Mailbag 📬 Mailbag: We know people don't believe us when we say security is our top priority. How can we be more authentic in our communications? Authenticity in security comms isn't about perfect words, but consistent patterns over time. Only communicating when legally required gives stakeholders no baseline for trust. Credibility during incidents is earned through regular communication during normal operations.
Mailbag 📬 Mailbag: What's the best approach for sharing vulnerability findings with developers to avoid inciting defensiveness? Vulnerability findings land differently depending on how you deliver them. Security professionals who understand framing and loss aversion can create conditions where dev teams want to fix them. Same finding, with a completely different outcome.
Mailbag 📬 Mailbag: What are the elements of a successful post-mortem? How do leading incident response teams transform post-mortems from technical reviews into engines of organizational change by focusing on cultural integration, behavioral psychology, and systemic patterns rather than just root cause analysis?
Mailbag 📬 Mailbag: How do you regain trust after an initial communications misstep? Whether it's a poorly timed announcement, an ill-considered tweet, or a misinterpreted internal message, the key to recovery lies in how you handle the aftermath. Here are a few recommendations on how to navigate your way back from a communications misstep.
Influence 📬 Mailbag: Where should security communications be on the organization chart? A reader asks: Where should security communications be on the organization chart?
Incident Response 📬 Mailbag: How do you manage/balance truthful communications about an incident/breach while mitigating legal exposure? A reader asks: How do you manage truthful communications about an incident while mitigating legal exposure?
Incident Response 📬 Mailbag: Are there any examples of good incident response communications? A reader asks: Are there any examples of good security incident communications?
Mailbag 📬 Mailbag: How should brands talk about security threats from abroad without sounding xenophobic? A reader asks, “How should brands talk about security threats from abroad without sounding xenophobic?”