Medical practices should consider details of a communications plan well in advance of a major incident, said Tom Bolitho, a crisis communications expert at FTI Consulting.
Proactive planning, transparency and consistency are key to effective communication during a cybercrisis, he said. Healthcare organizations must ensure that patients, regulators, employees and the public receive clear and factual information while dealing with cyber crises, while also avoiding premature conjecture, he said.
“One of the fundamental rules of communicating during a cybersecurity incident is making sure that you’re not getting out ahead of the facts, and that you’re demonstrating transparency while also not speculating and not providing information that is likely to change, or that is untrue,” he said in an interview with Information Security Media Group.
But above all, “putting patient care and patient focus at the middle is vital when communicating at the start of a cybersecurity incident,” he said.
In the interview (see audio link below photo), Bolitho also discusses:
- Best practices for communication before, during and after an cyber incident;
- Planning for and overcoming technology outages that hinder electronic communication during a cybercrisis;
- National security issues involving communications during critical infrastructure cyber incidents;
- Communicating with law enforcement, regulators and information sharing analysis centers and other similar external entities during a cyber crisis;
- Special communication considerations involving serious insider breaches.
Bolitho is a senior director in consulting firm FTI’s cybersecurity and data privacy communications team, based in Washington D.C. He has worked on numerous cyber incidents across healthcare, as well as multinational matters affecting high-profile consumer brands, and numerous cross sector matters across Europe and the U.S. Prior to joining FTI, Bolitho was a practice manager at Brunswick, responsible for the management and development of their cybersecurity practice group. Bolitho has a background in defense and security and previously served as British Army Officer.