During an IT outage or cyber incident, communication matters as much as the fix. Here’s a simple SME incident comms plan: roles, updates, and customer messaging.
When something goes wrong — ransomware, email compromise, a major outage — most SMEs don’t struggle because nobody cares. They struggle because communication becomes chaotic. Staff don’t know what’s happening, leaders get pulled into chasing updates, and customers start hearing mixed messages. The technical fix might be underway, but the damage to trust comes from uncertainty and silence.
A simple incident communications plan prevents that. It doesn’t need to be a 40-page document. It needs clear ownership, a predictable update rhythm, and a few pre-agreed rules about what you say internally and externally.
Amazing Support is a multi-award-winning, Microsoft Partner and Cyber Essentials Plus certified provider supporting UK SMEs across London, Greater London and Manchester — and in practice, calm comms is one of the biggest differences between a “bad day” and a reputational incident.
In plain English: incident communications is the process for keeping staff, leadership, and customers informed during an IT issue — clearly, consistently, and without speculation.
The 5 elements of a strong SME incident comms plan
1) Name an incident lead (one voice)
One person owns decisions and messaging. Others support, but don’t freelance updates.
2) Define your audiences
Typically:
- staff (what to do right now)
- leadership (impact, decisions, risk)
- customers/partners (service impact, reassurance)
- suppliers/insurers (facts and timelines)
3) Set an update rhythm
Even if there’s no new progress, a predictable update reduces panic:
- “Next update at 11:30” beats “we’ll let you know”
4) Use a simple message structure
Every update should cover:
- what we know (facts only)
- what we’re doing next
- what you should do (clear actions)
- when you’ll hear again
5) Decide what you won’t say
Avoid:
- blame
- speculation
- technical detail that creates confusion
Focus on impact, actions, and reassurance.
Common mistakes
- too many people sending updates
- silence while the technical team works
- sharing unverified causes (“it’s ransomware” before you know)
- no customer message until customers complain
- no alternative comms plan if email is affected
FAQ
Should we tell customers immediately?
If there’s impact to service or data risk, early and honest communication usually protects trust. The key is to communicate facts and next steps, not guesses.
What if email is the thing that’s broken?
Have an alternative channel ready (Teams, SMS tree, phone, a status page, or a pre-agreed WhatsApp group for leadership only).
Get In Touch if you want a calm, repeatable incident comms plan that your team can actually follow under pressure, we can build it with you and test it in a tabletop exercise.