# Discernible Inc > Communication experts for cybersecurity and privacy teams. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [About](https://www.discernibleinc.com/about.md) - Most communications support for security and privacy teams arrives after something goes wrong. Melanie Ensign built Discernible to change that. Melanie spent two decades leading security and privacy communications inside some of the world's most scrutinized organizations, including Facebook, Uber,… - [Case Studies](https://www.discernibleinc.com/case-studies.md) - The organizational challenges security and privacy leaders face don't arrive in neat categories; they're tangled up in politics, timing, and institutional history that generic frameworks can't account for. Our case studies document the real work of how teams shifted their standing with executives,… - [Clients & Testimonials](https://www.discernibleinc.com/clients-testimonials.md) - Who We Work With Discernible works with security and privacy leaders at organizations where the stakes are high and the internal dynamics are complex — CISOs navigating board relationships, privacy officers managing regulatory pressure, and security teams working to build the organizational standin… - [Get in Touch](https://www.discernibleinc.com/contact.md) - If you're exploring whether Discernible is the right fit for your organization or your own leadership development, we'd love to hear from you. - [Weekly Incident Drills](https://www.discernibleinc.com/experience.md) - The Discernible Experience Most security professionals build technical instincts through years of hands-on work. Communication instincts don't develop the same way — unless you practice them intentionally. The Discernible Experience gives you weekly opportunities to practice the communication momen… - [Privacy Policy](https://www.discernibleinc.com/privacy.md) - Last Updated: July 7, 2026 We believe the way we operate should reflect the work we do helping security and privacy professionals build influence and trust. That means no creepy tracking and no unnecessary data collection. This Privacy Notice describes our data collection and use practices on the f… - [Services](https://www.discernibleinc.com/services.md) - Work With Us Security and privacy teams are technically excellent. The gap isn't knowledge — it's the organizational skills needed to compete for resources, earn executive and cross-functional trust, and earn political capital that you can spend when you need it. That's what we help you develop. Di… ## Posts - [Issue 64: Thought leadership vs punditry](https://www.discernibleinc.com/issue-64-thought-leadership-vs-punditry-why-power-and-status-arent-the-same-thing-when-it-comes-to-influence.md) - Why thought leadership often becomes punditry instead, and why power and status aren't the same thing when it comes to real influence. - [Why Your Content Strategy Isn't Building the Influence You Expected](https://www.discernibleinc.com/why-your-content-strategy-isnt-building-the-influence-you-expected.md) - Most security professionals want thought leadership results but are using punditry tactics. Here's why that strategy mismatch is the real reason your content isn't building influence. - [Discernible Debrief: 7.29.26](https://www.discernibleinc.com/discernible-debrief-7-29-26.md) - A vendor breach hits the news. Your company never used the vendor, but a customer wants proof within 24 hours. Practice defending a "not affected" position. - [Discernible Experience: The Wrong List](https://www.discernibleinc.com/discernible-experience-the-wrong-list.md) - A vendor breach hits the news. Your company never used the vendor — but a customer wants proof within 24 hours. Practice defending a "not affected" position. - [Discernible Debrief: 07.22.26](https://www.discernibleinc.com/discernible-debrief-07-22-26.md) - This week's scenario explores a public CVE + a live exploit + the difference between "affected" and "exposed." - [Discernible Experience: Dependency Window](https://www.discernibleinc.com/discernible-experience-dependency-window.md) - A public CVE, a live exploit, and 14 services flagged as affected. Step into the role of Application Security Engineer and scope what's actually exposed. - [Discernible Debrief: 07.15.26](https://www.discernibleinc.com/discernible-debrief-inside-this-weeks-ir-scenario-2.md) - This week's IR scenario: communicating when an extortion group's public deadline outruns what your investigation has actually confirmed. - [Discernible Experience: The Leak Site](https://www.discernibleinc.com/discernible-experience-the-leak-site.md) - An extortion group's leak site claims breach before the investigation confirms scope. This IR tabletop scenario trains precise, defensible communication under deadline pressure. - [Discernible Debrief: 07.09.26](https://www.discernibleinc.com/discernible-debrief-07-09-26.md) - A model suspension, a federal review, and a rumor racing ahead of the facts. This week's Discernible Experience scenario looks at holding the line on precision when speculation moves faster than truth. - [Discernible Experience: The Access Window](https://www.discernibleinc.com/july-8-the-access-window.md) - A newsletter debrief summarizing the Access Window scenario and the communication principles it illustrates for Discernible Experience subscribers. - [Discernible Experience: Quiet Hours](https://www.discernibleinc.com/discernible-experience-quiet-hours.md) - A newsletter debrief summarizing the Quiet Hours scenario and the communication principles it illustrates for Discernible Experience subscribers. - [Discernible Debrief: 07.01.26](https://www.discernibleinc.com/quiet-hours-last-weeks-discernible-experience-scenario.md) - When no law compels you to act, what you choose to do reveals what your values are actually worth. Our most recent scenario is about a public safety tech company navigating a privacy violation with no breach, no notification requirement, and no easy answers. - [Don't Let AI Write Your Public Post-Mortem](https://www.discernibleinc.com/dont-let-ai-write-your-public-post-mortem.md) - AI-generated incident post-mortems recycle the same bad patterns of poor structure, too much noise, and buried ledes. Here's why you shouldn't let AI write yours, and a better prompt for teams without communications support. - [A Wishlist Is Not a Recommendation](https://www.discernibleinc.com/a-wishlist-is-not-a-recommendation.md) - Security teams that hand business leaders undifferentiated wishlists are offloading prioritization to people less equipped to do it. This post breaks down why these lists fail, what a real recommendation requires, and how reactive security comms holds organizations back. - [You’re Allowed to Ask for Help With This](https://www.discernibleinc.com/youre-allowed-to-ask-for-help-with-this.md) - CISOs navigating incidents, scrutiny, inherited dysfunction, or burnout are often better at absorbing hard experiences than asking for the right help. The framing you use determines the support you can receive -- and naming what you're actually experiencing is the critical first step. - [📬 Mailbag: We know people don't believe us when we say security is our top priority. How can we be more authentic in our communications?](https://www.discernibleinc.com/mailbag-we-know-people-dont-believe-us-when-we-say-security-is-our-top-priority-how-can-we-be-more-authentic-in-our-communications.md) - Authenticity in security comms isn't about perfect words, but consistent patterns over time. Only communicating when legally required gives stakeholders no baseline for trust. Credibility during incidents is earned through regular communication during normal operations. - [The Threshold Moves With Practice](https://www.discernibleinc.com/the-threshold-moves-with-practice.md) - Effective IR comms is built through consistent low-level stress exposure before crises arrive. The same neurological principle that makes experienced cave divers capable under pressure applies directly to security teams. Use small incidents to move the threshold. - [Embracing Morbid Curiosity: What Horror Fans Can Teach Us About Incident Response](https://www.discernibleinc.com/embracing-morbid-curiosity-what-horror-fans-can-teach-us-about-incident-response.md) - Horror fans showed greater psychological resilience during COVID because they practiced emotional regulation through scary scenarios. Security teams can apply the same principle -- frequent, varied incident comms drills build resilience by simulating crises in psychologically safe environments. - [The Privacy Professional's Influence Starter Kit](https://www.discernibleinc.com/the-privacy-professionals-influence-starter-kit.md) - No one hands privacy professionals a roadmap for building business influence, but the research and frameworks exist. This starter kit offers curated resources on negotiation, persuasion, and coalition-building -- the skills that turn privacy expertise into business outcomes. - [Why Are CISOs Afraid of Power?](https://www.discernibleinc.com/why-are-cisos-afraid-of-power.md) - Some CISOs struggle to build influence despite technical expertise because no one trains them in coalition-building, executive engagement, or team empowerment. The CISO role is fundamentally political, yet many security leaders lack the frameworks to develop the organizational influence it requires. - [3 Counterproductive Communication Patterns Holding Back Security Researchers](https://www.discernibleinc.com/3-counterproductive-communication-patterns-holding-back-security-researchers.md) - Even technically brilliant researchers undermine bug bounty success through communication missteps that create adversarial relationships. Here are three common patterns that damage disclosure outcomes and how to avoid them. - [Why Security Communication Feels So Hard (And What to Do About It)](https://www.discernibleinc.com/why-security-communication-feels-so-hard-and-what-to-do-about-it.md) - 3:43 PMClaude responded: You've learned to speak the business language.You've learned to speak the business language, but your concerns still get deprioritized. The problem could be the structure of who gets heard. Muted group theory explains why, and what to do about it. - [Calling Technology Magic is Bad Communication](https://www.discernibleinc.com/calling-technology-magic-is-bad-communication.md) - Consent frameworks were were designed to protect companies, not users. Lisa LeVasseur of Internet Safety Labs breaks down the tobacco playbook still running in tech, and what security and privacy leaders can do differently. - [Messaging != Communication](https://www.discernibleinc.com/messaging-communication.md) - Most security teams mistake messaging for communication strategy. The difference shows up when your polished deck doesn't move budget, your template doesn't preserve trust, and your awareness campaign doesn't change behavior. Words are not a strategy. - [Why Your Incident Response Should Be Unique](https://www.discernibleinc.com/why-your-incident-response-should-be-unique.md) - Same incident. Three teams. Three completely different — and equally valid — communication strategies. That's not a bug in how we teach incident response. It's the whole lesson. Templates fail because they assume you're someone else. - [The Template Trap](https://www.discernibleinc.com/the-template-trap.md) - The organizations that communicate best during incidents built for it. Pre-established relationships, clear decision authority, and pre-negotiated boundaries. Authentic responses don't happen by accident. - [CISO as Super-Facilitator: Elevating Board and C-Suite Security Leadership](https://www.discernibleinc.com/ciso-as-super-facilitator-elevating-board-and-c-suite-security-leadership.md) - How do CISOs elevate board and executive security leadership instead of just reporting to them? Apply the 'super-facilitator' approach to transform your leadership team from audience into collaborators who drive organizational security strategy. - [When Ransomware Groups Target Executives: Lessons from Our Latest IR Scenario](https://www.discernibleinc.com/when-ransomware-groups-target-executives-lessons-from-our-latest-ir-scenario.md) - Ransomware hits different when executives are personally targeted. One Discernible Experience scenario pushed participants to practice three overlooked skills: advocating for specificity over legal vagueness, sharing threat intel with competitors, and supporting leaders under pressure. - [Beyond Translation: How CISOs Lead When the C-Suite Can’t Decide](https://www.discernibleinc.com/beyond-translation-how-cisos-lead-when-the-c-suite-cant-decide.md) - When the C-suite stalls on security decisions, accountability rolls downhill while strategic direction never flows down. Learn four communication theory-based strategies that help CISOs lead effectively despite organizational ambiguity and competing priorities. - [How to Market Privacy Without Falling Into the Privacy Washing Trap](https://www.discernibleinc.com/how-to-market-privacy-without-falling-into-the-privacy-washing-trap.md) - Consumers have gotten good at spotting privacy washing. "Your privacy is important to us" doesn't land anymore. The brands building real credibility aren't making bigger promises — they're showing their work. - [The CISO's Guide to Making the Business Case: How Security Investments Drive Brand Performance](https://www.discernibleinc.com/the-cisos-guide-to-making-the-business-case-how-security-investments-drive-brand-performance.md) - The 2025 Edelman Trust Barometer: brand trust now beats institutional trust by 13 points, and 84% of consumers rank trust alongside cost and quality. That's a CISO's business case for why security investment drives revenue. - [Privacy Needs a Better Story](https://www.discernibleinc.com/privacy-needs-a-better-story.md) - Privacy teams that lead with risk reduction and compliance are writing their own cost center narrative. Porter's value chain and communication framing theory offer a different approach: connect your work to operational efficiency, customer engagement, and competitive advantage. - [Trust Recovery Starts Before the Incident, Not After](https://www.discernibleinc.com/trust-recovery-starts-before-the-incident-not-after.md) - Trust recovery starts before the incident. Most organizations treat customers as outsiders to protect from technical details but your incident is also happening to them. Withholding context doesn't protect you and wastes the opportunity to demonstrate competency. - [Your Team's Communication Isn't Just What You Say – It's Who You Are: Understanding Constitutive Theory](https://www.discernibleinc.com/your-teams-communication-isnt-just-what-you-say-its-who-you-are-understanding-constitutive-theory.md) - Your communication constitutes your security program. The patterns your team uses shape culture, decision-making, and operational reality. Leaders who understand this build political capital faster and design programs that actually perform. - [How Organizations Sabotage Media Relations by Misunderstanding Security Communications](https://www.discernibleinc.com/how-organizations-sabotage-media-relations-by-misunderstanding-security-communications.md) - Security communications is more than media relations, but most organizations stop there. Journalists covering your incident are drawing on months of accumulated context including your customer support, executive messaging, and transparency record. All of it counts. - [Transparency Schmarency: Security Disclosures Should Be Honest and Helpful](https://www.discernibleinc.com/transparency-schmarency-security-disclosures-should-be-honest-and-helpful.md) - The organizations building real trust do more than meet legal minimums. They also give affected users what they need to protect themselves: clear impact assessments, immediate action steps, and information that actually matches their situation. - [Why Effective Security Communication Starts with Strategy, Not Translations](https://www.discernibleinc.com/why-effective-security-communication-starts-with-strategy-not-translations.md) - Converting technical jargon into business language is just the first step and doesn't drive decisions alone. Effective security communication starts with the outcome you need and works backward through what your audience believes, assumes, and has experienced. - [Four Ways Exceptional Incident Response Creates Competitive Advantage](https://www.discernibleinc.com/four-ways-exceptional-incident-response-creates-competitive-advantage.md) - Incidents handled well create advantage. Four insights from a recent Discernible Experience drill on what separates organizations that earn trust under pressure from those that just survive it. - [A Communicator's Guide to Software Harm Prevention](https://www.discernibleinc.com/a-communicators-guide-to-software-harm-prevention.md) - Comms professionals need to be in the room before products ship — evaluating algorithmic bias, AI misuse potential, and data practices before they become headlines. - [What Could Go Right?](https://www.discernibleinc.com/what-could-go-right.md) - "What could go wrong?" is a defensive posture that caps your influence. The security teams building real political capital ask a different question: what could go right? Reverse engineer that outcome, and incident response stops being damage control and starts being strategy. - [Organizations Lack Sufficient Decision Frameworks to Expand Incident Response Options](https://www.discernibleinc.com/organizations-lack-sufficient-decision-frameworks-to-expand-incident-response-options.md) - The security leaders with the most options during an incident built them long before it happened using consistent, values-based decision frameworks as relationship tools. Communication strategy shapes how your organization decides, not just how it explains. - [📬 Mailbag: What's the best approach for sharing vulnerability findings with developers to avoid inciting defensiveness?](https://www.discernibleinc.com/mailbag-whats-the-best-approach-for-sharing-vulnerability-findings-with-developers-to-avoid-inciting-defensiveness.md) - Vulnerability findings land differently depending on how you deliver them. Security professionals who understand framing and loss aversion can create conditions where dev teams want to fix them. Same finding, with a completely different outcome. - [Boost Your Team's Influence with Corporate Anthropology](https://www.discernibleinc.com/boost-your-teams-influence-with-corporate-anthropology.md) - Your organization has a culture and your security program either works with it or against it. Corporate anthropology gives you a framework for mapping that culture, building the right relationships, and crafting narratives that make security feel essential. - [Breaking Down Barriers: Insights from Our Recent Bug Bounty Communications Scenario](https://www.discernibleinc.com/breaking-down-barriers-insights-from-our-recent-bug-bounty-communications-scenario.md) - Friction between security researchers and internal teams is usually an information problem, not a people problem. Closing the gap takes three things: better documentation, charitable assumptions, and effective communication channels. - [Decisive Under Fire](https://www.discernibleinc.com/decisive-under-fire.md) - Why do decision frameworks outperform templates for managing security incident communications? Because they empower internal stakeholders with the right expertise to make critical communication decisions under pressure. - [Beyond Breach Response](https://www.discernibleinc.com/beyond-breach-response.md) - Privacy incidents usually start with misalignment long before a breach. A Discernible Experience drill on privacy incident response explored how much damage happens when security, legal, and product aren't on the same page from the get go. - [Sharks in Engineering Waters](https://www.discernibleinc.com/sharks-in-engineering-waters.md) - Healthy organizations have disagreement and research shows engineering teams that nurture productive conflict outperform those that avoid it — better solutions & more innovation. Visible friction isn't a warning sign, but proof of psychological safety. - [5 Communication Assets to Build Before Your Next Security Incident](https://www.discernibleinc.com/5-communication-assets-to-build-before-your-next-security-incident.md) - Effective incident response requires proactive communication assets built in advance. Here are 5 foundational elements to streamline communications, enable nimble responses, and demonstrate your security team's ability to overcome complex challenges. - [CISO Communication Playbook](https://www.discernibleinc.com/ciso-communication-playbook.md) - Technical controls and human behavior are two sides of the same security coin. CISOs who master both domains build more resilient security programs that withstand evolving threats and organizational pressures alike. - [CUSTOMER CASE STUDY: Building CISO Resilience with Strategic Communications](https://www.discernibleinc.com/customer-case-study-building-ciso-resilience-with-strategic-communications.md) - Specialized communications coaching from Discernible helped CISO Amy Bogac navigate career transitions, strengthen reputation management skills, and build a stronger executive presence. - [When Less Is More: The Argument Dilution Effect](https://www.discernibleinc.com/when-less-is-more-the-argument-dilution-effect.md) - CISOs facing skeptical boards can learn from this landmark example of the "argument dilution effect," where adding weaker points to strong ones doesn't strengthen your case — it fundamentally weakens it. - [Introducing Discernible Experience: The Power of Persistent Practice](https://www.discernibleinc.com/introducing-discernible-experience-the-power-of-persistent-practice.md) - The Discernible Experience runs realistic communication simulations where security professionals from different organizations practice together. Same scenario, different perspectives — that's the point. You'll face challenges internal training never surfaces. - [The Myth of Shared Responsibility](https://www.discernibleinc.com/the-myth-of-shared-responsibility.md) - The uncomfortable truth is that "shared responsibility" is a myth that allows organizations to talk about security without making consequential changes to incentives and accountability structures. - [How Data Ethics Makes Incident Response More Effective](https://www.discernibleinc.com/how-data-ethics-makes-incident-response-more-effective.md) - Strong ethical data practices can enhance an organization's ability to respond effectively to security and privacy incidents. - [📬 Mailbag: What are the elements of a successful post-mortem?](https://www.discernibleinc.com/mailbag-what-are-the-elements-of-a-successful-post-mortem.md) - How do leading incident response teams transform post-mortems from technical reviews into engines of organizational change by focusing on cultural integration, behavioral psychology, and systemic patterns rather than just root cause analysis? - [Beyond Damage Control: The Science Behind Apologies](https://www.discernibleinc.com/beyond-damage-control-the-science-behind-apologies.md) - A shift in mindset – from defending organizational pride to rebuilding stakeholder trust – can help guide more effective incident response. - [Meeting the Moment: The Art of Apologizing After a Cybersecurity Incident](https://www.discernibleinc.com/meeting-the-moment-the-art-of-apologizing-after-a-cybersecurity-incident.md) - While the road to recovery from a security incident can be long and rocky, one part of the process is pretty simple: apologizing. At least it should be. - [CUSTOMER CASE STUDY: Cisco Secure](https://www.discernibleinc.com/customer-case-study-cisco-secure.md) - Discernible was brought in to provide strategic communications analysis, training, and professional development for Cisco Secure’s then new and expanding leadership team. - [Maintaining Composure: Effective Emotional Regulation in Security Incident Response](https://www.discernibleinc.com/maintaining-composure-effective-emotional-regulation-in-security-incident-response.md) - The ability to remain calm and composed during an incident response is critical to a successful recovery. Written plans and procedures are great, but execution is the hardest part because human emotions can get the better of security teams and their partners across the business. - [Empowering Business Leaders to be Savable Victims: Drawing Incident Response Insights from Rescue Scuba Diving](https://www.discernibleinc.com/empowering-business-leaders-to-be-savable-victims-drawing-incident-response-insights-from-rescue-scuba-diving.md) - Discernible helps security and privacy organizations build communication capabilities and political capital before crises happen, shifting teams from reactive explainers to proactive influence-builders. - [📬 Mailbag: How do you regain trust after an initial communications misstep?](https://www.discernibleinc.com/mailbag-how-do-you-regain-trust-after-an-initial-communications-misstep.md) - Whether it's a poorly timed announcement, an ill-considered tweet, or a misinterpreted internal message, the key to recovery lies in how you handle the aftermath. Here are a few recommendations on how to navigate your way back from a communications misstep. - [Building Trust Between Security and its Peers](https://www.discernibleinc.com/building-trust-between-security-and-its-peers.md) - Dr. Ryan K. Louie and Kim Burton join Discernible CEO Melanie Ensign for a discussion on how security teams can develop deeper trust with their partners in the business. - [Is Your Security or Engineering Team ready for a Chief of Staff?](https://www.discernibleinc.com/is-your-security-or-engineering-team-ready-for-a-chief-of-staff.md) - Advice from a CISO Chief of Staff on how to know when the time is right to hire a Chief of Staff and how to find the right one for your team. - [Why No One Listens to Cassandra](https://www.discernibleinc.com/why-no-one-listens-to-cassandra.md) - The widely misunderstood curse of Cassandra didn’t impact other people’s ability to understand each other. It changed how Cassandra communicated, burying the meaning of her advice in vague and opaque language. - [📬 Mailbag: Where should security communications be on the organization chart?](https://www.discernibleinc.com/mailbag-where-should-security-communications-be-on-the-organization-chart.md) - A reader asks: Where should security communications be on the organization chart? - [Powerful Expectations: Effective Communications for Bug Bounty Programs](https://www.discernibleinc.com/powerful-expectations-effective-communications-for-bug-bounty-programs.md) - Q&A with Reginaldo Silva, security researcher and former security engineer at Facebook/Instagram - [Takeaways from 2023 - and Resolutions for 2024](https://www.discernibleinc.com/takeaways-from-2023-and-resolutions-for-2024.md) - Here are three security communication patterns I observed the most often in 2023 and why you should resolve to address them in 2024. - [📬 Mailbag: How do you manage/balance truthful communications about an incident/breach while mitigating legal exposure?](https://www.discernibleinc.com/mailbag-how-do-you-manage-balance-truthful-communications-about-an-incident-breach-while-mitigating-legal-exposure.md) - A reader asks: How do you manage truthful communications about an incident while mitigating legal exposure? - [“The solution is not buying another server, it’s having better communications.”](https://www.discernibleinc.com/the-solution-is-not-buying-another-server-its-having-better-communications.md) - Q&A with DEF CON founder and CEO Jeff Moss on the value of security communications. - [📬 Mailbag: Are there any examples of good incident response communications?](https://www.discernibleinc.com/mailbag-are-there-any-examples-of-good-incident-response-communications.md) - A reader asks: Are there any examples of good security incident communications? - [CUSTOMER CASE STUDY: Twilio](https://www.discernibleinc.com/customer-case-study-twilio.md) - Discernible was brought in by Twilio’s CISO to design a creative and easily deployable solution to entice people from across the security organization to speak, blog, and generally share the good work the teams were doing and engage more deeply with their cohort outside the company. - [A CISOs right hand on how security communications can build credibility across the organization](https://www.discernibleinc.com/a-cisos-right-hand-on-how-security-communications-can-build-credibility-across-the-organization.md) - Jessica Walters is Senior Security & IT Program Manager at Tessian, and former Chief of Staff to the CISO of Cisco’s Security Business Group. In this Q&A, she shares her perspective on how to use security communications proactively in building an effective security team. - [How Security Communications Gives Recruiting an Edge](https://www.discernibleinc.com/how-security-communications-gives-recruiting-an-edge.md) - Lauren Bryant has worked as a senior technical recruiter at Uber, Paypal, Lime, and more. Here, she discusses the critical relationship between recruiting and communications teams when it comes to hiring the best and brightest in cybersecurity and technology today. - [Not Just Security: CISOs are Business Executives](https://www.discernibleinc.com/not-just-security-cisos-are-business-executives.md) - New research shows effective communication strategy and execution is critical for CISOs to earn and maintain legitimacy with the business. - [Every Security Decision is a Business Decision. Communicate Accordingly.](https://www.discernibleinc.com/every-security-decision-is-a-business-decision-communicate-accordingly.md) - Glenn Thorpe is the Sr. Director of Security Research and Detection Engineering at GreyNoise and a Discernible Advisor. In this Q and A, Glenn shares his insights into why understanding business and how to communicate effectively is critical for anyone working in cybersecurity today. - [Keep Calm and Plan On: Expert Advice on Incident Response Communications](https://www.discernibleinc.com/keep-calm-and-plan-on-expert-advice-on-incident-response-communications.md) - In this Q&A with Brooke Pearson, we discuss the relationship between internal and external communications as part of a comprehensive incident response program. Brooke is the former head of security awareness at Uber and a Discernible advisory board member. - [Words with Impact: Communication Tips for Privacy Technologists](https://www.discernibleinc.com/words-with-impact-communication-tips-for-privacy-technologists.md) - An interview with Discernible CEO Melanie Ensign and the Shifting Privacy Left Podcast. - [Turning Incident Response Communications into a Sustainable Security Communications Program](https://www.discernibleinc.com/turning-incident-response-communications-into-a-sustainable-security-communications-program.md) - The best incident response communications are built on a foundation of strong, ongoing security communications. Here are a few thoughts on how to do that. - [Communication Measurement and AI](https://www.discernibleinc.com/communication-measurement-and-ai.md) - AI makes outcomes-based measurement even more practical. Imagine tracking the real impact of specific content, language, and timing in incident response communications — not just counting outputs, but understanding what actually moved stakeholders. That capability is closer than most teams realize. - [CUSTOMER CASE STUDY: Trail of Bits](https://www.discernibleinc.com/customer-case-study-trail-of-bits.md) - “I noticed that Melanie has a rare ability to speak in headlines and get right to the point in a compelling way [and] I wanted to learn how to do that.” - [Communication Research Takes on the Myths of Privacy Compliance](https://www.discernibleinc.com/communication-research-takes-on-the-myths-of-privacy-compliance.md) - Trust requires understanding, so if people don't know how their data is used, what rights they have, or how to exercise them, your privacy program isn't building trust it's simply avoiding complaints. Measure your communications and adjust until no one feels duped. - [CUSTOMER CASE STUDY: Response Planning](https://www.discernibleinc.com/customer-case-study-incident-response-comms-plan.md) - The hallmark of Discernible’s approach is that incident response plans are designed to address a variety of security-related incidents regardless of severity or impact. - [A CISO’s Guide to “Negative Megaphoning”](https://www.discernibleinc.com/a-cisos-guide-to-negative-megaphoning.md) - Negative megaphoning doesn't just damage company reputation, but also signals to security talent what it's like to work there. CISOs who ignore employer reputation make hiring harder for their team. - [Scrub these Phrases from Your Data Breach Statements](https://www.discernibleinc.com/scrub-these-phrases-from-your-data-breach-statements.md) - Speed and accuracy are table stakes for incident response, but three common elements in public statements quietly undermine both — and most organizations don't catch them until the credibility damage is done. - [Don’t Get Stuck in Conflict: Communication Techniques for InfoSec and Privacy Teams](https://www.discernibleinc.com/dont-get-stuck-in-conflict-communication-techniques-for-infosec-and-privacy-teams.md) - Alignment isn't a prerequisite for progress. In fact, security and privacy professionals who influence engineering and product decisions don't wait for consensus — they learn to move work forward in the presence of disagreement. It's an invaluable communication skill. - [Knocking on the Boardroom Door](https://www.discernibleinc.com/knocking-on-the-boardroom-door.md) - Quarterly board presentations and executive updates check boxes. The CISOs who get resources and retain influence have solved a harder problem — not how to report on their program, but how to make their work visible in ways that actually matter. - [📬 Mailbag: How should brands talk about security threats from abroad without sounding xenophobic?](https://www.discernibleinc.com/mailbag-how-should-brands-talk-about-security-threats-from-abroad-without-sounding-xenophobic.md) - A reader asks, “How should brands talk about security threats from abroad without sounding xenophobic?” - [Words that Work: Persuasive Language for Security and Privacy Communications](https://www.discernibleinc.com/words-that-work-persuasive-language-for-security-and-privacy-communications.md) - Counting distribution and engagement tells you why you're busy. It doesn't tell you if your communications are working. Do you know which words actually land with your security and privacy audiences? There's only one way to find out — start measuring. - [Does Your Security Comms Strategy Need an Upgrade?](https://www.discernibleinc.com/does-your-security-comms-strategy-need-an-upgrade.md) - The best crisis communication strategy is the one you're doing when nothing's on fire. Consistent, routine security and privacy communications reduce both the frequency and impact of crises — because demonstrated care compounds before you ever need it. - [Beyond the Technical: Emotions and Negotiating in Security Leadership Roles](https://www.discernibleinc.com/beyond-the-technical-emotions-and-negotiating-in-security-leadership-roles.md) - Discussions about emotions come up a lot in our incident preparedness and response work with clients because we’re always thinking about how different stimuli impact people’s expectations and ability to communicate effectively. - [Self-Inflicted Pain and Artificial Adversity in InfoSec](https://www.discernibleinc.com/self-inflicted-pain-and-artificial-adversity-in-infosec.md) - The popular saying “what doesn’t kill you makes you stronger” isn’t a guarantee. Traumatic or stressful situations can still destroy trust and motivation, cause irreparable damage to our health, and push people out of the profession. - [If You Want a Seat at the Table, You Have to Earn It](https://www.discernibleinc.com/if-you-want-a-seat-at-the-table-you-have-to-earn-it.md) - Technical expertise gets you in the room, but it doesn't keep you there. Security and privacy professionals who earn lasting influence position themselves as business problem solvers fluent in competitive dynamics, not just compliance requirements. - [Risk Communications: Recognizing Turning Points and Managing Decisions](https://www.discernibleinc.com/risk-communications-recognizing-turning-points-and-managing-decisions.md) - Not communicating about security until it escalates into a crisis is a self-fulfilling prophecy. Instead, security communicators should constantly be on the lookout for critical turning points that can determine the direction of the organization’s future or cost them their reputation. - [Third Party Security Incident Response: Communicating Even When You’re Not Exposed](https://www.discernibleinc.com/third-party-security-incident-response-communicating-even-when-youre-not-exposed.md) - Why you should communicate with stakeholders about 3rd party security incidents even if you’re not exposed. - [Risk Communications: An Introduction](https://www.discernibleinc.com/risk-communications-an-introduction.md) - Security is about more than managing risk. It's also about helping non-experts make decisions with it. That's risk communication — and whether you've studied it or not, you're already doing it. The question is whether you're doing it well. - [Privacy Outrage: How to Avoid it When You Can and Mitigate it When You Can’t](https://www.discernibleinc.com/privacy-outrage-how-to-avoid-it-when-you-can-and-mitigate-it-when-you-cant.md) - Organizations don't stumble into privacy crises — they build them. Audit every new product and feature before launch: What data are you collecting? Who gets it? What did you promise users? If you can't answer those questions clearly, neither can your customers. - [This Year’s Strategic Relationships: Do You Have What You Need?](https://www.discernibleinc.com/this-years-strategic-relationships-do-you-have-what-you-need.md) - Most of us spent months planning this year's objectives. Fewer stopped to ask whose support, approval, or adoption do we actually need to get there? - [The Rise of Privacy Tech: Defining the Privacy Tech Landscape 2021](https://www.discernibleinc.com/the-rise-of-privacy-tech-defining-the-privacy-tech-landscape-2021.md) - Privacy tech companies blur together with generic alphabet-soup marketing that obscures what their products actually do. Standing out means understanding privacy as cross-functional, engaging the community, and solving real pain points; not just selling compliance fear. - [Exercising Influence as the Security Team: Look for Friction Not Just Fuel](https://www.discernibleinc.com/exercising-influence-as-the-security-team-look-for-friction-not-just-fuel.md) - Sometimes in security, we try to win people over by pushing harder, missing the friction that prevents them from exercising the behavior or decisions we need. - [The Communication Theory of Resilience: 5 Tips for Security & Privacy Organizations](https://www.discernibleinc.com/the-communication-theory-of-resilience-5-tips-for-security-privacy-organizations.md) - The Communication Theory of Resilience gives security and privacy teams strategies to build collective strength through communication instead of individual grit. Forward-looking orgs develop these processes before crises hit, because building infrastructure during incidents is always harder. - [Sincere and Effective Apologies](https://www.discernibleinc.com/sincere-and-effective-apologies.md) - Effective apologies require surrendering power and control. Organizations must recognize forgiveness doesn't equal trust, stop expecting victims to act like harm never happened, and focus on accountability to begin rebuilding relationships. - [Metacommunication and Bug Bounty Programs](https://www.discernibleinc.com/metacommunication-and-bug-bounty-programs.md) - Bug bounty programs run on async text where unspoken cues make or break researcher relationships. Effective teams focus on outcomes over winning arguments, explain decisions without defensiveness, and invest in trust to maintain productive long-term partnerships. - [Measuring Communication Effectiveness in Security and Privacy - Research, Analysis, and Evaluation](https://www.discernibleinc.com/measuring-communication-effectiveness-in-security-and-privacy-research-analysis-and-evaluation.md) - Without effective communication, IR is sluggish, policies go unenforced, leaders make uninformed decrees, audits tank morale, and external confusion breeds mistrust. There's never been a better time for security and privacy leaders to upgrade their comms skills. - [Preparing for Task Loading During Incident Response](https://www.discernibleinc.com/preparing-for-task-loading-during-incident-response.md) - Proactively planning for task loading in our incident response gives us more cognitive capacity to take in and make sense of more elements of the situation. - [Resilience is a Team Sport Chief Security Officers Must Learn How to Coach](https://www.discernibleinc.com/resilience-is-a-team-sport-chief-security-officers-must-learn-how-to-coach.md) - One of the most overlooked aspects of incident response is how the culture, communication, and resilience of security teams will change. - [Steering Clear of ‘Privacy Washing’](https://www.discernibleinc.com/steering-clear-of-privacy-washing.md) - Privacy communications that claim commitments without acknowledging potential harms is privacy washing; a manipulation that erodes trust regardless of legal outcomes. Comms pros must understand privacy harms, because public perception operates independently of legal liability. - [Rescue Diving and the Psychology of Security & Privacy Incidents](https://www.discernibleinc.com/rescue-diving-and-the-psychology-of-security-privacy-incidents.md) - Like rescue diving, most security and privacy incidents stem from poor judgment, cutting corners, insufficient prep, and panic. Teams can prevent the majority of incidents by proactively assessing situations with communications professionals before they snowball. - [The Socially Responsible Tech Company](https://www.discernibleinc.com/the-socially-responsible-tech-company.md) - Tech's perverse incentives reward firefighting over prevention, rushing products out and keeping comms teams on standby for disasters. True social responsibility requires internal leaders with the backbone to challenge irresponsible decisions before they become crises. - [What is a Security or Privacy Incident? Hiccups, F*ck Ups, and Give Ups](https://www.discernibleinc.com/what-is-a-security-or-privacy-incident-hiccups-f-ck-ups-and-give-ups.md) - Most orgs only disclose what's legally required, ignoring everyday hiccups, avoidable mistakes, and routine apathy that cause more long-term damage than major breaches. Proactive comms across low-risk, high-frequency incidents builds muscle memory before real crises hit. - [Communication Gaps in Security and Privacy](https://www.discernibleinc.com/communication-gaps-in-security-and-privacy.md) - Security and privacy teams hit avoidable crises when they only call communications pros after incidents strike. Treat communication strategy like compound interest -- invest early in relationship-building, incident prep, and resilience before you need crisis management. - [The Origin of Discernible](https://www.discernibleinc.com/the-origin-of-discernible.md) - Discernible helps security and privacy teams build internal influence and communicate business value, shifting from reactive crisis management to proactive strategy that prevents incidents before they happen. ## Optional - [RSS Feed](https://www.discernibleinc.com/rss/) - [Sitemap](https://www.discernibleinc.com/sitemap.xml) - [Full content of pages and posts](https://www.discernibleinc.com/llms-full.txt)