Incident Response Transparency Schmarency: Security Disclosures Should Be Honest and Helpful The organizations building real trust do more than meet legal minimums. They also give affected users what they need to protect themselves: clear impact assessments, immediate action steps, and information that actually matches their situation.
Influence Why Effective Security Communication Starts with Strategy, Not Translations Converting technical jargon into business language is just the first step and doesn't drive decisions alone. Effective security communication starts with the outcome you need and works backward through what your audience believes, assumes, and has experienced.
Incident Response Four Ways Exceptional Incident Response Creates Competitive Advantage Incidents handled well create advantage. Four insights from a recent Discernible Experience drill on what separates organizations that earn trust under pressure from those that just survive it.
Ethics A Communicator's Guide to Software Harm Prevention Comms professionals need to be in the room before products ship — evaluating algorithmic bias, AI misuse potential, and data practices before they become headlines.
Incident Response What Could Go Right? "What could go wrong?" is a defensive posture that caps your influence. The security teams building real political capital ask a different question: what could go right? Reverse engineer that outcome, and incident response stops being damage control and starts being strategy.
Company Updates Organizations Lack Sufficient Decision Frameworks to Expand Incident Response Options The security leaders with the most options during an incident built them long before it happened using consistent, values-based decision frameworks as relationship tools. Communication strategy shapes how your organization decides, not just how it explains.
Mailbag 📬 Mailbag: What's the best approach for sharing vulnerability findings with developers to avoid inciting defensiveness? Vulnerability findings land differently depending on how you deliver them. Security professionals who understand framing and loss aversion can create conditions where dev teams want to fix them. Same finding, with a completely different outcome.
Influence Boost Your Team's Influence with Corporate Anthropology Your organization has a culture and your security program either works with it or against it. Corporate anthropology gives you a framework for mapping that culture, building the right relationships, and crafting narratives that make security feel essential.
Bug Bounty Breaking Down Barriers: Insights from Our Recent Bug Bounty Communications Scenario Friction between security researchers and internal teams is usually an information problem, not a people problem. Closing the gap takes three things: better documentation, charitable assumptions, and effective communication channels.
Incident Response Decisive Under Fire Why do decision frameworks outperform templates for managing security incident communications? Because they empower internal stakeholders with the right expertise to make critical communication decisions under pressure.
Privacy Communication Beyond Breach Response Privacy incidents usually start with misalignment long before a breach. A Discernible Experience drill on privacy incident response explored how much damage happens when security, legal, and product aren't on the same page from the get go.
Organizational Communications Sharks in Engineering Waters Healthy organizations have disagreement and research shows engineering teams that nurture productive conflict outperform those that avoid it — better solutions & more innovation. Visible friction isn't a warning sign, but proof of psychological safety.
Incident Response 5 Communication Assets to Build Before Your Next Security Incident Effective incident response requires proactive communication assets built in advance. Here are 5 foundational elements to streamline communications, enable nimble responses, and demonstrate your security team's ability to overcome complex challenges.
Chief of Staff CISO Communication Playbook Technical controls and human behavior are two sides of the same security coin. CISOs who master both domains build more resilient security programs that withstand evolving threats and organizational pressures alike.
Case Study CUSTOMER CASE STUDY: Building CISO Resilience with Strategic Communications Specialized communications coaching from Discernible helped CISO Amy Bogac navigate career transitions, strengthen reputation management skills, and build a stronger executive presence.
Chief of Staff When Less Is More: The Argument Dilution Effect CISOs facing skeptical boards can learn from this landmark example of the "argument dilution effect," where adding weaker points to strong ones doesn't strengthen your case — it fundamentally weakens it.
Incident Response Introducing Discernible Experience: The Power of Persistent Practice The Discernible Experience runs realistic communication simulations where security professionals from different organizations practice together. Same scenario, different perspectives — that's the point. You'll face challenges internal training never surfaces.
Influence The Myth of Shared Responsibility The uncomfortable truth is that "shared responsibility" is a myth that allows organizations to talk about security without making consequential changes to incentives and accountability structures.
Ethics How Data Ethics Makes Incident Response More Effective Strong ethical data practices can enhance an organization's ability to respond effectively to security and privacy incidents.
Mailbag 📬 Mailbag: What are the elements of a successful post-mortem? How do leading incident response teams transform post-mortems from technical reviews into engines of organizational change by focusing on cultural integration, behavioral psychology, and systemic patterns rather than just root cause analysis?
Incident Response Beyond Damage Control: The Science Behind Apologies A shift in mindset – from defending organizational pride to rebuilding stakeholder trust – can help guide more effective incident response.
Guest Post Meeting the Moment: The Art of Apologizing After a Cybersecurity Incident While the road to recovery from a security incident can be long and rocky, one part of the process is pretty simple: apologizing. At least it should be.
Case Study CUSTOMER CASE STUDY: Cisco Secure Discernible was brought in to provide strategic communications analysis, training, and professional development for Cisco Secure’s then new and expanding leadership team.
Incident Response Maintaining Composure: Effective Emotional Regulation in Security Incident Response The ability to remain calm and composed during an incident response is critical to a successful recovery. Written plans and procedures are great, but execution is the hardest part because human emotions can get the better of security teams and their partners across the business.
Incident Response Empowering Business Leaders to be Savable Victims: Drawing Incident Response Insights from Rescue Scuba Diving Discernible helps security and privacy organizations build communication capabilities and political capital before crises happen, shifting teams from reactive explainers to proactive influence-builders.