What to Say First During a Ransomware Incident

When a ransomware incident occurs, the first communication mistake often causes more damage than the malware itself.

Teams either say nothing while waiting for certainty, or say too much before facts are verified. Both create credibility risk. The goal of the first message is not resolution. It is control.

What the first message should do

A first ransomware holding statement should:

  • Acknowledge the situation without speculation

  • Confirm awareness and investigation

  • Establish authority and restraint

  • Prevent rumors from filling the vacuum

This message is often internal first, then external. Silence is rarely neutral.

Common mistakes in early ransomware communication

  • Waiting for technical confirmation before acknowledging impact

  • Letting Legal and Communications operate on separate timelines

  • Over-reassuring before verification

  • Issuing multiple uncoordinated internal messages

These errors usually stem from unclear decision authority, not lack of intent.

A practical approach

Organizations benefit from having a pre-built ransomware holding statement that can be quickly adapted once verification begins. This reduces delay, debate, and improvisation.

If leadership is already asking questions, the worst time to draft from scratch is during the incident.

Next step:
View crisis readiness tools designed for ransomware response and first-hour communication discipline.

Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations in Providence, Boston, Portsmouth, Portland, and Hartford, and across New England, nationally, and globally. mindthegapcyber.com

Share This