the board must take ownership of cybersecurity risks, and this year proposing that public boards must explain how often they engage with their CISOs. So that’s what piqued my interest. ## **Tell me more about the SEC requirements.** As of 2018, the SEC has offered guidance that boards should state in their annual proxy statement to shareholders how they are managing cybersecurity risk. In 2022 the SEC is taking it further with a proposed rule (inspired by the New York Department of Financial Services’ cybersecurity rules) which would require boards to state in their proxy statement (1) whether the company has a CISO, (2) to whom the CISO reports, (3) qualifications of the CISO, and (4) how frequently the CISO reports to the board. The SEC is also proposing that boards state whether someone with cybersecurity expertise serves on the board and what that expertise entails. So regulatory pressure is increasing, which can help drive more conversation between CISOs and their board members. ## **How did you research this dynamic?** We wanted to answer the question, “What inhibits or facilitates CISO’s legitimacy in the eyes of the board and C- suite executives?” We wanted to look at the question from both the board’s point of view and the CISOs’ perspective. So far we have conducted in-depth interviews with 36 board members and CISOs at mid-to-large cap publicly held companies, as well as a few large privately held companies. We’ve also spoken with consultants who advise boards and CISOs about cybersecurity. ## **What did you discover?** Our [preliminary findings](https://anthonyvance.com/research/CISO-legitimacy-ICIS-2022.pdf?ref=discernibleinc.com) indicate that CISOs often lack legitimacy in the eyes of the board of directors and the C-suite, and for CISOs this can be very frustrating. Even though they are submitting reports and communicating with the board, it’s not enough. Some CISOs said they submit a report to the board but never get any feedback. Instead, they get a brief “thank you.” Or they routinely get bumped from the regular board meeting agenda. Which means the board is missing an opportunity to learn directly from CISOs about substantial security issues that pose the greatest risk to the organization. The interviews were like a therapy session for some of the CISOs we spoke with because they were able to talk about the issues they struggle with every day. They want more engagement with the board and the executive team but many are unclear how to do this more effectively. ## **So how can they do that?** In our research, the theme of the legitimacy of the CISO as perceived by the board and C-suite kept coming up, and that with increased legitimacy comes increased support and collaboration. We’ve found that this is a process as CISOs demonstrate to the board that they are a legitimate partner. In practical terms, this means a CISO must *proactively* engage with the board and be the main driver in building legitimacy. For example, one CISO told me that as soon as a new board member is appointed, he sets up a meeting with that person individually, outside of the regularly scheduled board meeting cycle, and briefs them about how the CISO can be a resource to them as a board member. This type of proactive engagement outside of board meetings is a common pattern that I see with the more successful CISOs. ## **How does this help increase legitimacy with the board?** It helps the board see the CISO as a resource to them and to the business beyond just reporting statistics. Through “micro engagements” with the board, CISOs can show that they understand the company’s business priorities – which after all is the main focus of any board - and that the CISO has valuable input to share. As the board’s awareness of the CISO grows, their perception of the legitimacy of the CISO increases. And this leads to a virtuous cycle with tangible security program outcomes, like increased security budgets, support of the CISO’s initiatives, and facilitating communication between the CISO and C-suite. Another valuable outcome of this is that the board’s increased interactions with the CISO can cause the C-suite to engage with the CISO more. For example, one of CISO I spoke with said that because of their interactions with the board, “now the C-suite takes a little more interest in cybersecurity, because they’re getting asked questions by about cybersecurity by the board.” Now he meets regularly with the CEO and their direct reports. So we’re really seeing two virtual cycles of legitimacy: one with the board and one with the C-suite, in which increased legitimacy of the CISO in the eyes of the board leads to greater interaction with the C-suite, and in turn, increased legitimacy of the CISO in the eyes of the C-suite. ## **What should CISOs take away from your research?** Proactively engaging the board may not come naturally. In the typical career path for a CISO, they are not trained to build trust and negotiate with the board and executives. It’s a missing skill. Yet they need to understand that they can’t wait 12 months at a time to connect with these people. And it can’t be left to chance. Getting feedback and advice from other CISOs who are experienced in this can really help, as can professional coaching. ## **Will there be more research forthcoming from your team?** I have published an [academic conference article](https://anthonyvance.com/research/CISO-legitimacy-ICIS-2022.pdf?ref=discernibleinc.com) about this topic and I have an article about the board’s perspective also in *The Wall Street Journal* now available [here](https://www.wsj.com/articles/corporate-boards-cybersecurity-experts-11662494801?ref=discernibleinc.com). ### 📬 Mailbag: How should brands talk about security threats from abroad without sounding xenophobic? URL: https://www.discernibleinc.com/mailbag-how-should-brands-talk-about-security-threats-from-abroad-without-sounding-xenophobic/ Last updated: 2026-07-01T04:18:26.000Z *Mailbag questions are submitted by our readers. Submit your own question for our team at discernibleinc.com/contact.* --- When it comes to foreign-based security threats, we all live in glass houses and are subject to the laws of our respective countries, be they just or not, democratic or not. Governments have allies and enemies, and they often expect the businesses they regulate to support their position on international relations. This can make it difficult for brands who seek to balance patriotism and legal compliance with protecting their company and customers against security threats. The way we communicate about these threats matters because today’s brands are increasing multinational, so even the perception of xenophobia can have serious consequences when you have customers, employees, and regulators all over the world. Businesses are often put in the difficult position of harmonizing global values and cultures even when our governments fail to do so. The most important thing to remember is that when it comes to security, we can’t separate business from geopolitics. What we perceive as a threat from abroad is based not only on the government or law enforcement agencies we and our own governments trust at any given moment, but also who expects us to support their position due to political alliances or business deals. So how do we avoid xenophobia in the way we communicate about security threats, knowing that many, if not all of them contextual and rooted in politics just as much as technology? 1. **Focus on the Threat, Not the Group -** Fear is the foundation of hate, so be careful where you focus your concern. It’s lazy and xenophobic to blame an entire population for the actions of their government or organized crime syndicates (sometimes one in the same). Even if you believe a foreign government agency or regime is responsible for a specific security threat or campaign, be thoughtful in your language and focus on the threat. Don’t fall for naming entire populations of people as shorthand for the much smaller group of individuals responsible. 2. **Use Specific Examples -** Specific examples help your audience understand the nature of the threat and why it’s important to be aware of it. For example, instead of simply saying, *“consumers face significant security threats from the United States,”* you could say, *“due to concerns about whether U.S. intelligence services will respect the human rights of individuals from other countries, numerous governments have declared on multiple occasions that all data transfers to and from their country to the United States must stop, significantly impacting operations for even the largest and wealthiest American companies.”* 3. **Explain the Context -** Don’t forget that governments can be engaged in severe conflicts even when their citizenry are not – and research shows that fewer and fewer consumers are closely following geopolitical events. Therefore, to the extent possible, explain the political constraints, influence, and perspective that factor into how you identify, define, and mediate security threats. ### Words that Work: Persuasive Language for Security and Privacy Communications URL: https://www.discernibleinc.com/words-that-work-persuasive-language-for-security-and-privacy-communications/ Last updated: 2026-07-07T21:53:46.000Z Every year, the month of October inspires a lot of discussion about how security teams engage with their colleagues. Many companies schedule special events, contests, training sessions, and marketing content – with varying degrees of performative vs. impactful investments. I respect security engagement and education programs in theory, but one thing I can’t get past is just how many of them settle for “awareness” as a sufficient objective. If that term were in my job title or PKIs, I would be advocating hard to replace it with something action-oriented. I’ve discussed the difference between outputs, outtakes, and outcomes [before](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/) because many security teams measure the wrong things and miss the opportunity to demonstrate tangible bottom line value to their organizations. With infrequent, static engagements like the ones we often see in October, there is more focus on reporting how many “things'' the security team does rather than its impact. In my experience, the most effective stakeholder engagements aren’t treated merely as informational exercises, but as integrated, coordinated, and ongoing initiatives to increase influence over the decisions made by individuals and the business. ## **Different words lead to different outcomes** An underrepresented source of potential influence for security and privacy organizations is the words we use. Not all words are created equal and they play a significant role in how our stakeholders interpret and process what we tell them. The persuasive power of language has been studied by social scientists for hundreds if not thousands of years, but it's only now emerging as a recognized discipline by security and privacy professionals. It is not enough to simply create rules and tools. *How* we advocate for them makes a big difference in how well they’re adopted. For example, in a [recent episode](https://mayim.simplecast.com/episodes/dr-maya-shankar-find-the-asset-in-your-defect-tZfA4X0%5F?ref=discernibleinc.com) of *Mayim Bialik's Breakdown* podcast, the host Mayim Bialik — neuroscientist and star of TV’s *Blossom* and *The Big Bang Theory —* interviewed Dr. Maya Shankar, cognitive scientist and former Senior Advisor on behavior science to the Obama administration. Dr. Shanker shared her experience working on public policy initiatives including a simple A/B test with the Department of Veterans Affairs focused on enrolling more veterans in a public benefits program after they returned from their time serving overseas. In their email to veterans, instead of saying they were *eligible* for the program, they reminded them that they had *earned* it through their years of service. That one word change led to a 9% increase in enrollment and access to benefits. Do you know which words are most effective for the context and audiences of your security and privacy communications? If you’re not sure, now is a good time to start measuring the impact of the language you use. Counting the number of times you distribute content or engage with stakeholders is a good measurement of why you’re so busy, but are your communications as effective as they *could* be? Want to find out? [Let us know](https://discernibleinc.com/contact?ref=discernibleinc.com)! Dr. Shankar also hosts her own fantastic podcast *Slight Change of Plans*. Check it out [here](http://podcasts.pushkin.fm/slight-change-of-plans?ref=discernibleinc.com)! ### Does Your Security Comms Strategy Need an Upgrade? URL: https://www.discernibleinc.com/does-your-security-comms-strategy-need-an-upgrade/ Last updated: 2026-07-07T21:52:17.000Z *Shifting from crisis mode to a persistent demonstration of care through routine security communications* A security team’s first encounter with a security communications professional is often tied to incident response: what, when, and how do we communicate the details of what’s happening to stakeholders? So it’s no surprise that the general understanding of security communications among security executives and their teams is rooted in crisis management. But it’s the decisions companies make *before* an incident occurs that are usually the most impactful in how an incident is perceived. Effective crisis management includes not only a timely demonstration that you care in the wake of an incident, but also a persistent demonstration that you still care for as long as stakeholders expect you to. This brings up a significant shortcoming I see with many corporate communications programs that perceive security only through the lens of crisis: exactly when do our stakeholders *not* expect us to care about safeguarding their data, securing their online experiences, and communicating transparently? In other words, why are we only talking to them *now,* in the midst of a crisis, about how much we care? Can our demonstration of caring ever truly stop? No, it must be persistent. A persistent demonstration is both deliberate and organic. It’s about how you show up as a company and a security organization, ready to discuss the issues that matter to your stakeholders whenever they need it. Organizations unprepared to talk about security and privacy on a regular basis find that everyday blunders routinely escalate into a crisis before they’re remediated. Recent examples include [rumors of keylogging by TikTok’s in-app browser](https://techcrunch.com/2022/08/19/tiktok-fb-in-app-browser-tracking-analysis/?ref=discernibleinc.com) and [Patreon’s security layoffs](https://www.cyberscoop.com/patreon-security-team-layoffs/?ref=discernibleinc.com). I discussed [own goals](https://en.wikipedia.org/wiki/Own%5Fgoal?ref=discernibleinc.com) in security communications before and you can read more about that [here](https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups/). Without a persistent demonstration that organizations give a sh\*t about avoiding security crises– not just surviving them, each incident feels more significant than it should because trust and benefit of the doubt haven’t been earned. Moreover, when we choose to manage security communications one crisis at a time, stakeholders perceive a pattern of chaos as we’re flung into one crisis after another. ## **Routine Communications for Mitigating Risk** In leading the security and privacy communications strategy for both small and global brands, I’ve found that ongoing attention to routine communications helps minimize both the volume and impact of potential crises. As a result, we advise our clients to prioritize routine security and privacy communications as one way to demonstrate persistent care. I consider the following routine tasks staples for any security or privacy communications professional to ensure there’s no doubt whether we’ve done all we can for our stakeholders: - **Product/engineering design reviews**: Put yourself in the review loop and read the docs. Does the proposed change demonstrate persistent care? If not, talk to the engineers and product managers behind the effort to understand their goals and help them identify alternatives or improvements. Most of the time, they want to do the right things, and pointing out how their new project will be perceived by stakeholders is a powerful exercise. I previously [published](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/) a sample list of questions I consider when reviewing a new product or engineering proposal. - **Customer/sales communications:** How often is your organization communicating to customers and prospects about security and privacy? > *Do they only hear from you when things go wrong? Do you even know what your organization is telling them?* When things go wrong, it’s not impossible to maintain customer trust despite negative headlines, but you need to develop and nurture those relationships in advance. I recommend routine communications that help them understand the risks and proper mitigation techniques for using your product or service securely, as well as establishing dedicated communication channels to provide adequate (and accurate) support when an incident occurs. - **Technical blog posts:** Many organizations are eager to brag about their technical capabilities, but they miss red flags in the content they publish, creating opportunities for critics and even well-intentioned industry peers to point out security issues and vulnerabilities using your own words. Sometimes the fix is as simple as a word choice, sometimes it’s a more difficult conversation about whether a specific project is truly ready for primetime attention. A strong security and privacy communications strategy considers how content from across the organization contributes or distracts from your persistent demonstration of care. - **Bug bounty communications:** Misunderstandings and escalated emotions among external security researchers can cause a lot of noise for your organization and burn out your security team. Take the time to help them communicate effectively with this important stakeholder group and avoid/prepare for public tantrums that distract from your persistent demonstration of care. Incidents happen, but if they’re the be-all-end-all of your security communications strategy, you’re missing the opportunity to earn trust and credibility from your most important stakeholders before something goes wrong. The scrutiny and urgency of a crisis makes it the worst time to introduce your security or privacy team to the world. Give them the opportunity to demonstrate how much they care before an incident happens. ### Beyond the Technical: Emotions and Negotiating in Security Leadership Roles URL: https://www.discernibleinc.com/beyond-the-technical-emotions-and-negotiating-in-security-leadership-roles/ Last updated: 2026-07-07T21:51:16.000Z Discussions about emotions come up a lot in our incident preparedness and response work with clients because we’re always thinking about how different stimuli impact people’s expectations and ability to communicate effectively. It’s also a very common topic of focus with the CSO/CISOs and team leads who engage *Discernible* for communication coaching. This week alone, I received the following comments from two different clients (shared with consent): > *“Thanks for the help, you've got me past the murderous stage.”* > > *“It may be a bad move, but it’s the only impulse that I have.”* Current events suggest other security leaders may be struggling with how to navigate emotional situations. So, here’s a resource I recommend: [*Beyond Reason* by Roger Fisher and Daniel Shapiro](https://www.amazon.com/Beyond-Reason-Using-Emotions-Negotiate/dp/0143037781?ref=discernibleinc.com). This book builds on Fisher’s previous work from the 1980s, [*Getting to Yes: Negotiating Agreement Without Giving In*](https://www.amazon.com/Getting-Yes-Negotiating-Agreement-Without-ebook/dp/B0051SDM5Q?ref=discernibleinc.com)*,* which he wrote with co-author William Ury. ## **Why am I recommending this book to security leaders?** In any cross-functional security role, such as a CSO/CISO, product security engineer, or TPM, a significant percentage of the work requires negotiating, e.g. what engineering tools/processes will be allowed, what risk tolerance will the organization accept, what security issues must be fixed before a release? I recommend reading the book *Beyond Reason* specifically because it analyzes the role that emotions play in negotiating, two things that often trip up security leaders. Before I get into the details of the book, let’s think about why emotions matter to leadership. When strong emotions arise, our attention narrows and impairs critical thinking. We’ve discussed the impact of negative emotions on this blog [before](https://www.discernibleinc.com/preparing-for-task-loading-during-incident-response/) when talking about how stress impacts our ability to think and complete tasks during incident response. The way our bodies and minds respond to strong emotions can lead to failure of even simple or familiar tasks as we reach the limits of our cognitive capacity. Strong emotions change the way we think, so having a strategy to deal with them before entering into a negotiation is strongly advised. Next, consider that negotiations are a core competency of effective problem solving. Too often people associate negotiations as uncomfortable or difficult conversations, or perhaps a last ditch effort to resolve a seemingly dead end conflict. If that’s how you approach negotiating, that’s what it will become. However, in my experience, effective negotiation skills are a fundamental part of working with cross functional partners whose perspective, goals, and needs differ from ours. There’s no escaping it if you want to move your work forward. Forming productive relationships with other teams requires negotiation – and effective negotiation does not ignore emotions. Below is a summary of a few key ideas explored in *Beyond Reason* and my thoughts on how they relate to leading effective security teams. According to Fisher and Shapiro, an emotion is: 1. an experience 2. of personal significance 3. associated with a distinct type of physical feeling, thought, physiology, and action tendency This indicates that emotions are deeply personal and highly influential. Negative emotions often create obstacles during negotiations while positive emotions can be used as an asset or facilitator in moving negotiations forward. Rather than suppress our emotions or let them overwhelm our perspective, *Beyond Reason* outlines five core concerns to help us identify and address underlying needs at the root of human emotions. ## **The 5 Core Concerns** 1. **Appreciation:** Everyone wants to feel understood and valued, and cooperation increases when there is a *mutual* feeling of appreciation. Three primary obstacles to achieving this are: - Failing to understand a different point of view - Criticizing the merit of someone else’s point of view - Failing to effectively communicate your own merit 1. **Affiliation:** Affiliation describes our sense of connectedness with another group or person. Often we fail to recognize commonality as group members and individuals. We don’t have to become friends with everyone we work with, but recognizing affiliation helps us humanize them, which is an important element of effective negotiation. Fisher and Shapiro offer a specific piece of advice that I relay to my clients as well: avoid agreements based solely on emotions because they are prone to manipulation. Emotions can quickly and unexpectedly change. Agreements based on shared business goals, resources, or formal policies help keep things on track even when emotions change. 💡 **Note: there’s a great episode of the Hidden Brain podcast that discusses how our mindset shifts when we feel part of a group. Check it out* [**here*](https://hidden-brain.simplecast.com/episodes/separating-yourself-from-the-pack-AXNnRTlI?ref=discernibleinc.com)**.* 1. **Autonomy:** Having “freedom to affect or make decisions without the imposition of others,” is critical to negotiations, but so is having the discipline not to interfere with someone else's autonomy. Joint brainstorming sessions are common tactics for ensuring everyone is adequately informed of the challenges and metrics for success, but we don’t often enough consider consulting other colleagues before making decisions that will impact them. This infringes on their sense of autonomy and creates friction in negotiating. 2. **Status:** Competing for status is a quick way to torpedo any negotiation because it directly impacts feelings of self-worth. Why would cross-functional teams want to work with security if we make them feel bad about themselves, or if we don’t demonstrate respect for their expertise and experience? Do they feel treated as equal partners in the negotiation or do they get a strong-arm and competitive vibe from us? 3. **Role:** Everyone needs to feel fulfilled in their role during a negotiation in order to foster feelings of appreciation, affiliation, autonomy, and status – the required conditions for successful collaboration. You have the freedom to limit your role to the things you are obligated or expected to do, or you can expand it to incorporate more of your skills and interests. ## **Social Triggers** For group communications and relationship building, I also recommend leaders consider a [SCARF](https://neuroleadership.com/research/tools/nli-scarf-assessment/?ref=discernibleinc.com) training for their teams. The SCARF Model was developed by David Rock, in his 2008 paper *"SCARF: A Brain-Based Model for Collaborating With and Influencing Others,"* and represents the five key "domains" that influence our behavior in social situations: - **Status** – our relative importance to others - **Certainty** – our ability to predict the future - **Autonomy** – our sense of control - **Relatedness** – how safe we feel with others - **Fairness** – how fair we perceive interactions between people The SCARF model is based on neuroscience research that implies these five social domains activate the same threat and reward responses in our brain that we rely on for physical survival. As individuals, we prioritize and associate with these domains to varying degrees, which is why we don’t all react the same way to things. I mention SCARF here because of the similarities the social domains have with the core concepts discussed in *Beyond Reason*. Both resources are helpful in identifying and anticipating triggers that create specific reactions from ourselves and the people we work with. Additionally, both recognize that the expression of strong negative emotions is rooted in an underlying concern that needs to be addressed in order for us to work together productively. This means understanding our own triggers and emotions as well as those of the people we’re working with. Learning how to identify those needs to effectively negotiate is an important part of effective leadership. ### Self-Inflicted Pain and Artificial Adversity in InfoSec URL: https://www.discernibleinc.com/self-inflicted-pain-and-artificial-adversity-in-infosec/ Last updated: 2026-06-28T17:38:01.000Z I was reflecting on [Jackie Bow’s](https://www.linkedin.com/in/jackie-bow-83933840/?ref=discernibleinc.com) recent Keynote at BSidesSF 2022 when I heard a new episode from the Hidden Brain podcast on ["What We Gain from Pain](https://hidden-brain.simplecast.com/episodes/what-we-gain-from-pain-zf5MVs6B?ref=discernibleinc.com),” exploring whether adversity is the secret sauce to success. Jackie’s presentations entitled, “We Need More Mediocre Security Engineers,” touched on the common (& wildly unrealistic) expectation within our industry of perfection, from ourselves and others. “We expect ourselves to be unicorns,” Jackie said. She also called out the unhealthy assumption that we must be doing security not only for work, but that we’re hacking on side projects, participating in CTFs, reading white papers, keeping up with InfoSec Twitter, and going to conferences on Saturdays. “Basically, we have this perception that in order to be a great security engineer or practitioner, security has to be your life. There seems to be this idea that by living and breathing and only doing security we’re making ourselves better professionals and making the world more secure… Our extreme expectations of ourselves and each other drive burnout, not excellence.” YAS, Jackie! 🔥 She continued to discuss the effects of burnout and security’s predisposition to it, particularly because we’ve allowed our work to have 24/7 accessibility to our lives as a standard expectation of our role. \[*Editor's note: we teach others how to treat us*.\] You really should watch Jackie’s entire keynote because it’s awesome: [https://www.youtube.com/watch?v=3YmixOGqylY](https://www.youtube.com/watch?v=3YmixOGqylY&ref=discernibleinc.com). ## **InfoSec’s Obsession with Pain** On the episode of Hidden Brain from July 4, host Shankar Vedantam speaks with psychologist [Eranda Jayawickreme](https://jayawide.sites.wfu.edu/?ref=discernibleinc.com) at Wake Forest University, whose research finds that while suffering can have benefits — they’re not necessarily the ones we expect. As a young immigrant to the United States, Jayawickreme noticed many American protagonists, including our superheroes like Batman and Spiderman, are forced to experience extreme trauma as a prerequisite for greatness–the idea being that suffering is necessary for growth. Finding opportunities in the challenges we face or in having a positive outcome during difficult times can be an effective way to cope with trauma. However, what Jayawickreme is talking about is a cultural expectation that we become the best version of ourselves only by vanquishing some kind of adversity that has been bequeathed to us. It’s an aspect of what is referred to as “post-traumatic growth” or the idea that people can experience positive psychological changes by going through stressful life experiences. In InfoSec, we’re bombarded with this message through countless marketing and recruiting messages implying that we’ve been enlisted into an elite fellowship to save the world. In reality, you do not need to join the Avengers or develop mutant powers to have a successful career in security, grow as an individual, or have a meaningful impact on society. I believe the superhero, warrior, and patriot tropes we see all too often in our industry are actually adding to the increasing reports of anxiety and burnout. The popular saying “what doesn’t kill you makes you stronger” isn’t a guarantee. Traumatic or stressful situations can still destroy trust and motivation, cause irreparable damage to our health, and push people out of the profession. The importance of safe and secure technology in our day-to-day lives is stressful enough. We don’t need to add the unreasonable presumption that we should be available 24/7 to save billionaires from themselves or protect governments who don’t protect us. As the saying goes, you are not required to set yourself on fire to keep others warm. ### If You Want a Seat at the Table, You Have to Earn It URL: https://www.discernibleinc.com/if-you-want-a-seat-at-the-table-you-have-to-earn-it/ Last updated: 2026-06-28T17:33:02.000Z I believe security and privacy perspectives are critical participants at the decision-making table, but that could be because I’ve seen the damaging financial, competitive, and regulatory consequences from inside companies who didn’t listen to their security or privacy advisors. Perhaps it’s because my role requires me to study and understand the attitudes of everyone outside an organization such as the SEC, the FTC, and customers — all of whom are demanding security and privacy play a bigger role in business leadership. Yet, despite the advantages of having all your risk functions represented at the senior-most table, many security and privacy professionals are still a long way away from becoming welcomed and trusted advisors inside their organizations– and this prevents them from having a meaningful voice in strategic business discussions even if they’re at the table. ## **Value over function** When security and privacy professionals argue that they deserve a seat at the table simply because of their function, they’re doing themselves a disservice. I learned this the hard way as a young corporate communications professional. External perception and reputation seemed like obvious perspectives to have in any discussion of material substance (particularly in the context of security or privacy); but in reality, most business executives only care about what helps them make better decisions and what makes them better leaders. I don’t fault them for this, that’s their job. Most executives think they’re already good at communicating (even if they’re not!) and so simply being an expert in my functional area wasn’t enough. If the CTO already thinks they’re an expert in my field, they’re not going to pull out a chair for me unless I can offer something they value because business leaders listen to advisors whose perspectives *they think* they need. If they already think that security and privacy are merely a function of compliance checklists or government hand waving, they likely don’t think they need your perspective on anything more strategic. . ## **Leaders listen to the advisors they think they need** We often hear the mantra that we can earn a seat at the table through the value we bring to the organization, but remember, *value* is in the eye of the beholder. Many of our clients come to Discernible because they’re seen by senior leadership only as “implementers”–people who can execute but aren’t seen as originators of significant insights. Some are seen as “tacticians,” which are essentially managers of implementers. These are critical roles for the success of an organization for sure, but they are not viewed as trusted advisors by senior leadership. How do you break out of that mold once you decide you no longer want to be seen as an implementer or tactician? - **Define your role and live it.** If you view yourself and your role in limited terms, so will everyone else. Remember that we teach others how to treat us–and if you need more resources to scale a program that goes beyond compliance or bare minimum procurement requirements, then stop characterizing your work according to individual regulations. Leaders won’t trust your counsel beyond your functional area until they see you as a business problem solver. - **Use the business’s frame and vocabulary.** Use sufficient business acumen to understand the dynamics, processes, and vocabulary of your industry and sector. Understand the dynamics of your organization that leads to or inhibit competitive advantage. - **Give options with outcomes.** Sound decisions are made based on outcomes, not personal preferences. The job of trusted advisors is to help leaders identify and strategize toward the best outcome or sometimes simply the least bad outcome. Instead of using language like “we should do x” or “we have to do y,” try offering 3 doable options with anticipated outcomes. For example, what will happen if we do nothing, what will happen if we do something modest, what will happen if we do something big? Now, deliver your insights in those predictions. Don’t forget to include unexpected consequences – those are predictable too! ### Risk Communications: Recognizing Turning Points and Managing Decisions URL: https://www.discernibleinc.com/risk-communications-recognizing-turning-points-and-managing-decisions/ Last updated: 2026-07-07T21:46:48.000Z I’ve [written](https://www.discernibleinc.com/the-origin-of-discernible/) previously about how poorly the traditional crisis communications approach works for security communications. Today, I’m going to do it again. :) Crisis Communications implies that what you’re communicating about is out of the ordinary or outside your standard operating procedures. In reality, security communications is a daily engagement not only because of the frequency of potential security incidents. From vulnerability disclosures and user account takeovers (ATOs) to legally-defined data breaches, security is a topic of daily interest to our most important stakeholders. Not communicating about security until it escalates into a crisis is a self-fulfilling prophecy. Instead, security communicators should constantly be on the lookout for critical turning points that can determine the direction of the organization’s future or cost them their reputation. These turning points are almost always punctuated by decisions; thus an effective security communication strategy isn’t merely about what to say in high-pressure situations, but how to manage the decisions that lead us into them. In fact, as I noted in a recent [post](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/) about avoiding security and privacy outrage, it really all boils down to the individual decisions organizations make and whether our stakeholders – the people whose opinions and behaviors have the ability to impact our success – understand our decisions and support how we made them, even if they disagree with our specific conclusions. This is where a lot of organizations get tripped up because they’ve fallen to the misconception that transparency of the decision itself is equivalent to transparency of the decision-making process. Especially when it comes to decisions that function as turning points, transparency about how decisions get made is paramount because the determining factor in nearly every case I’ve seen is whether or not the process (not the conclusion) meets the expectations of our stakeholders. And when your decision-making process is perceived opaque or unfair–either because you failed to adequately explain it, or because it truly is flawed–individual decisions are now vulnerable to attack and discredited. Over the past two years, Discernible has been engaged by dozens of security and privacy organizations to diagnose security communication issues, architect tailored solutions, and lead the execution for these customized programs with both internal and external stakeholders. - **Align with organizational values** and communicate which ones have the most weight when making decisions; if you can’t prioritize your values, you don’t truly have any. - **Set standard criteria for who is involved**, why, and their role. Consider adopting a decision-making framework like Marcy Swenson’s [The Matrix](https://www.marcyswenson.com/my-writing/this-matrix-helps-growing-teams-make-great-decisions?ref=discernibleinc.com). - **Document the process**, including who is responsible for the final decision whether it be determined by consensus, executive power, or majority rule. - **Be consistent** in how decisions are made (unless your process sucks, then fix it and communicate the changes ASAP). Nobody likes surprise decisions. Below are a few additional tips for communicating your decision-making process to avoid creating an [incident](https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups/). ## **Tips for Communicating Your Decision-Making Process** - **Don’t get defensive** – Passing shade on someone for not understanding or daring to question your decisions and peek behind the curtain is so Facebook and Wizard of Oz. If you’re confident you made the right call based on the situation, be mature enough to explain it plainly even to folks who disagree with you. Finding common ground is critical to negotiating productive relationships. - **Be helpful –** Don’t try to gaslight people with so much unnecessary information that they give up before an effective engagement can happen. Not everyone is going to agree with every decision you make, but it’s important for long-term relationships and your reputation that even those who dislike you do so based on facts, rather than poorly managed communications. - **Find humility –** No one feels bad for companies facing hard choices. Recognize your privilege and don’t try to downplay the influence your decisions have on others. Ignoring this fact is an easy way to miss turning points that can escalate into an incident. - **Seek more perspectives** \- The most often cited cause of frustration with decision-making among internal stakeholders is the feeling that decisions are made behind your back even then they impact you. Here are a few questions we address with our clients when deciding who needs to be involved in the process: - Who has to carry out the course of action decided? - Who will it affect if something goes wrong? - Are you willing to take responsibility for a mistake? - How much time is available to spend on this decision? - Is there a deadline for making a decision and what are the consequences of missing this deadline? - Is there an advantage in making a quick decision? - Will spending more time improve the quality of the decision? - **Assign ownership -** Assign an owner for the decision-making process. They are responsible for ensuring the process is followed, documented, and completed, but not for making the decision themselves. Stuff without owners doesn’t get documented. - **Document & share -** Make it easy to find your process documents and specific decision-making procedures and considerations. Current and future employees will significantly benefit from the ability to review and learn from your choices instead of having to repeat the same mistakes in order to learn the same lessons. ### Third Party Security Incident Response: Communicating Even When You’re Not Exposed URL: https://www.discernibleinc.com/third-party-security-incident-response-communicating-even-when-youre-not-exposed/ Last updated: 2026-07-07T21:45:29.000Z *“The fundamental way of getting public approval is to deserve it.” - Arthur W. Page* Several weeks ago, our team was able to use the security incident at Okta to begin stress testing new IR communications procedures we recently developed for a few clients. What an amazing opportunity to confirm whether we’d hit the right chord for their organization with the protocols, roles and responsibilities, and operating principles designed for each one! As a result of their preparedness, these organizations were able to quickly assess their exposure, communicate risk levels to business units, and thoughtfully engage with external stakeholders. Perhaps most importantly, the incident provided a relatively safe way to practice their new procedures with cross-functional colleagues who were primed and ready to engage at the time and depth most appropriate for their responsibilities. I’ve since heard from a number of my contacts in the broader security community that they unfortunately faced significant resistance from business leaders, PR teams, and legal counsel when they attempted to communicate with employees and customers about their level of exposure, even when it was zero. I find this reaction both antiquated and revealing. Antiquated because it signals a lag in competency and revealing because it exposes an organization’s deficient attitude toward transparency and trust. ## **Why Some Companies Still Stick Their Head in the Sand** Fear is the #1 cause I’ve observed among companies that decide not to engage in stakeholder communications unless forced into it by regulatory or contractual obligations. They’re nervous about potentially negative attention because they don’t know how to talk about security or privacy as a positive pillar of their brand. If they’re that concerned about people looking under the hood, maybe they’re justified in hoping no one will notice, but that strategy comes with its own risks. Not acknowledging that risk doesn’t make it go away. The #2 cause is typically a lack of dedicated resources and ownership for relevant communications, meaning they don’t have anyone with the expertise or bandwidth to craft a cohesive strategy for stakeholders. It’s understandable that even well-intentioned brands don’t want to half-ass communications about security or privacy; but to an external stakeholder, the decision appears identical to that of the fearful organizations. ## **Benefits of Communicating When You Don’t Have To** Ultimately, companies that either run away from or seek to avoid engaging in conversations with stakeholders about their exposure to 3rd party incidents are missing important opportunities to build trust and credibility in advance of inevitable 1st party incidents during which all eyes will be on them. In my experience, it’s better to learn how to manage effective security and privacy communications before you become the primary target of public scrutiny. In fact, establishing a reputation with stakeholders for proactive and helpful incident communications has given our clients tangible value for their business. **Build Customer Trust** –Anticipate customer questions, demonstrate you care about them, and show you’re in touch with the latest developments by reaching out to your customers before they start sending out mass questionnaires.Even when your exposure level to a 3rd party incident is zero, show you’re a valuable resource to your customers by providing a basic overview of known facts, and reassurance that you’re monitoring the situation. At the same time, you can share details about previous engineering or business decisions that helped lower your exposure levels. *Pro tip: you can save your customer support and security assurance teams from having to respond manually to every individual request, while ensuring message consistency, by creating standardized, legally-approved information that can be shared publicly on your website or privately through a customer portal.* **Improve Internal Literacy** – If there’s one thing your c-suite, board of directors, and non-security employees have in common, it’s a lack of visibility into the value your security and privacy teams deliver when you’re not in the thick of a breach investigation. If you can’t bring your organization around to the position of communication proactively with external stakeholders, at least don’t squander the opportunity to educate people inside the company about your organization's relevance as a trusted partner and advisor. For example, a real-world 3rd party incident is an important moment to remind everyone of the tools, controls, and best practices you’ve set up – as well as their role in actually using them. :) It should have been an easy decision for organizations to remind their employees about when it’s safe to approve Okta sign-ins. Again, even if your organization doesn’t use Okta, how can you take advantage of the moment to direct employees’ attention on something you need them to do? **Normalize Communications** – Finally, one day you’ll need all internal and external stakeholders to trust what you say and your competency in mitigating a 1st party incident. It happens to everyone. **Everyone**. You will also need to avoid causing panic because, [as we’ve discussed before](https://www.discernibleinc.com/rescue-diving-and-the-psychology-of-security-privacy-incidents/), panic leads to poor judgment and decision-making. Normalizing stakeholder communications about security and privacy *before* a major incident reduces the risk of panic by establishing your organization as someone who has your shit together and can safely guide them through uncertainty. Moreover, the best antidote against a negative and material news cycle is an informed customer base that trusts you. Consider periodic educational campaigns for customers about potential risks, how you’re addressing them, and any action they need to take. If stakeholders only hear from you about security issues when you’ve caused them or been forced to disclose them, don’t be surprised if you actually end up causing panic every single time. It doesn’t have to be this way – you can make security and privacy safe topics for your company to discuss any day of the week. ### Risk Communications: An Introduction URL: https://www.discernibleinc.com/risk-communications-an-introduction/ Last updated: 2026-07-07T21:37:15.000Z Risk makes individuals, groups, and markets behave in certain ways. Our success as security and privacy professionals depends on our ability to help non-experts make risk-related choices. The study of risk communications examines the processes that determine how our communication with these stakeholders enhances or degrades their decision-making ability. Dr. Baruch Fischhoff, the Howard Heinz University Professor at the Institute for Politics and Strategy and the Department of Engineering & Public Policy at Carnegie Mellon University, has studied risk communications for decades and authored some of the most significant research and theory in this area. I discovered his work years ago and had the pleasure of participating in a [workshop](https://cltc.berkeley.edu/designing-risk-communications/?ref=discernibleinc.com) with him a few years ago at UC-Berkeley to investigate the current state of risk communications in the technology sector. In my experience, a risk communications framework is more appropriate for security and privacy issues instead of crisis communications work, which is primarily reactive by design. [As I’ve written before](https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups/), incentivizing crisis communications over prevention communications is a recipe for disaster. [It’s why I founded Discernible in the first place](https://www.discernibleinc.com/the-origin-of-discernible/), to give security and privacy organizations a communications partner that was equally invested in *preventing* crises. Even when counseling clients through incident response, our north star isn’t to defend mistakes or put lipstick on a pig. **Our goal is always to inform people about the benefits, risks, and other costs of their decisions, so they can make sound choices.** Every stakeholder benefits from helpful, empowering, and productive communications. Risk communications addresses their fear head on, strengthening relationships and helping people move forward. For example, let’s look at how Fischhoff's 4 steps for effective risk communications can help organizations work through incident response communications. [Fischoff outlined these steps in his 2012 overview of communication sciences](https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3752164/?ref=discernibleinc.com) presented to the National Academy of Sciences. I’ve added my own commentary and context regarding incident response. ## **1\. Identify the science most relevant to the decisions people face** First, we need to define who the “people” are in our situation. It could be customers, regulators, employees, other third party security teams, law enforcement, investors, etc. Typically, it’s a combination of overlapping stakeholders who consume information differently in various contexts. Informed choices usually require knowledge about multiple sciences. In most security or privacy incidents, the decisions facing our stakeholders might include aspects relevant to psychology, sociology, and economics. **Why does this matter?** Because one of the most important responsibilities of a professional communicator is identifying the specific facts that people need to know among the myriad of facts that would be nice to know. That analysis depends on the decisions we need to inform. We have to put ourselves in the position of our stakeholders and ask: *“When deciding what to do, how much difference would it make to learn X, Y, or Z?”* Our messages should begin with the most valuable information first and then continue as long as the benefits of learning more outweigh its costs i.e. recipients reach their absorptive capacity and don’t retain the most valuable information. You can also consider linking to additional information for those that are interested. Remember the facts that matter to security and privacy professionals may not matter to other stakeholders. However, we cannot disregard these professionals in our communications strategy either because of the influence they have over other stakeholders. As Fischhoff put it: *“No layperson could understand all of the relevant sciences to any depth. Indeed, neither could any scientist. Nor need they have such vast knowledge. Rather, people need to know the facts that are “material” to their choices (to use the legal term). That knowledge might include just summary estimates of expected outcomes (e.g., monetary costs, health risks). Or, it might require enough knowledge about the underlying science to understand why the experts make those estimates. Knowing the gist of that science could not only increase trust in those claims, but also allow members of the public to follow future developments, see why experts disagree, and have a warranted feeling of self-efficacy, from learning—and being trusted to learn—about the topic.”* ## **2\. Determine what people already know** Following a security or privacy incident, your stakeholders will think, feel, and believe a number of different things based on what they already know (or think they do). How much do they know about your organization’s security and privacy capabilities and investments? **This is my plug for proactive risk communications that distribute knowledge to your stakeholders in advance of an incident**. 😉 Be careful to avoid using full disclosure as a way of burying inconvenient facts within irrelevant ones. When your audience is forced to read between the lines of expert statements, they can’t make full use of the knowledge you’re giving them. Nor can they fairly evaluate our performance as experts – if you ever hope to receive the benefit of the doubt in the wake of an incident, you need proactive risk communications to educate stakeholders before that information becomes critical in their decisions regarding an incident. ## **3\. Design communication to fill the critical gaps** More than a century of social, behavioral, and decision science research has revealed many principles that can be used in designing effective risk communications. According to Fischhoff, *“a comprehensive approach to communication would consider not only principles of judgment and choice, but also behavioral principles identified in studies of emotion, which find that feelings can both aid communication, by orienting recipients toward message content, and undermine it, as when anger increases optimism—and diminishes the perceived value of additional learning. A comprehensive approach would also consider the influences of social processes and culture on which information sources people trust and consult.”* Security and privacy communications must factor in how stakeholders make decisions about the related risks. For example, fear may draw more initial attention to a message, but it also impedes judgment and sound decision-making; so informing without amplifying fear is important for risk communicators. ## **4\. Evaluate adequacy and repeat as necessary** Poor communications cause immediate damage if they keep people from using available security or privacy knowledge. They cause lasting damage if they erode trust between organizations and their stakeholders. This happens when stakeholders see organizations as insensitive to their needs and security/privacy professionals treat our stakeholders as incapable of grasping seemingly basic facts. Fischhoff provides a simple task analysis to test the adequacy of our communications. A communication is adequate if it: 1) contains the information that recipients need, 2) in places they can access, and 3) in a form they understand. Because each of these elements can be measured, it’s possible to measure general performance of our communications. However, [these are outputs, not outcomes](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/) and to truly measure our effectiveness, we need to measure the impact of our communications, such as changes in organizational reputation, trust, and stakeholder behavior. ### Privacy Outrage: How to Avoid it When You Can and Mitigate it When You Can’t URL: https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant/ Last updated: 2026-06-26T20:39:22.000Z One of the things our clients routinely ask for is help preparing for privacy incidents that don’t involve security breaches–things that are likely to cause outrage among customers, journalists, activists, or regulators, such as: - [Yes Facebook is using your 2FA phone number to target you with ads](https://techcrunch.com/2018/09/27/yes-facebook-is-using-your-2fa-phone-number-to-target-you-with-ads/?ref=discernibleinc.com) - [The Los Angeles Department of Transportation’s Ride Tracking Pilot is Out of Control](https://eff.org/deeplinks/2019/04/los-angeles-department-transportations-ride-tracking-pilot-out-control?ref=discernibleinc.com) - [Apple’s privacy reputation is at risk with the changes it announced](https://www.cnbc.com/2021/08/06/apples-privacy-reputation-is-at-risk-with-new-changes.html?ref=discernibleinc.com) - [Broken promises: How Singapore lost trust on contact tracing privacy](https://www.technologyreview.com/2021/01/11/1016004/singapore-tracetogether-contact-tracing-police/?ref=discernibleinc.com) Truth is, the best way to prepare for these scenarios is to understand how to prevent them by considering public perception throughout the design process. Below, I’m sharing a sample of questions I commonly ask when reviewing a product or feature proposal. When I led privacy, security, and engineering communications at Uber, my cross-functional partners probably got sick of hearing these questions from me, but over time they learned what I was looking for and often came to the table prepared for a more thoughtful discussion. Obviously, privacy communications professionals can’t single-handedly control everything in an organization, but I’ve seen this kind of proactive and self-reflective approach prevent embarrassing and costly privacy outrage more times than I can count. --- ## **Internal Privacy Comms FAQ** **What is the purpose of this feature/product?** *Be as specific as possible.* **Does it require collecting new types of data about people that we weren’t collecting before?** *Doesn’t matter if it legally falls under the category of PII or not, people will still care.* **Does it use data we already have in a new way than we’ve used it before e.g. phone numbers collected for 2FA now being used for ad targeting or shifting from aggregated to non-aggregated?** **What is the customer benefit?** *If there’s no meaningful customer benefit, the risk of outrage increases proportionally with the degree of potential harm to the customer, e.g. collecting personal data only for the benefit of your business without providing meaningful value from the customer’s perspective.* **Are any third parties involved and why did we choose them?** *If yes, check out the security and privacy reputation of each third party and prepare to explain why you believe they’re trustworthy. If you run into red flags, share your concerns with internal teams and consider alternative partners. You will be judged by who you choose to do business with.* **Has our information security team reviewed this feature/product for potential risks and vulnerabilities?** *If yes, find out if and where the security team expects potential issues to occur as well as any mitigation measures taken to reduce the risk to customers, e.g. adding 2FA by default on a new digital wallet product.* **What industry standards, research, or best practices justify our security assessment e.g. tokenizing payment information instead of storing in plain text?** **Have we done a data privacy impact assessment (DPIA) on this feature/product?** *If yes, ask for a copy to determine potential risk factors identified by legal, e.g. use of PII, as well as potential justifications/trade offs, e.g. encrypting data to reduce potential risk for customers.* - **Boss Mode**: Work with your legal colleagues during the DPIA process to ensure the language in those documents is clear and precise for a non-legal audience. You may want/need to make a DPIA public someday, so it should be understandable to non-legal stakeholders. If you’re ever nervous about a DPIA becoming public, that’s a reputation liability and you need to make the business aware of that risk. **What are the default security/privacy settings for this feature/product? Why did we choose them, i.e. what threat models are we considering?** **Are there relevant settings/controls that users can choose to exercise different privacy preferences than our defaults?** **Have we explored other design/business alternatives?** *If yes, why weren’t they chosen? If not, how will you justify not considering other options?* **What privacy commitments have we made publicly in our policies, media interviews, presentations, or contracts?** *How does this product/feature honor those promises?* ### This Year’s Strategic Relationships: Do You Have What You Need? URL: https://www.discernibleinc.com/this-years-strategic-relationships-do-you-have-what-you-need/ Last updated: 2026-06-26T20:21:35.000Z Welcome to 2022! This year – as in every previous year – relationships will be absolutely critical to the success of your team, your projects, your program, and your individual role. Over the past two decades, the most influential security and privacy executives I worked with were masterful at building, nurturing, and leveraging relationships. Many of us have spent the past few months planning for the coming year and documenting the objectives and outcomes we want to achieve this year. I bet fewer folks spent time considering the specific people whose support, approval, or adoption we need to meet those goals. Yet, the trust and influence we earn from the people around us–whether it’s our boss, business partners, customers, or team members–will determine the direction, scope, and impact of our efforts. Relationships need to be discussed during planning and execution. ## **Hot, warm, or cold** A simple exercise for strategic relationship management is to list the individuals critical to your short-term goals. If your success depends on a group or community of people, identify the decision-makers who influence or direct the behavior of other group members. I find it helpful to create a matrix of important relationships and conduct a periodic review of each by determining if they’re hot, warm, or cold. - **Hot -** individuals in hot relationships trust you, can easily forgive honest mistakes, and routinely articulate that they share your goals. When relationships are hot, you can turn to them when you’re in a pinch or accurately expect that they’ll advocate on your behalf in rooms you're not in. - **Warm -** a cordial, respectful relationship that still requires repeated persuasion and negotiating to gather support. - **Cold -** these relationships are non-existent, stale, or hostile. If you haven’t connected before or in a long time, even previously hot and warm relationships can become cold and unpredictable. In boss mode, you can expand those considerations to include long term aspirations, positioning, and trajectory of an entire organization, program, business unit, or company. If you know where you want to be in the next few years, it’s important to build the necessary relationships now, before you need to call on them. Most professional relationships I’ve come across fall in the category of warm. There’s nothing particularly wrong with them except that they require ongoing and consistent effort to prevent them from turning cold. On the other hand, many cold relationships could easily become warm with even just a small amount of attention and sincerity. Additionally, it’s common that for some important security and privacy relationships, such as customers or regulators, there may be someone else at your company responsible for managing those relationships. Specialization and familiarity are helpful in engaging with certain individuals. Normally, this is completely fine and it’s not worth fighting over ownership so long as the work is done well; but if these relationships are critical to your success, you need to contribute to their success by supporting and collaborating with your colleagues to build and nurture each relationship. This also means that those individuals responsible for the organizational relationships that matter to you are also priority relationships for you to care for. ## **3 tips for managing relationships** Relationships need time and attention. Don’t expect dramatic results overnight. That’s not how genuine and reliable trust is built. Rather, start early and think about what you can do to make the relationship truly beneficial for both parties. - **Meet other people where they are.** Use the language of your intended audience. This requires listening and paying attention to the cues around you. Don’t ever assume your expertise is the most important. - **Manage expectations** **honestly**. Be upfront about limitations and opportunities. When people don’t get what they expect from you, it hurts your credibility in those relationships. - **Add value by understanding what other people want and need**. Leave out the “optics” and “smoke and mirror” tricks you learned from unscrupulous leaders, and build your own reputation for delivering ethical win-win solutions. “Help me understand,” is a disarming and productive request. ### The Rise of Privacy Tech: Defining the Privacy Tech Landscape 2021 URL: https://www.discernibleinc.com/the-rise-of-privacy-tech-defining-the-privacy-tech-landscape-2021/ Last updated: 2026-06-25T19:10:04.000Z Last month, the Rise of Privacy Tech (TROPT) published their foundational white paper to define and fuel the nascent market of privacy tech. I was a part of the working group that met together over a span of eight months to create this resource for the key players in privacy tech: founders, investors, domain experts, and buyers. Thanks to the impressive leadership of TROPT CEO Lourdes Turrecha, the white paper pulls together important concepts from privacy pioneers and luminaries, and explores the role of privacy tech throughout data and development lifecycles. The white paper is available [here](https://www.riseofprivacytech.com/definingprivacytechwhitepaper2021/?ref=discernibleinc.com) (without having to provide any personal information to download - leading by example). Last week, I joined Lourdes for a public discussion about the white paper and to share some of my thoughts about the current state of communications in the privacy tech market. This blog post is a summary of the key takeaways. You can watch the full recording of our conversation [here](https://youtu.be/b2bcO5ax9uU?ref=discernibleinc.com). ![](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/00b909d8-b8bc-427c-8029-d71c073938da/Quotes-09.png) ## **Words matter** Creating good websites is really hard. I get it. That’s why I partner with trusted experts when advising clients on the navigation and design of their public sites. What I do know are words and how the privacy community responds to them. Sadly, the majority of copy on B2B privacy tech websites serve up the exact same flavor of bland alphabet soup no matter what their products actually do. This makes it really hard for the right prospects to find you and understand how you can help them. From your home page, visitors should be able to immediately discern the following: - The specific privacy tasks or jobs your product handles - What (honestly) sets your technology apart from everyone else (including in-house solutions) - Where it fits in a typical tech stack - Any non-privacy benefits to help secure buy-in from other stakeholders Additionally, visitors should be able to easily locate the following from your navigation bar: - Technical documentation - Privacy policies and practices (unless you’re one of those privacy tech companies that doesn’t believe in what you sell) - Security certifications and attestations ## **Think like an ethnographer** Effective communication in any context is not only about knowing the words we use, but also how well we understand the customs and norms of the culture. As the privacy tech community grows and evolves, so does our culture. What was once considered the ugly duckling of legal departments, is now launching a thousand ships inside engineering, data science, and marketing organizations. Organizations are spending significant resources to support the likes of [Enigma](https://www.usenix.org/conference/enigma2022?ref=discernibleinc.com), [SOUPS](https://www.usenix.org/conference/soups2022?ref=discernibleinc.com), and [TROPT Data Privacy Week](https://hopin.com/events/tropt-data-privacy-week-event/registration?ref=discernibleinc.com), which bring together cross-functional privacy practitioners. At events like these, you’ll learn which privacy pain points still aren’t being addressed by existing solutions, how technical teams evaluate technical solutions, and how privacy leaders allocate resources. The best way to get to know the privacy tech community and what makes us tick is to join us in building direct relationships with individuals leading, influencing, and participating in privacy work. This includes engaging with the members of privacy-focused groups like [TROPT](https://www.riseofprivacytech.com/troptinnovatorsmembershipprogram/?ref=discernibleinc.com) as well as groups like [USENIX](https://www.usenix.org/?ref=discernibleinc.com) whose members are often engaged in privacy tech work even if they don’t identify as privacy professionals. ![](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/c386a792-12d0-4b9e-b854-d3b2f1f265c2/Quotes-11.png) There is a common assumption among venture capital firms and some privacy tech startups that the growing volume of global privacy regulations will automatically drive demand and adoption for every kind of privacy technology that claims to aid in compliance. This expectation isn’t guaranteed. First, it ignores the very real ability and preference inside many companies to build their own solutions tailored to their chosen architecture, scale, and flavor of dysfunction. Many vendor marketing strategies are so reliant on the fear of non-compliance that they don’t see how capable their prospects are at identifying and designing their own solutions, and in a fraction of the time it takes to implement some third party solutions. As a third party, your responsibility is to articulate and deliver a compelling value proposition that companies can’t build for themselves. To understand this, you need to dig deeper into understanding privacy in practice. Second, it ignores the fundamental cross-functional nature of privacy work. The data ~~minefields~~ landscapes inside most organizations are incredibly complex, as are the internal politics that surround them. Marketing privacy tech is not as simple as convincing a legal team to adopt your tool when they don’t have their own engineering resources or ownership over the relevant systems to implement it. Similarly, vendor promises of “automagical” compliance are typically less compelling for technical teams whose primary objective is to ensure a certain standard of performance and reliability for mission-critical operations. If you don’t understand the personalities and incentives your customers have to work with, you don’t understand your customers. Ultimately, the growth of privacy tech is a net positive for the world. We’ve demonstrated that there is value in protecting individual privacy, not only in exploiting it. But to be successful in the next chapter of this nascent field, startups will need a deeper understanding of how privacy work is done inside organizations in addition to keeping abreast of the latest regulatory requirements. Engaging with the community helps vendors build solutions nimble enough to grow with the profession of privacy and not confine it to checklists. ### Exercising Influence as the Security Team: Look for Friction Not Just Fuel URL: https://www.discernibleinc.com/exercising-influence-as-the-security-team-look-for-friction-not-just-fuel/ Last updated: 2026-06-25T19:02:55.000Z How do you drive security considerations into decisions made by other teams and stakeholders? As I discussed in my presentation at the [USENIX Conference on Privacy Engineering Practice and Respect (PEPR) in 2020](https://www.usenix.org/conference/pepr20/presentation/ensign?ref=discernibleinc.com), learning how to influence people outside your reporting chain is a boss-mode skill. Many security professionals believe that more internal marketing or “awareness” campaigns will lead to better security outcomes. But often, these efforts fail to move the needle. That’s because these programs often try to convert stakeholders into security champions willing to swim upstream for the cause, instead of looking for the obstacles that prevent stakeholders from making good security choices by default. This is something we encounter a lot in our work with clients at Discernible and was a major inspiration for our negotiation and group decision-making workshops. ## **What are your stakeholder’s hidden frictions?** Subscribers of Discernible’s [newsletter](https://discernibleinc.com/newsletter-signup?ref=discernibleinc.com) know that I’m a big fan of the Hidden Brain podcast as well as applying lessons from other disciplines to security communication challenges. Other fields of study beyond security already know so much about how the human brain works and how people make sense of the world around them, we’d be crazy not to learn from their scholarship. The Hidden Brain podcast aired an episode last week entitled “[Hidden Obstacles](https://omny.fm/shows/hidden-brain/work-2-0-the-obstacles-you-dont-see?ref=discernibleinc.com)” that I found poignantly relevant to security communications. The episode highlights the research of Loran Nordgren, Professor of Management and Organizations at the Kellogg School of Management at Northwestern University. I’ve taken the liberty of applying his insights to common situations I experience with security organizations. The episode focuses on Nordgen’s research and includes the story of a Chicago-based company that manufactures fully-customizable sofas and chairs, promising a one-of-a-kind piece of furniture. After spending hours designing their custom furniture in the showroom, would-be customers disappeared and the company wasn’t able to convert the sale. As a result, the company considered lower prices, changing the customer experience, or altering the product in order to drive more sales conversions. However, an ethnographic study among their target customers revealed that the problem was actually that people didn’t know what to do with their existing sofa. This conundrum was enough to prevent them from buying a new sofa no matter how much they liked the ones sold by the manufacturer in Chicago. Upon learning this, the company began offering to pick up customers’ old sofas when the new one was delivered. This immediately resolved the company’s conversion problem. Sometimes in security, we try to win people over by pushing harder, missing the friction that prevents them from exercising the behavior or decisions we need. Nowhere is this more prevalent perhaps than in the way we use media headlines to try and scare our colleagues into compliance with our demands instead of starting from a place of empathy. In fact, most of the time, our colleagues already agree with us that security is important, but we’ve failed to take into account simple things standing in their way, such as: - Do employees know you exist and how your work relates to them personally? - How easy is it for people to reach your security team with questions or concerns? Are there self-service options for resolution? - How timely, supportive, and compassionate is your security team in their response? - How disruptive or out-of-band is the process for working with your security team? ## **Instead of adding more fuel, build a lighter spaceship** Hidden Brain podcast host Shankar Vadantam asks Nordgren about why organizations and individuals tend to focus on the “fuel” component of the equation, rather than on friction. If we’re trying to launch a spaceship into space, he says, it is tempting to focus on building a bigger rocket instead of designing a lighter spaceship. According to Nordgren, this is because we naturally understand behavior in terms of internal forces such as motivation and intent. These are “fuel.” When people don’t take the action we want, we often (incorrectly) assume the appeal is insufficient, so we try to increase the appeal with more fuel. For security teams, it can seem easier to look for a bigger, flashier solution instead of smaller solutions that could help address friction. Yet, Nordgren cites the common but incorrect assumption that adding more gun powder to a gun will make a bullet travel faster or farther as an analogy for how a focus on fuel can be counterproductive. Although gunpowder is responsible for the initial velocity of a bullet, the reason a bullet is able to fly so far and so true is because of its aerodynamic design. The shape of the bullet helps reduce the friction, or drag, caused by wind resistance and gravity. Adding more gun powder actually creates more drag. How many appsec or product security engineers spend hours every day trying to convince developers and other engineers to patch their systems or fix code vulnerabilities? Depending on the size of your organization, your team could potentially have dozens of identical and duplicative negotiations happening at any given time with cross-functional team members. Each of them are fighting to add more gunpowder instead of making the process more aerodynamic. In this kind of situation, I often find significant friction from the lack of formal incentives for developers to maintain the health and quality of their code. If security considerations aren’t mentioned in leveling ladders or performance reviews, the headwinds preventing developers from prioritizing security work is very strong. This is where CISOs and senior members of the security team need to flex their influence and relationships with their senior engineering peers to negotiate for security to be an official expectation of their team. For all the CISO’s reading, if you don’t already have this kind of influence, it’s not too late to start earning it. You can remove a lot of headwind for your entire team. ## **Subtracting friction** Nordgren suggests that in order to identify friction, we need to do the upfront work to find it and shift our focus from the issue to the audience, specifically, the broader, contextual, emotional needs of our audience. He says friction tends to be buried and therefore requires discovery, perspective taking, and knowing your audience to find it. We can’t dismantle it until we can see it. So, what kinds of friction do security professionals need to look for and then minimize? Nordgren mentions three types of friction in the episode, which I’ve put into a security context: - **Path of least resistance** \-Have we made it easy for individuals to interact with our security people, tools, and procedures? - **Inertia** \- Our minds reflexively favor things that are familiar even when the benefits of change are overwhelming, and this pushback is usually greatest when we’re pursuing big, radical change. So how are we connecting security work to things already familiar to our stakeholders and is it possible to break big changes into smaller, incremental ones? - **Emotional cost -** It’s common for there to be anxiety about tough conversations with both internal and external stakeholders. Have we trained our security team members to have those discussions with confidence and empathy? Are we seen as a supportive guide or partner to our stakeholders or do they still see us as out-of-touch with their needs? *If you’re interested in learning more about Loran Nordgren’s research, check out his Wall Street Journal Bestseller, “*[*The Human Element: Overcoming the Resistance That Awaits New Ideas*](https://www.amazon.com/Human-Element-Overcoming-Resistance-Awaits/dp/1119765048?ref=discernibleinc.com)*.”* ### The Communication Theory of Resilience: 5 Tips for Security & Privacy Organizations URL: https://www.discernibleinc.com/the-communication-theory-of-resilience-5-tips-for-security-privacy-organizations/ Last updated: 2026-06-25T19:00:28.000Z There is a lot of contemporary discourse about resilience, inspired by years of collective crisis, local and global unrest, and personal suffering. It's difficult to feel stable and not burn out. A number of communication theories and research studies dive into the factors behind the seemingly unstoppable terribleness of things; like the rise of the attention economy, systemic racism and social injustice, polarization, and misinformation. But I want to focus here on what we do next. How do we move forward together as teams, organizations, and communities? A decade before 2020 became the year that would never end, Patrice Buzzanell, now Chair and Professor of the Department of Communication at the University of South Florida, proposed a new way of understanding and explaining how communication processes can help people reintegrate after difficult life experiences such as disruption, loss, trauma, or disaster. She called her proposal the [**Communication Theory of Resilience**](https://doi.org/10.1111/j.1460-2466.2009.01469.x?ref=discernibleinc.com). The theory is rooted in Buzzanell’s [belief](https://digitalcommons.usf.edu/spe%5Ffacpub/798/?ref=discernibleinc.com) that rather than being an “individual phenomenon that someone either possesses or does not, resilience is developed, sustained, and grown through discourse, interaction, and material considerations.” Yet, major stressors that impact security and privacy teams are complex and unfold over time. So, different strategies may be more effective at different stages of the process and in different contexts. For example, disruptions caused by poorly managed security incidents may be brief but jarring, often leaving security teams to lick their own wounds in fearful anticipation of the next one while the rest of the company quickly moves on. In contrast, the loss of a trusted leader or colleague due to the extremely short talent retention periods in infosec points to something more systemic beyond any single organization. The Communication Theory of Resilience offers five communicative processes through which resilience can be developed and nourished: 1. Crafting normalcy or being able to talk normalcy into reality 2. Affirming identity anchors or the stories we rely on to define who we are in relation to others 3. Maintaining and using communication networks, or building and utilizing social capital 4. Reframing or finding new ways to look at a triggering event 5. Validating negative feelings while focusing on positive emotions, such as hopefulness and self-efficacy In my experience, security and privacy teams are typically dealing with simultaneous changes and concerns. A breach is never just a breach; it’s long hours, intense pressure, interpersonal conflict, and self-doubt. I wrote about some of that [here](https://medium.com/discernible/resilience-chief-security-officers-must-coach-2c34c45a75db?source=friends%5Flink&sk=352f3ca853385a73ca30ada17e6c2bfd). Similarly, for most privacy teams the grueling intensity never seems to show any signs of slowing down; whether it’s jumping in front of a speeding train to stop the latest product disaster from flying out the door, or the ever-present high expectations with insufficient resources. These experiences wear on our teams, and leaders need to step up to build and sustain resilience among their team. Something that comes up routinely in our work at Discernible is the need for teams to build these communicative processes *before* their teams face difficult experiences. A good strategy for change management should include similar considerations; but as incident response teams know, trying to build the relational and procedural infrastructure while responding to a triggering event is always more difficult and less effective than being proactive. Building on Buzzanell’s framework, below are the five communicative processes from her theory, translated into everyday strategies for security and privacy teams to build stronger, longer-lasting resilience. **1\. Make efforts to maintain your and your team’s sense of normalcy, and be open to creating new routines and adapt.** No one fights change like engineers and lawyers, and for understandable reasons. Without reliable infrastructure or legal precedent, it would be even harder to manage security and privacy projects. But might I suggest that a healthy sense of normal includes confidence in our ability to adapt. Procedures and requirements may change, so anchor your sense of normalcy in how you treat each other and your willingness to step outside your comfort zone to protect something you value. **2\. Celebrate your identity.** Yes, you’re the security or privacy team for Acme Co, but who are you really? What are the characteristics and qualities that form your viewpoint and decision-making? Anchoring your identity is about more than knowing who you are, it’s also about setting consistent expectations. Mission statements and written values mean nothing if you don’t live them. Everyone on your team should be able to articulate your shared aspirations, principles, and priorities -- and demonstrate them through their work and interactions with others. **3\. Establish strong communication networks and stay connected.** Your team needs trusted communication channels, norms, and procedures that can support the needs of different situations and contexts. People need to know where to look for critical information, how to get help, and which notifications they can ignore during a stressful situation. A matrix of available channels, recommended use cases, and a prioritized SLA for each is a helpful start. **4\. Look for silver linings (& hidden levers).** So your CSO doesn’t report to the CEO yet. Where else can they earn and exercise influence to improve life for their team? Where can team members build relationships with cross functional partners to make security outcomes a shared goal? Talk about these opportunities frequently and openly as a team. You have more power than you think. **5\. Acknowledge when things suck and be proactive about moving forward.** Losing a trusted CSO, being on-call during a Sev1 outage, being treated as the clean up crew for other teams, not being consulted about decisions that directly impact your work – all of these things suck, and they’re common among many security and privacy organizations because we’re not proactive enough about shaping our own normalcy before bad things happen. ### Sincere and Effective Apologies URL: https://www.discernibleinc.com/sincere-and-effective-apologies/ Last updated: 2026-06-25T18:55:20.000Z Many of us learned the basics of an apology when we were young because it’s fundamental for sustaining human relationships. When we mess up we express remorse, accept responsibility, and do something to rectify the situation. This process shows not only how much we value our relationship with the person we’ve wronged, but it’s essential for moving the relationship forward. An effective apology is the first step in an ongoing process between offender and victim that helps build understanding over time. Yet, despite how early or often we’re reminded of their importance, apologies are still really hard for many people and organizations. Moreover, good apologies can feel elusive unless you understand their purpose and how to satisfy their expectations. ## **Why are apologies hard?** There are a number of reasons why something we learn as a child can feel infinitely harder as an adult. On the June 21, 2021 [episode](https://hiddenbrain.org/podcast/the-power-of-apologies/?ref=discernibleinc.com) of the Hidden Brain podcast, psychologist Tyler Okimoto and host Shankar Vedantam discuss some of the mental barriers that can challenge our ability to say “I’m sorry.” First, admitting we’ve done something wrong relinquishes power and control. This can feel threatening to the person apologizing, but I argue that’s exactly what’s required to make an apology effective and save a relationship. When someone gives us an apology that attempts to protect their power and control, we know right away it’s insincere. Effective apologies require surrender. But Okimoto also mentions how admitting a mistake can question concepts we hold about ourselves, e.g. “I’m a good person,”or “our company has a positive impact on the world,” etc. Maintaining a positive self-image is important not only to individuals, but also organizations. The cognitive dissonance between the harm we’ve caused and who we want to believe we are makes it difficult for a lot of people to give sincere apologies, even when it’s clear to everyone else that it’s the right thing to do for a relationship. ## **Apologies that fail** Even with the best intentions, apologies can easily miss their mark. Okimoto mentions a couple of the most common reasons throughout his discussion with Vedantam. First, *how* we apologize can make victims furious. Denial, looking for excuses, and attempting to paint yourself in the best possible light are all triggering elements of bad apologies. Using apologies to do anything other than sincerely apologizing to the person or people who’ve been hurt is a recipe for rejection. Another common failure is giving an apology in order to convince someone to forgive you. The purpose of giving a sincere apology is that it’s the right thing to do; it shows respect for your relationship, and in high-profile cases, can even make society better. I love Okimoto’s recommendation to think about apologies as a gift without the expectation of forgiveness. It’s something we do for others, not ourselves. Finally, missing or dismissing when an individual case reflects a symbolic case can easily compound the problem by destroying the credibility of an apology. For example, apologizing for individual incidents of workplace harassment, discrimination, product failures, or societal harms caused by our organizations as if they’re isolated cases for everyone else ignores the lived experiences of those we’ve hurt. We can’t sincerely apologize for things like racist policies or behavior, online abuse, and unfair working conditions as if they’re not part of large systematic societal issues. Trying to dodge the larger context is a self-protecting mechanism that consistently fails to meet the expectations of victim groups looking for broader systemic solutions; organizations disregard this at great cost to their own integrity and public trust. ## **When you really mean it** In 2013, therapist Jennifer Thomas teamed up with Gary Chapman (author of The 5 Love Languages) to publish a book entitled, “When Sorry Isn’t Enough.” It’s a guide to using the five apology languages based on interviews they conducted with thousands of Americans to ask two questions: *When you apologize, what do you typically say or do?* *When someone is apologizing to you, what do you want them to say or do?* According to Thomas and Chapman, one or two apology languages are required in what any individual reconsiders to be a sincere apology. If you miss the types of apology language they respond to, then they see your apology as incomplete and probably won’t accept it. I found this particularly interesting as a communications professional who advises individuals and organizations on giving apologies, because it underscores something we already know to be true for other types of communication: > *There is no universal formula; you need to understand your audience.* Based on their research, Thomas and Chapman define the following five apology languages: 1. **Expressing regret.** This apology language communicates that you feel bad that your behavior hurt the relationship by acknowledging that what you did was wrong. Don’t get stuck into thinking that what you did has to be morally wrong. If it hurts the relationship, it is wrong. When you effectively express regret, you also tell the other person precisely what you’re sorry for without blaming them for your behavior. If you say “I’m sorry for X, but I did it because you did Y,” you’re no longer apologizing. 2. **Accepting responsibility.** This apology language includes explicitly accepting responsibility for our behavior. Again, for some people, this is what they consider to be a sincere apology; and if you don’t acknowledge that what you did was wrong, then in their mind, you’re not sincere. Even if you say, “I’m sorry,” they’ll struggle to believe what you’re saying because they don’t think you really mean it. 3. **Making restitution.** A third apology language is offering to make restitution by committing to do whatever it will take to make things right. This is something that some people are waiting for when you apologize. If you don’t offer to make things right, then they have a hard time forgiving you. The sincerity to ask how you can make it right and the willingness to actually do it, is how these folks will know your apology is real. 4. **Genuinely repenting.** The fourth apology language is expressing the desire to change and the commitment to prevent it from happening again. For some people, if you don’t express the desire to change your behavior, they find it difficult to forgive you, especially if you’re trying to apologize for a pattern of behavior. In this case, every time you said, “I’m sorry,” in the past caused them to question what you were going to do about it. 5. **Requesting forgiveness.** The last apology language is asking for forgiveness. For some people, this is what they consider to be a sincere apology, and if you don’t actually request forgiveness or ask for forgiveness, in their mind, you haven’t apologized. From a communications perspective, this is mostly likely because they’re looking for an explicit transfer of power and for you to accept whatever decision they make. This is a difficult language for many organizations that lack the patience or humility to offer power over the relationship to someone else. ## **What this means for leaders and organizations** First and foremost, I want to re-emphasize the point about understanding your audience. We’re all dependent on our relationships with others, both as individuals and organizations. So if there’s someone or some group of people that is important to you or your company, get to know them now. Apologies are the wrong time for guessing the values, attitudes, and expectations of the people you’ve hurt. Moreover, forgiveness does not equal trust. It merely opens the door to the possibility that trust can be rebuilt. As psychologist Charlotte Witvliet, Professor of Psychology at Hope College, discusses on the June 14, 2021 [episode](https://hiddenbrain.org/podcast/the-power-of-mercy/?ref=discernibleinc.com) of the Hidden Brain podcast, forgiveness doesn’t destroy or erase all of the painful emotions experienced by the person or people we’ve hurt. In fact, nursing a grudge can help take the edge off their sadness and give them a greater sense of perceived control. Don’t expect anyone to behave as if the hurt never happened, even if they do forgive you. Often, I see organizations flustered that their apology is not accepted or even if it is, the recipient continues to look for evidence to justify their anger. Let them. Anger about *what* you did may never go away, but a sincere apology and restitution can help you start a new journey with them that redefines or heals your relationship. Witvliet explains that when we’re distressed, we usually aren’t in a position to think flexibly. We’ve discussed this idea [before](https://medium.com/discernible/preparing-for-task-loading-during-incident-response-ee7cbe524ccb?source=friends%5Flink&sk=b77e9d7a7b4852a9a8e158d7d3ad25cf) in the context of appropriate task loading for effective incident response. As Witvliet describes, when we ruminate on past hurts, we often experience a stress response, which makes it harder for us to get past a grudge. Therefore, we can’t expect anyone to forgive us on our terms, especially if we haven’t assured them the psychological safety they need and don’t have plans in place for accountability that stops the harm. Witvliet’s research suggested that giving people something to remind them of your humanity can help support a calmer, more regulated response. ### Metacommunication and Bug Bounty Programs URL: https://www.discernibleinc.com/metacommunication-and-bug-bounty-programs/ Last updated: 2026-06-25T18:48:29.000Z In the early 1950s, Jurgen Ruesch and Gregory Bateson coined the term metacommunication, defined as “communication about communication.” It’s commonly understood as the unspoken or nonverbal cues that accompany or encapsulate a message. Things like body language, tone of voice, gestures, and facial expressions often contain their own meanings that amplify, clarify, or confuse the words we use. But what about in written communications, such as those used for email and bug bounty platforms? These are text-based, asynchronous messages where many of the most commonly recognized non-verbal cues like body language and facial expressions are non-existent. But that only amplifies the meaning of other cues and misunderstanding them or ignoring them often leads to unnecessary and emotionally-charged escalations, distrust, and burn out. When working with asynchronous, text-based communications, what metacommunication do bug bounty teams and researchers need to be aware of? In my experience, the most important are context and relationships. ## **Context** There is a lot of context surrounding written communications, such as when messages are sent (e.g. day of the week, time of day, amount of time it takes to respond, etc.), their length, and the cultural perspective with which they’re crafted and interpreted. This means sending an effective message includes considering the context in which it will be received. What’s convenient or culturally acceptable to a security engineer in the United States may not be the best approach for communicating with a researcher on the other side of the world. Understanding context is critical to effective communication because it impacts our interpretation of language, tone, and meaning. Whether your message is clear or confusing comes down to the structure of your prose and the context in which it’s read. Getting this right is often more difficult without the cues of live or face-to-face communication, so some bug bounty teams become overly dependent on phone or video conference calls for all conflict resolution. Sometimes this approach is helpful, but unless appropriate norms and expectations are already in place, the context of switching formats can immediately signal an escalation and put people on edge. A significant part of our business at Discernible is coaching bug bounty teams and researchers on when to use certain communication channels and how to use them effectively by maximizing the advantages of context and minimizing its potential risks. ## **Relationships** Another critical aspect of metacommunication is that every message also includes an implicit metacommunication about the relationship between the people involved. This relationship not only frames the message, but the message itself can imply a certain type of relationship (for better or worse). A simple way to think about this is the difference in how we speak to people we’ve just met compared to people we’ve known for a long time. What we disclose and the words we use often change depending on who we’re talking to. When I first started working with responsible disclosure programs more than 10 years ago, most of them were private and invite-only. Researchers were invited to join only after establishing a trusted relationship with the security team. This meant that all our communications were framed within an existing (and usually positive) relationship. Things like benefit of the doubt were far more common because we all knew each other and assumed good intent. It’s much easier to unfairly or harshly judge someone we don’t know, and the emotional frustration that comes with constantly facing animosity is one reason triage teams burn out so quickly. Today, many bug bounty programs solicit reports from researchers the security team may not know personally, which adds another layer of complexity to the communication requirements. How we communicate to each other tells us something about how we perceive our current relationship and, by extension, how we feel about the other person. Language that divides internal security teams from external researchers can be interpreted as dismissive or condescending, communicating to the other person that we don’t value them as an equal to ourselves. Building trusted relationships with strangers is not easy; it takes time, patience, and consistent commitment. However, the best bug bounty programs and researchers invest in good communications, not only to improve efficiency, but to protect themselves from getting stuck in unproductive or destructive loops. ## **Pro Tips** Over the years, I’ve focused on a few key skills with the bug bounty teams I work with to help them overcome some of the most challenging aspects of bug bounty communications. - **Focus on outcomes**. Trying to win an argument is not an outcome, it’s a sign of immaturity. Remove “winning” as an expectation of your communication. For both bug bounty teams and external researchers, maintaining a productive long term relationship is usually the more valuable prize. That does not mean you should put up with abuse or unprofessional behavior --- it means be strategic about the boundaries set and the tone you use, with the expectation that the person you’re currently communicating with could be in your life longer than you might choose. Don’t shoot yourself in the foot. - **Explain your decisions but don’t get defensive.** It’s not a fight unless *you* make it one. Every message is an exercise in learning about someone else’s communication style and proficiency. In helping the other person understand where you’re coming from, don’t assume they will see the same set of information the same way you do, even before the added complexity of context. Simply throwing facts at someone rarely works, especially if you're hoping to convey respect. Relationships, whether with this specific individual or others in the community who may see the exchange, are paramount. - **Pay attention to what they heard**. If you’re not getting the reaction you expected, resist the temptation to get frustrated or escalate. Instead, find out what they interpreted from what you said and if you need to, calmly and patiently clarify what you meant. - **Slow down.** It’s common for people to feel anxious when they don’t understand each other, which can cause rapid-fire responses and emotional escalation. There is no reward for the fastest response when it adds confusion, anxiety, or destroys a relationship. Take your time to gather your thoughts and ensure that you’re interpreting their message accurately. Calmly and respectfully ask for clarification if you need it. ### Measuring Communication Effectiveness in Security and Privacy - Research, Analysis, and Evaluation URL: https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation/ Last updated: 2026-06-25T18:45:39.000Z One of the most well-known communication models is the one developed by political scientist and communication theorist Harold Lasswell in 1948\. It’s been adapted many times over the years due to it’s easy-to-understand description of communication: ## **Who ➡️ Says what ➡️ To whom ➡️ With what effect?** Communication is critical to every aspect of security and privacy operations. While major incidents steal the headlines and public attention, the reality is that everything within the purview of security and privacy benefits from improved communications. Without effective communication, incident response is sluggish and chaotic, policies aren’t followed or enforced, business leaders make uninformed decrees, audits drown team morale, and confusion among external stakeholders breeds mistrust and resentment. If there was ever a time for security and privacy leaders to upgrade their communication skills and those of their team, this is it! Folding communication theory and practice into a security or privacy organization is a natural part of earning trust, credibility, and influence. However, it’s not always obvious how to build this capability without a formal communications mandate or experienced staff. Fortunately, the Institute for Public Relations (IPR) offers a useful [guide](https://instituteforpr.org/wp-content/uploads/IPR-Guide-to-Measurement-v13.pdf?ref=discernibleinc.com) for quantifying the impact of communications using research, analysis, and evaluation. Initially intended as a resource for chief communication officers, the guide is applicable to anyone who seeks to improve communications within their function, measure its impact, and articulate that value to leadership. The non-linear process of communication, as defined by IPR, includes five core components: 1) landscape analysis, 2) setting objectives, 3) developing strategy, 4) tactical creation and activation, and 5) evaluation and continuous improvement. Our team at Discernible is often called in to rescue security and privacy communication initiatives that stall and burn out before advancing beyond tactical creation and activation. It’s easy to get excited about specific program elements or new assets. It’s also easy to measure to measure outputs. You can simply count how many times you distributed a communication asset such as to an email, presentation, newsletter, blog post, or quarterly business review (QBR) report. However, without conducting research to first understand the environment, to define and prioritize objectives based on those findings, or to develop appropriate messaging for various stakeholders, programs born solely from tactical creation and activation can easily end up as an expensive shot in the dark. Additionally, communication programs that lack evaluation rob your team of the ability to accurately capture and articulate value beyond output volume. ![Image Credit: Institute for Public Relations](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/1625672596817-8AI684PDSL0G9LJ0YOQE/IPR+Communication+Process.png) **Image Credit: Institute for Public Relations* ## **Outputs, Outtakes, and Outcomes -- why does it matter what we measure?** When measuring the effectiveness of communication activities, it’s imperative that we use valid metrics—meaning they actually measure what they’re supposed to. Metrics like click through or open rate can’t measure the persuasiveness of a message or its effect on perception, credibility, and trust. Your overall communication objectives — outputs, outtakes, or outcomes — dictate what we need to measure in order to evaluate the effectiveness of our efforts. - **Output:** the number of communication artifacts produced and/or distributed. *It’s a measure of what the organization does rather than its impact.* - **Outtakes:** measurement and analysis of *how* stakeholders received your communication such as awareness, recall, understanding, and retention. - **Outcomes:** the effect, consequence, or impact of communication activities, ultimately representing the perspective of stakeholders with a *quantifiable change* in attitude or behavior. This comparison from IPR’s report further illustrates the difference between how outputs, outtakes, and outcomes can be measured in the field of public relations. ![Image Credit: Institute for Public Relations](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/1625672757619-W42HH0Q6CDQIPQY7TRIS/IPR+Outputs+Outtakes+and+Outcomes.png) **Image Credit: Institute for Public Relations* Below, I’ve made a simple adaptation to show how this same framework can be applied to communication initiatives for security or privacy. Remember, we can’t just claim that our activities lead to trust or reputation benefits, we must measure it in order to prove it. In certain cases, I recommend partnering with business partners that already measure these types of outcomes for the company at large (i.e. marketing, customer research, PR, etc.) and ask how your efforts might be included in their ongoing research and evaluation measurements. ![Image Credit: Discernible Inc](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/1625673102394-ECD2R5D1VQKEFD0G5AYR/Security+Comms+Outputs+Outtakes+and+Outcomes_Discernbile+Inc.png) **Image Credit: Discernible Inc* Whether your team needs to communicate about a new security training program, data protection regulation, or emerging incident, don’t miss your opportunity to research, measure, and evaluate the effectiveness of your communication investments. I highly recommend reviewing the entire IPR guide for more insights on how to effectively measure communication effectiveness, and adapting these principles to meet the communication needs of your security and privacy organizations. ### Preparing for Task Loading During Incident Response URL: https://www.discernibleinc.com/preparing-for-task-loading-during-incident-response/ Last updated: 2026-06-25T18:40:44.000Z Our capacity for processing information is limited. Originally proposed in 1988 by psychologist John Sweller at the University of New South Wales, cognitive load theory [states](https://www.sciencedirect.com/topics/psychology/cognitive-load-theory?ref=discernibleinc.com) that “as a result of higher cognitive load, a stimulus is more difficult to pay attention to.” A “task load” describes the degree of difficulty we experience when performing a task and task loading indicates the accumulation of tasks necessary to perform a specific operation. I first learned about task loading as a scuba diver, but it’s also common — along with the subsequent distraction and stress it causes — during security and privacy incidents. ## **Impact of Task Loading** Human beings have a limited cognitive capacity, meaning our perceptual systems (those that process information from the five senses: vision, hearing, smell, taste, and touch) and our neuropsychological processes of attention can only do so much at the same time. New and unfamiliar tasks require a significant amount of this capacity with skills requiring conscious thought and laborious execution. As tasks become more familiar, they require less conscious attention and the associated skills become embedded in memory. Therefore, the more familiar a skill is, the less cognitive capacity it requires. In addition to taking up cognitive capacity, new situations and tasks increase activation of [affect systems](https://en.wikipedia.org/wiki/Affect%5F%28psychology%29?ref=discernibleinc.com), triggering strong emotional responses, such as excitement, fear, and anxiety. A little activation is helpful in stimulating us to action, but higher levels inhibit thinking and reduce our cognitive capacity. In new tasks or environments the demands on our cognitive capacity mean that our ability to attend to all elements of a situation is limited. Excessive task loading can also lead to failure with even simple or familiar tasks as we reach the limits of our cognitive capacity. It’s not uncommon for individuals to enter a cycle of [perception narrowing](https://medium.com/discernible/rescue-diving-and-the-psychology-of-security-privacy-incidents-5a8a264b8a84?ref=discernibleinc.com), focusing exclusively on one perceived problem or task to the detriment of the overall situation. ## **Incident Response Planning** Almost every aspect of incident response includes multiple tasks from the moment an investigation begins. As a result, some task loading is inevitable. However, we should try to limit task loading to an individual’s level of training and experience. In diving, more experienced divers with advanced certifications are expected to look out for the entire group and assess the surrounding environment in detail, while new divers are instructed to focus on critical and immediate tasks like equalizing their ears and maintaining good buoyancy. In incident response, individuals unfamiliar with the subject matter or response procedures may have situational awareness limited to themselves and their job function. They might miss important aspects of the situation, such as how all the elements relate to each other or how a specific incident fits within the context of company history, industry trends, attack campaign, or public perception. Understanding that members of our security and privacy teams, as well as cross-functional partners, have varying levels of experience with incident response, it’s important to proactively consider how you’ll reduce the effects of task loading during an incident. ## **Make it Routine** New situations overwhelm our senses with new information, forcing our brains to work hard to sort out what to do with it. At the same time, our perceptual systems are trying to respond with more difficult, conscious understanding like assigning words to new things we haven’t seen before. All of this takes up cognitive capacity. A clear procedure helps individuals and organizations address a situation by completing tasks that are most essential first. By practicing the procedure, it becomes habitual and automatic, which reduces the demand for cognitive resources and helps reduce delays due to uncertainty about what to deal with first. This is a core aspect of nearly every incident response plan I’ve seen — — but most of them still fail to address task loading because they’re not aligned with day-to-day operations. The more distinct your incident response plan is from the way your team works everyday, the harder it will be for those procedures to become habitual and automatic. Rather than approach incident response planning and practice as an infrequent occurrence, a better approach is to consider it from the perspective of a cognitive behavioral chain. As a cognitive behavioral chain, alternative routes exist at every step or stage of an incident. Selecting the most appropriate ones is a skill and the more you do it, the better off you’ll be, both in terms of your competency with individual tasks and reducing the impacts of task loading. Because of this relationship between frequency and habituation, the best incident response plans mimic everyday operations up to the point of escalation, and then adopt existing procedures and protocols from across the company. For example, many companies have cross-functional response procedures for major outages, physical safety threats, and other non-security incidents. Aligning with procedures already familiar to cross-functional partners helps them reduce excessive task loading caused by a new and foreign process. Over time, as tasks and environments become familiar they require less of our cognitive capacity and are less stimulating to affect systems. Proactively planning for task loading in our incident response gives us more cognitive capacity to take in and make sense of more elements of the situation. ### Resilience is a Team Sport Chief Security Officers Must Learn How to Coach URL: https://www.discernibleinc.com/resilience-is-a-team-sport-chief-security-officers-must-learn-how-to-coach/ Last updated: 2026-06-25T18:38:32.000Z One of the most overlooked aspects of incident response is how the culture, communication, and resilience of security teams will change. I recall one instance when a PR exec expressed a concerning level of surprise upon learning that their company’s security team was struggling with low morale, high burnout, and feelings of betrayal following the public fumbling of a major incident disclosure. The PR team felt they’d achieved the best results possible given the situation, measuring success by the mere inclusion of the company’s statement in press stories and the speed at which journalists were willing to move on to new stories. They hadn’t considered how internal reactions to their PR campaign might impact the effectiveness of other teams could make or break another news cycle. The lingering consequences for the security team and the potential impact this would have for future incidents was considered inconsequential or simply neglected by company leadership. The security team was left behind while the rest of the company tried to forget anything ever happened. The crisis certainly didn’t automatically increase the level of influence or respect they experienced throughout the company — instead, they were abandoned to fend for themselves, care for their wounded, and on some days, simply hold it together. It was one of the most incomplete incident responses by a seemingly experienced “crisis communications” team I’ve ever observed and it cost the company dearly. Unlike the celebratory corporate response our product or marketing colleagues often receive following major sprints or releases, most of the attention security teams ever receive from their companies is in the context of an incident when they’re expected to save the company’s ass. The most stressful situations security teams endure on behalf of their employers are rarely recognized or rewarded by business leaders, let alone incite a company-wide town hall or creative new swag representing every new button in a mobile app. Unfortunately, it’s common for security teams to feel under appreciated and isolated from the rest of the company, especially when it’s not seen as core to the business (future posts will discuss how to position and communicate security as core to the business). In either case, security leaders would do well to consider a dedicated resiliency strategy for their organization so that individual incidents — or a series of incidents — don’t contribute a long tail of burnout, attrition, and mental health challenges. Security leaders know the true cost of an incident can’t be found in legal settlements or regulatory fines. There was a great [article](https://hbr.org/2021/01/the-secret-to-building-resilience?utm%5Fmedium=email&utm%5Fsource=newsletter%5Fweekly&utm%5Fcampaign=insider%5Factivesubs&utm%5Fcontent=signinnudge&deliveryName=DM117694) on resilience published by the Harvard Business Review in early January. Written by Rob Cross, Karen Dillon, and Danna Greenberg, it discussed new research that contradicts the conventional thinking that says, “resilience is something we find within ourselves only when we are tested — a kind of solitary internal “grit” that allows those of us who are strong to bounce back.” Instead, the authors found that “resilience is not purely an individual characteristic, but is also heavily enabled by strong relationships and networks.” The article presents a strong framework for identifying relational sources of resilience (below), which aligns with many of the areas Discernible counsels CSOs and team leads on building a resilient security organization. One of the reasons I advocate so forcefully for security communications as a proactive rather than reactive investment is to ensure security organizations have the relationships they and their team members need to rebound from setbacks. ![Sources of Resilience_HBR.png](https://images.squarespace-cdn.com/content/v1/5ec880e2357f2b58e114cd7a/1620160165762-ZK2S79GHH6PI3K9WTI3I/Sources+of+Resilience_HBR.png) Resilience for your team can be built and nurtured through these relationships by helping individuals shift demands, find meaningful purpose, or identify a path forward to overcome the challenges they face. As the authors note, these are the kinds of interactions that motivate us to persist because they function as a support system that can provide empathy and bolster our resilience by shifting perspective and reminding us we are not alone in the fight. “Resilience is not something we need to find deep down inside ourselves: we can actually become more resilient in the process of connecting with others in our most challenging times.” They counsel further that merely having a network of supporters isn’t sufficient, but in truly connecting with them when you need them most. Because it’s in the actual interactions and conversations themselves that “validate your plans, reframe your perspective on a situation, help you laugh and feel authentic with others, or just encourage you to get back up and try again because the battle is a worthy one — that we become resilient.” ## Strengthening Your Security Team’s Sources of Resilience Their research also showed that sources of resilience are not universally or equally important to everyone due to personal experiences, values, and context. In working with Discernible clients, I’ve found the same is true for security teams. The relationships security teams rely on to navigate day-to-day challenges often differ by company, leadership, industry, and organizational history. Understanding which sources are most important for your team provides a helpful guide in prioritizing the sources that will be most helpful during difficult times. These can include a number of connections such as a cross-functional team, an industry peer, an executive sponsor, or an advisor. They can be a professional association or informal community group, or simply a friend. As the authors note, diversity in another important element of resiliency. “Exposure to a diverse group of people allows us to learn different ways of managing, leading, and handling crises, and helps us develop different relational skills such as negotiating with various stakeholders. It also helps us cultivate empathy and perspective that we carry back into our work, among other benefits.” Keep a pulse on the sources of resilience for your team at any given time and invest in strengthening them by expanding existing relationships or initiating news ones. Remember these relational sources may change over time as team members, circumstances, or context change. ### Steering Clear of ‘Privacy Washing’ URL: https://www.discernibleinc.com/steering-clear-of-privacy-washing/ Last updated: 2026-06-25T18:35:34.000Z Danielle Citron and Daniel Solove recently [published](https://poseidon01.ssrn.com/delivery.php?ID=331005097121007067064006076106099090117046093006002049011113030091078006124069029002000030020015104116044126066029101001113001041026000040040124095022094004097088051054085086091070030124075114073095023090075103088019030124091006126090066107022113011&EXT=pdf&INDEX=TRUE&ref=discernibleinc.com) a fantastic roadmap for courts to understand different types of privacy harm and provided suggestions on when harm should be required in legal cases. I highly recommend it for anyone working in privacy today. Of course I read it, not as a lawyer, but as a communications advisor — and one who’s spent a great deal of time helping organizations understand how good privacy can be a proactive brand-building strategy rather than a defensive response. “Privacy harms are highly contextual,” write Citron and Solove, “with the harm depending upon how the data is used, what data is involved, and also how the data might be combined with other data. Sharing an innocuous piece of data with another company might provide a key link to other data or allow for certain inferences to be made.” This means the definition of harm can also vary in legal contexts, which the authors seek to clarify. Yet, while the law continues to progress with meaningful discourse such as this recent report, there is an area of privacy where further debate on definitions is morally irresponsible: privacy communications. Legal definitions or precedents do not define public expectations or trust. So, it should be clear to any communications professional responsible for privacy-related issues that there is no grey area when it comes to privacy. Messaging that claims privacy commitments, guarantees, or benefits without an acknowledgement and honest due diligence into potential arms is “privacy washing” — a form of manipulation designed to make people believe that an organization is doing more to protect privacy than it really is. In fact, where Citron and Solve state, as legal scholars that, “in many cases, harm should not be required because it is irrelevant to the purpose of the lawsuit,” the opposite is true in privacy communication strategies. The harm is exactly the point. Focusing on the legal consequences of privacy violations, Citron and Solove further explain: > *“When cases are dismissed due to the lack of harm, organizations engaging in wrongdoing escape without accountability. The message to other organizations is both clear and troubling — they can ignore privacy commitments enshrined in legislation and common law without concern.”* Based on my experience working with organizations before, during, and after major privacy violations, I agree completely with this sentiment. I’ve seen it happen. However, when it comes to public perception and organizational reputation, people have little patience to wait for clarifications from the court. Public judgment on your brand is immediate and not bound by legal opinion. You do not need to be found legally liable in order for privacy violations to destroy trust and erode reputations. The courts do not hold a monopoly on public accountability and often, they’re too late anyway. The reality behind all of this is that not being able to prove harm in court does not mean harm doesn’t exist. The mere perception of harm should matter a great deal to anyone with responsibility over an organization’s reputation. Speculation and rumors may not hold up in court, but they will haunt your brand for years. As I’ve written [before](https://medium.com/discernible/communication-gaps-in-security-privacy-b17f2b965387?ref=discernibleinc.com), it should always be our primary goal to prevent privacy violations from happening in the first place. But when accidental incidents occur, communications advisors need to be prepared with recommendations to: 1. Compensate those who have been harmed or believe they’ve been harmed 2. Secure assurances to prevent repeated incidents 3. Go beyond expectations to reinvest in public trust ## Types of Harm Caused by Privacy Violations Below are the 14 types of harm defined by Citron and Solove in their paper. It would be prudent for communications advisors to familiarize themselves with these concepts because regardless of their standing with a judge, they are very real to customers, politicians, partners, and employees. **Physical Harms:** “Entities handling personal data have been found liable for negligently, knowingly, or purposefully paving the way for a third party to physically injure someone.” **Economic Harms:** “Privacy violations can result in financial losses…Many privacy violations involve the loss of important opportunities rather than direct financial injuries.” **Reputational Harms:** “Reputational harms impair a person’s ability to maintain ‘personal esteem in the eyes of others’ and can taint a person’s image. They can result in lost business, employment, or social rejection.” **Emotional Harms:** “One of the most common types of harm caused by privacy violations is emotional distress. Emotional distress encompasses a wide range of emotions, including annoyance, frustration, anger, and various degrees of anxiety. The impact of emotional harm varies depending upon the emotion triggered. Fear can be among the most damaging emotions given its impact on people’s life choices…Privacy violations can cause emotional distress that can impede someone’s life as much as certain physical injuries.” **Relationship Harms:** “Privacy violations can harm personal and professional relationships as well as relationships with organizations. People modulate personal relationships by maintaining boundaries around their information or by withholding information from some people and not others…Relationship harms are two-fold: most immediately, the loss of confidentiality and in the longer term, damage to the trust that is essential for the relationship to continue.” **Chilling Effect Harms:** “Privacy violations can produce harm by inhibiting people from engaging in certain civil liberties such as free speech, political participation, religious activity, free association, freedom of belief, and freedom to explore ideas. Such harm is often called a ‘chilling effect…’ Chilling effects have an impact on individual speakers and society at large as they reduce the range of viewpoints expressed and the nature of expression that is shared.” **Discrimination Harms:** “Privacy violations can cause discrimination harms, which involve entrenching inequality and disadvantaging women and people from marginalized communities. Discrimination harms thwart people’s ability to have an equal chance to obtain and keep jobs, secure affordable insurance, find housing, and to pursue other crucial life opportunities. The misuse of personal data can be particularly costly to women, sexual minorities, and nonwhites given the prevalence of destructive stereotypes and the disproportionate surveillance of women and marginalized communities in their intimate lives.” **Thwarted Expectations Harms:** “A common type of privacy violation involves thwarting people’s privacy expectations by breaking promises made about the collection, use, and disclosure of personal data.” **Control Harms:** “Losing control over our personal data constitutes an injury to our peace of mind and our ability to manage risk. In the clutches of organizations, personal data can be used for a wide array of purposes for an indefinite period of time. Privacy laws seek to regulate data flows to protect individuals from potential downstream uses.” **Data Quality Harms:** “Many privacy laws require that organizations adhere to the principle of ‘data quality’ — keeping data accurate, complete, and up-to-date… It can be hard for individuals to find out about errors and when they do, third parties will ignore requests to correct them without the real risk of litigation costs.” **Informed Choice Harms:** “When individuals are not informed of their rights or not given important information, they are harmed because they lose their ability to assert their rights at the appropriate times, to respond effectively to issues involving their personal data, or to make meaningful decisions regarding the use of their data.” **Vulnerability Harms:** “…failing to follow security safeguards that have not yet resulted in a data breach.” **Disturbance Harms:** “Disturbance harms involve unwanted communications that disturb tranquility, interrupt activities, sap time, and otherwise serve as a nuisance.” **Autonomy Harms:** “Autonomy harms involve the restriction, coercion, or manipulation of people’s choices. People are either directly denied free will to decide or are tricked into thinking that they are freely making choices when they are not…Manipulation can affect not just individuals but also create societal harm, as people’s decisions can affect not just themselves but society as well.” ### Rescue Diving and the Psychology of Security & Privacy Incidents URL: https://www.discernibleinc.com/rescue-diving-and-the-psychology-of-security-privacy-incidents/ Last updated: 2026-07-01T18:14:12.000Z In scuba diving, the most common cause of emergencies is poor judgment. In my professional experience advising senior executives and technical teams, the same is true with regards to cybersecurity and privacy incidents. In both environments, the majority of issues are actually preventable and can be traced back to a poor decision that kicked off a series of events and culminated in trouble. One of the most critical skills in rescue diving is the ability to proactively and automatically assess situations, considering potential hazards and how to handle them. Poor judgment in identifying potential risks or how we respond to them sets the stage for emergencies — in diving, and in security and privacy. As I’ve said [before](https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups/), not every security or privacy incident results in a major breach or stems from a software vulnerability. Many start as an overlooked instance of poor judgment, like failing to account for potential abuses facilitated by your product or service, not treating account authentication systems as tier 1 services with your production engineers, or ignoring damaging rumors about your data practices. Every incident has the potential to grow infinitely worse in scope and impact as poor judgment snowballs from one bad decision to another depending on how an organization responds. From a communications perspective, it’s never wise to treat security and privacy as reactive-only. Waiting for bad things to happen is the definition of a communications team punching above their weight. Savvy communications, security, and privacy teams are in the weeds together every day, proactively assessing situations and how to handle potential hazards. To be clear, this does not mean every security and privacy team needs a public profile or publicity (reminder communications!=publicity), but it does mean that the folks you trust to make decisions during an emergency should be doing everything they can to prevent emergencies from happening in the first place. After more than a decade advising tech companies on security and privacy issues, I’ve found there are three primary symptoms of poor judgment — red flags that indicate an incident was either avoidable or made more severe by the response. ## Cutting Corners I find poor judgment difficult to forgive in situations where credible roadmaps and best practices exist. For example, I once reviewed a proposal for a controversial product based on a sample size of eleven users. Eleven. No consideration for representative demographics or use cases. Reliable and scientifically sound market research would take much longer and cost more money, so it was simply skipped and the product launched without adequate data to defend it. Tasked with explaining to external stakeholders how privacy was balanced against other considerations, the team’s cutting corners left me with one hand tied behind my back. As expected, the product did not land well with users and was justifiably criticized by privacy advocates around the world. It became a major PR issue for the company and stalled launch plans for the product in several markets. Yet, everyone from the product director and engineering leads to the PR and marketing teams involved contributed poor judgment to a series of decisions that started with “how do we decide what to build?” and led to a significant and costly (yet avoidable) hurdle for the business. Similar situations can arise when developers cut corners on code analysis or fail to close follow-up tasks from a previous incident. Communicators tend to hold their tough questions until it’s time to prepare for external engagement — but what if we asked them earlier, in the moments where we can influence and guide teams to develop better judgment? ## Insufficient Preparation The most effective responses result from teamwork and preparation. And although there are several reasons why proactive and ongoing preparedness is crucial, one of the most important aspects for me as a communications advisor is the benefit of giving team members something they can control. The human brain is not optimized to support complex cognitive function under duress, that’s why good response professionals are relentless about keeping their training fresh and relevant. By thinking about what may happen and how you need to respond, you’re mentally preparing to override the hindbrain’s natural “fight or flight” response. Good preparation increases the speed and efficiency with which we can handle an emergency, so making it a habit to constantly prepare is important. This is one reason why I advocate for a single incident response plan regardless of the scope or size of the incident — the more often you use the plan, the better you will be at executing it. There will always be things we can’t control about an incident, which leads to anxiety and even more poor judgment within an organization. Therefore, preparing for a good response includes giving team members something they can control to help reduce panic and enable them to use better judgment. ## Panic As a rescue diver, I immediately assess three key indicators to help estimate someone’s aptitude for avoiding panic: their training, their ability to acknowledge their limits, and their personal disposition. Important characteristics of an effective incident response — such as discipline, organization, and foresight — all depend on your ability to avoid panic. Once panic sets in, my attention must focus on protecting response procedures from thrashing and poor judgment. It’s not uncommon for me to ask someone in the war room (physical or virtual) to take a break and get their limbic system under control before continuing. Stress is a part of the job for incident response, but if we allow it to control our response, we risk perception narrowing (when an individual is unable to notice or deal with subtle aspects of a situation because they’re fixated on a single element). At depth, the effects of perception narrowing become far more serious for divers; and for security and privacy professionals, the potential damage of this narrowing increases with incident severity and external attention. As rescue divers, we also understand the importance of communicating to a victim or patient about what we’re doing to help as we proceed. So it’s not just about knowing how to escape immediate danger, but also how to maintain workable risk levels by keeping others calm and informed. A panicked diver — or a panicked executive — is a risk to themselves and everyone around them. ### The Socially Responsible Tech Company URL: https://www.discernibleinc.com/the-socially-responsible-tech-company/ Last updated: 2026-07-01T18:13:20.000Z Last week, [Ian Mitroff](https://www.linkedin.com/in/ACoAACEYXUMBH1IRumYwellIGvx6vdiRYhXee0o?ref=discernibleinc.com) and I joined [Gerald Harris](https://www.linkedin.com/in/ACoAAAH1H4YBrv%5FnGaM5xusjiVxQw0vmBqG-h8U?ref=discernibleinc.com) for a discussion on crisis management for the socially responsible tech company, hosted by [The Commonwealth Club of California](https://www.linkedin.com/in/ACoAAAjGluMBU9qgRYk%5FvVFc5IhUznq9x6kvius?ref=discernibleinc.com). I encourage you to watch the [full video](https://www.youtube.com/watch?v=P4Tza85P1jM&ref=discernibleinc.com) to hear all the insights shared during our 1-hour discussion, but the primary theme we covered was perverse incentives. Inside most tech companies, firefighting is glorified over fire prevention. This is particularly prevalent among product development and communications teams. Unfortunately, this also leads to incomplete regulatory responses. On the product side, we’ve allowed companies to become addicted to rapid-fire feature roadmaps, regardless of whether we truly understand their impact. Few product teams in tech conduct sufficient and honest research into a problem space before building a product they’ll market as a solution. Too often, press attention and publicly are misinterpreted as influence over sustainable business outcomes. They are not the same thing. Journalists covering tech need to push harder on companies to produce the market research and product testing behind their creations. Strong product development processes will aid companies in building trust and credibility. For others, exposing an emperor without clothes is the least reporters can do for consumers right now. For communications organizations — the people usually tasked with reputation management in our job descriptions — careers are still too often built on swooping in during a crisis instead of steering businesses away from disaster. Kicking the tires to uncover issues before a launch is met with hostility, in part because it rubs against the performance incentives of product teams. There is little or no reward for thinking longterm about how to establish effective checks and balances, ethical norms, or rigorous governance required for effective crisis management. As I’ve mentioned before, the practice of [crisis heroism](https://www.discernibleinc.com/the-origin-of-discernible/) in the communications profession can lead to serious problems for a company: > *It was obvious that very few communications teams were providing this level of support to the organizations inside their own company whose ongoing success was so critical to the operations, reputation, and stability of their business. They were simply waiting for something bad to happen so they could ship a statement and get promoted.* For regulators hell-bent on holding companies accountable for irresponsible behavior, don’t let up — but we also need someone to focus exclusively on outcomes for consumers. Punishing companies is not the same as protecting consumers and one without the other is insufficient for driving lasting change within the tech industry. Fortunately for companies, consumers, and regulators alike, the best approach to crisis management is also an effective path to social responsibility. However, the only way change happens is with someone inside the company with the backbone and authority to consistently call out behavior that falls short. ### What is a Security or Privacy Incident? Hiccups, F*ck Ups, and Give Ups URL: https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups/ Last updated: 2026-07-01T18:12:35.000Z One of the most common reasons organizations struggle with incident response communications is that their definition of an “incident” excludes most incidents. Too often incident response planning and execution only considers situations with legal disclosure obligations. It’s one reason why so many companies stumble with their public response, even if their technical response was exceptional. A proactive communications approach not only nurtures relationships you need to have before serious incidents occur, it also sharpens your thinking and helps prepare you for incidents down the road. While regularly scheduled tabletop exercises are helpful in [identifying](https://www.discernibleinc.com/communication-gaps-in-security-and-privacy/) weaknesses in process and procedure, it’s the constant engagement in everyday incidents that refine individual and team decision-making, exemplify your true principles, and establish context for the next incident. It’s rarely the major breaches that cause long-term impact on a brand’s reputation, especially compared to other kinds of potentially negative events for a company. The greatest damage is caused by the sleeping giants that don’t receive communications attention until it’s too late. High-frequency incidents have a greater potential to create a snowball effect in regards to public perception. Additionally, your public response to a seemingly simple issue is critiqued more than the original cause. Below, I’ve included a short summary of a few non-breach incidents where ongoing and proactive communications can help avoid or minimize damaging impact — or even create positive opportunities. The most effective security and privacy communications strategies cover all of this and more. ## **Hiccups** These are frequent, typically low-risk moments depending on failsafe and defense mechanisms, but if the technical or communications response is mismanaged, the situation can easily escalate to the level of a f\*uck up. On the other hand, if managed well, they can create proactive and positive opportunities to demonstrate transparency and engage in community knowledge exchange. **Outages:** including rumors of an outage 😑; Keep communications informed of any outages. I recommend adding them to production engineering’s alert distribution list. **Persistent Threats:** Being in the loop on botnets, phishing campaigns, credential stuffing, etc. enables you to answer stakeholder questions on the spot, identify underlying industry context, and engage with external partners to help mitigate quickly and effectively. **Routine Governance:** Privacy Impact Assessments (PIA), Product Review Documents (PRD), Internal Audit (IA), 3rd party audits, and M&A security assessments are all helpful in catching areas of concern *before* they cause an incident. The earlier in the process you can assert influence, the less effort it requires. You need this muscle memory for good proactive communications. ## **F\*ck Ups** Warranted or not, these incidents are *perceived* as both avoidable and the result of incompetence. You will probably apologize whether you’re at fault or not because it’s the right thing to do. A good outcome is protecting public trust in your ability to blow your nose unsupervised and sharing lessons learned to help others avoid similar mistakes. **Technical:** Bad product designs, broken configurations, security vulnerabilities (including vendor bugs you haven’t patched yet), etc. These all reflect poorly on engineering capabilities and organizational leadership. **Customer Support:** One time, I provided documentation to the head of Risk showing that the most frequent questions I received from journalists globally across all related security and privacy topics were about unauthorized service charges showing up on credit cards stolen from other service providers. Although the actual volume of fraud was at an all-time low, the poor quality response given to customers when they called for assistance caused a high percentage of these individuals to seek resolution from local TV news stations, which led to a growing misperception that we had a serious problem preventing fraud. Together, the head of Risk and I approached the head of Customer Service with some ideas — and resources to support them. **Public Statements & Representations:** Conference talks, blog posts, social media, press interviews, patent applications, etc. If someone is on your payroll, whatever inaccurate or idiotic thing they just said will be attributed to the organization and it’s now your problem. ## **Give Ups** This category of incidents results from intentional business decisions. It typically requires significant political capital and strategic influence to nudge the business on these issues, which is why ongoing proactive engagement is a way of life for effective communication advisors. **Data Practices:** Over-collection, surveillance, opaque third-party data-sharing, a lack of effective consumer choice or controls, burdensome processes for exercising data rights, etc. erode customer trust faster than any other types of incident I’ve seen — and it can take years to repair the damage. Communications advisors must ensure ignorance, arrogance, and inexperience are snuffed out of the decision-making process. **Culture & Policies:** - Assholes are never worth it. - Don’t let leadership off the hook with performative allyship. - Growth at all costs will cost you *everything.* **Business Priorities:** Business strategies and market environments can change quickly, and if your communications advisor isn’t clued in on future plans, they will have a hard time providing proper guidance on external engagements and internal operations. Retracted commitments and missed deadlines are good indicators that an organization’s right hand isn’t aware of what the left hand is promising. It’s even worse when one of those hands is also the mouth. 💥 ### Communication Gaps in Security and Privacy URL: https://www.discernibleinc.com/communication-gaps-in-security-and-privacy/ Last updated: 2026-07-01T18:11:53.000Z Communication strategies work a lot like compound interest — the longer you wait to invest, the less value you accumulate over time. For a security and privacy communications professional, the more time you can spend getting to know a team and their environment, the more insights you can provide them about potential risks and opportunities. You become attuned to their culture and sensitive to signals for concern. This is one of the reasons I advise security and privacy communications professionals to stay active in the technical community even if no one else in their communications organization engages with relevant communities. It’s also why I advise against communication strategies that only consider security or privacy once there’s a fire. The best incident preparedness efforts I’ve been part of helped avoid crises because we anticipated how something might play out long before it became an issue. ## Communication Ecosystem If you consider the most public aspect of most communications, media relations, as the spark for public dialogue (whether positive or negative), then the question is whether there is sufficient fuel and oxygen to actually ignite and sustain a fire (for better or worse). How you communicate, inside and outside your organization, on a daily basis determines how much fuel exists to ignite either a positive or negative spark. Your relationship with the broader community controls the supply of oxygen. In my experience, one of the most common causes of completely avoidable security and privacy crises is the lack of understanding this relationship between media, internal communications, and community engagement. You cannot effectively build, repair, or sustain influence over business strategy or your reputation in an industry without a deep understanding of these overlapping priorities. In fact, I’ve found no other factor as important to determining the full impact of an incident or opportunity, than an organization’s dexterity in navigating this chemical reaction. No communication effort happens in a vacuum. You are always compared to someone else in terms to technical capabilities, business readiness, ethics, and transparency. If you are not yet the industry standard by which others are measured, you better be prepared to outshine that benchmark in as many areas as you can before the spotlight shifts to you — — and as I mentioned [previously](https://www.discernibleinc.com/the-origin-of-discernible/), this approach requires communications professionals to dig deep with technical organizations and provide proactive counsel on an ongoing basis. ## Self-Inflicted Crisis Products you build specifically for security or privacy purposes are only half the battle. Your reputation and subsequent influence are also determined by data practices present across all products and services. Nowhere is this more visible perhaps than at companies boasting a lengthy list of “privacy settings” while enabling their business to exploit, manipulate, and obfuscate data practices from public view. More often, however, security and privacy teams simply lack the oversight and mechanisms to shape business outcomes outside their immediate purview. This is how even well-intentioned companies let things slip through the cracks — — products that mistakenly over collect user data, service integrations with inadequate or unchecked security configurations, overly-permissioned mobile apps — — all common symptoms for organizations where security and privacy are a priority for some teams, but not all teams. Companies (and government agencies) that claim these as priorities, must be able to demonstrate the authority of these functions to impact the business. Too often, this authority comes only in the aftermath of a damaging or embarrassing incident unless security and privacy teams proactively establish their influence in advance. Below are a few moments where proactively putting someone inside your process to exercise internal and external influence makes all the difference to avoid or minimize the impact of an incident. ## Product and Engineering Reviews Product managers and engineering leads are committed to their projects like Frankenstein to his monster, often with similar results. Simple tweaks can often make a big difference and save projects from becoming skeletons hidden in a closet or unnecessary risks for an organization, but only if someone is there to ask the right questions early and often. Don’t hold your breath for lawyers or compliance teams to do this, you need to think beyond legal requirements and consider the *perception* of your choices because once you launch, perception is all that matters. When I worked in-house, I insisted on sitting with the engineering teams rather than the communications organization because I knew where I needed credibility to be effective. When potentially controversial ideas arose, I asked the appropriate project lead to write a blog post about what they were considering and why. I provided them with a list of anticipated stakeholder questions that the blog post needed to address with complete honesty and technical evidence. I set the expectation that if the project advanced, the blog post would be published publicly under their name to ensure full transparency about any policy or design decisions. Even I was surprised by how effectively this technique put problematic projects to rest or led to a more thoughtful approach. Holding people accountable by name matters, but it only works if you’re inside the process. ## Incident Preparedness Don’t limit your focus to crisis response. Think about how you teach and support strong communication habits among your teams and cross-functional partners all the time. Do you consider relationship management as an ongoing action item after every tabletop exercise to ensure decisions can be made well *and quickly* by the right people informed with the necessary information? A simple way to build this capability is to follow the same communications response procedure for all security incidents whether it’s a bug bounty report, insider threat, or intrusion investigation. Identify which organizational relationships facilitate the outcomes you need and which ones put a wrinkle in the process. Then iron them out NOW. You may even discover that no one has the necessary authority or ownership of a critical function to get things done. If your security team can’t get simple bug bounty tickets closed by certain engineering teams or are unable to effectively enforce service-to-service authorization requirements on an ongoing basis, guess which teams will drag their feet during a serious incident? If your privacy team’s first attempt at relationship management with technical teams is the lead-up to a regulatory deadline, you will struggle to build momentum in time. Make friends *before* you need them. ## Organizational Resilience One of the most frequently overlooked aspects of security and privacy is the impact of intense uncertainty and high-stakes for the teams that respond, clean up, and rebuild in an industry of constant change. Whether it’s a security incident or a seemingly routine re-organization, the emotional labor required of security and privacy professionals is rarely considered by business leaders, corporate communications, or legal teams in their various “strategic” planning. Getting the facts straight, sharing lessons with the community, and acknowledging actions that help prevent further escalation matters a hell of a lot to the people who show up everyday to protect your assets and your customers. They are invested in your success and stick around to help knowing you’ll likely scapegoat them anyway. If you’re not already talking about mental health with your security and privacy teams, start now. Ideally, you’re also tackling incident preparedness with cross-functional teams so these individuals aren’t constantly tasked with swimming upstream against business inertia but in the absence of influence, at least give them adequate support and communications training so they can find fulfillment and emotional safety amidst the challenges. There are still too many security and privacy organizations, including in-house and vendors, who view communications as an eleventh hour mouthpiece to broadcast decisions after the fact. What a waste! Communications professionals have unique insights and expertise that can help you make better decisions to build influence and productive reputations for your team. Don’t wait until *you* think you need communications help — ask about the value they can contribute *now* and earn interest on your interest. ### The Origin of Discernible URL: https://www.discernibleinc.com/the-origin-of-discernible/ Last updated: 2026-07-01T18:10:30.000Z ## Confronting Crisis Heroism Our company logo features a hammerhead shark because that’s how I see specialized security communications: a tangible domain advantage developed through a long, painstaking evolution. That’s the story of Discernible. The earliest motivation for *Discernible* grew from the realization that both the infosec and communication professions suffer from a self-inflicted hero complex that often conflicts with the obligation to protect people and keep them safe. When we glorify firefighting instead of fire prevention, we end up with a lot more fires, but unfortunately in my experience, crises lead to more job promotions than strategic crisis avoidance. Moreover, I’m often disheartened by the prevalent apathy and inability of traditional communications approaches to help prevent security or privacy incidents by investing proper attention to how security teams communicate among themselves, other organizations at the company, and industry peers. Too often, an incoherent and reactive media statement is considered good enough by PR teams, especially those incentivized by crisis. They rarely have the interest or time to dig deep with security organizations and provide proactive counsel that could actually eliminate the need for a public statement. At the same time, security and privacy teams struggle to articulate their business value beyond incident response and compliance, which costs them influence inside and outside their companies. As a result, the world is now filled with too many hollow promises of security and privacy commitments from corporate and government organizations, while simultaneously denying a voice to the experts responsible for this work. I found tremendous success bringing these disciplines together in every position I held as a consultant and in-house advisor. By improving the way teams communicate with each other and their leadership, we built political clout for risk-focused teams, navigated change management challenges, and reduced the number of times PR needed to draft a public apology. Whenever I engaged with a new member of any security team, they would inevitably tell me how shocked they were at what we were able to accomplish together because they’d never had this kind of dedicated support from a communications advisor before. It was obvious that very few communications teams were providing this level of support to the organizations inside their own company whose ongoing success was so critical to the operations, reputation, and stability of their business. They were simply waiting for something bad to happen so they could ship a statement and get promoted. So I started Discernible to give more security and privacy teams a communications ally who isn’t eager for a crisis.