Skip to main content

How to Manage Stakeholder Communications During an Operational Resilience Incident

This guide sets out how to run regulator, investor, and customer communications when an operational incident is unfolding in real time. After reading, senior leaders will know how to sequence disclosures, coordinate messaging across audiences, and preserve credibility under pressure.

When a payments outage, cyber intrusion, or third-party failure hits, the technical recovery is only half the job. The other half is what you say, to whom, and when. Get communications wrong and you compound a contained incident into a trust event that outlasts the disruption by years.

Key Executive Takeaways

  • Regulator, investor, and customer communications must run on separate tracks with a single source of truth, or you will contradict yourself within hours.
  • Speed matters, but accuracy and consistency matter more: err toward brief, factual, timestamped updates over polished narratives you may later need to retract.
  • The tone regulators remember is candour under pressure, not the absence of problems, so surface what you do not yet know as clearly as what you do.

Start with a single incident narrative

Before anyone communicates externally, the crisis team needs one written account of what has happened, what is confirmed, what is suspected, and what is unknown. Every outbound message, to any audience, draws from this document. Assign one person, usually the Chief of Staff or a senior communications lead, to own it and version it. When the CFO briefs an analyst and the COO briefs the regulator two hours apart, they must be working from the same facts.

The most common failure here is letting each function draft its own version. Legal writes for regulators, IR writes for the market, operations writes for customers, and by day two the accounts diverge. Fix this at hour one.

Sequence the disclosures deliberately

Regulators generally come first, and rightly so. Under the FCA and PRA operational resilience rules, and equivalent regimes elsewhere, notification obligations are time-bound and specific. Know your thresholds cold before an incident, not during one. If the incident is material, notify early and update often. A short initial notification with a commitment to follow up within a defined window is almost always better than a delayed, comprehensive one.

Customer communications should follow quickly, especially where service is degraded or data may be affected. Silence is read as concealment. A plain factual holding statement, published on your status page and pushed through the channels customers already use, buys credibility.

Investor communications require judgement on materiality. If the incident is likely to be price-sensitive, disclosure obligations under MAR or equivalent regimes are triggered and IR must coordinate with Legal and the Company Secretary immediately. Do not brief analysts selectively.

Match the message to the audience

Regulators want to see that you understand what happened, that your controls are being tested honestly, and that you have a credible remediation path. They are not impressed by reassurance. They are impressed by clarity about root cause, customer impact, and governance response.

Customers want to know three things: is my money or data safe, when will service resume, and what should I do now. Answer those three questions in that order. Avoid corporate framing.

Investors want to understand financial impact, operational implications, and management competence. Do not speculate on cost until you can defend the number. Say what you are doing to quantify it.

What good looks like on day three

By day three, the pattern should be visible: regular timed updates to each audience, no contradictions between them, a designated executive owner for each channel, and a clear internal log of every external statement made. The board should be receiving a daily written brief, not just verbal updates. Front-line staff should have scripted responses that match public statements verbatim.

What most firms get wrong

They overpromise resolution timelines in the first 24 hours. They let the CEO make a definitive public statement before forensics have concluded. They treat regulator engagement as a compliance chore rather than a relationship. They forget that customer-facing staff, branch, call centre, relationship managers, are a communications channel and need briefing every few hours.

Your next decision

Before your next quarterly risk review, ask one question: if a severe but plausible incident struck this week, who owns the single incident narrative, and have they ever drafted one under time pressure? If the answer is unclear, run the exercise now, not after the event.

Frequently Asked Questions

How quickly should we notify the regulator?

As soon as you have enough confirmed facts to make a meaningful notification, and within any hard deadlines that apply. Waiting for complete information is a mistake. Regulators expect an initial notification followed by updates as understanding develops.

Should the CEO be the public face of the incident?

For material incidents affecting customers or markets, yes, at least for the primary statement. Delegating entirely to a communications director signals the incident is not being taken seriously at the top. But the CEO should speak from the incident narrative, not extemporise.

How do we handle media enquiries we cannot yet answer?

Acknowledge receipt, state what you can confirm, and commit to a follow-up time. Do not go off the record. Do not speculate. Silence and speculation both damage credibility.

When is it safe to declare the incident closed?

When service is fully restored, root cause is confirmed, customer remediation is under way, and the regulator has been given a written post-incident report. Declaring closure early, then reopening, is worse than a longer active phase.

Frequently asked questions

How quickly should we notify the regulator?

As soon as you have enough confirmed facts to make a meaningful notification, and within any hard deadlines that apply. Waiting for complete information is a mistake. Regulators expect an initial notification followed by updates as understanding develops.

Should the CEO be the public face of the incident?

For material incidents affecting customers or markets, yes, at least for the primary statement. Delegating entirely to a communications director signals the incident is not being taken seriously at the top. But the CEO should speak from the incident narrative, not extemporise.

How do we handle media enquiries we cannot yet answer?

Acknowledge receipt, state what you can confirm, and commit to a follow-up time. Do not go off the record. Do not speculate. Silence and speculation both damage credibility.

When is it safe to declare the incident closed?

When service is fully restored, root cause is confirmed, customer remediation is under way, and the regulator has been given a written post-incident report. Declaring closure early, then reopening, is worse than a longer active phase.

Related guides

Regulation & Regulatory Change

How to Run an ESG Materiality Assessment That Holds Up

A practical guide to designing and executing an ESG materiality assessment that satisfies CSRD double materiality expectations and stands up to auditor, regulator, and investor scrutiny. Readers will finish with a clear method for scoping, evidencing, and governing the exercise.

Regulatory submissionSustainability transitionRegulators
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Board Diversity Disclosure That Satisfies the FCA Without Inviting Activist Scrutiny

This guide sets out how to draft a Listing Rule 6.6.6R(9) and (10) diversity disclosure that meets FCA expectations while managing exposure to activist investors, proxy advisers, and campaign groups. After reading, you will know how to sequence the numerical disclosure, contextual narrative, and forward statements to satisfy regulators without creating avoidable hostages to fortune.

Regulatory submissionRegulatorsInvestors
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Pillar 3 Remuneration Disclosure for PRA and Proxy Scrutiny

A practical guide to drafting a Pillar 3 remuneration disclosure that satisfies PRA supervisors while surviving ISS, Glass Lewis and institutional investor challenge. Read this to understand how to sequence the narrative, reconcile the two audiences, and avoid the disclosures that most often trigger follow-up.

Regulatory submissionRegulatorsInvestors
4 min readRead guide →
Boards, Governance & Defensibility

How to Run an ESG Materiality Assessment That Holds Up

A step-by-step guide to running an ESG materiality assessment that withstands board, auditor, and regulator scrutiny - covering double materiality, stakeholder engagement, scoring, and common failure points.

Sustainability transitionRegulatorsInvestors
5 min read · Step by stepRead guide →
Boards, Governance & Defensibility

How Boards Demonstrate Real Accountability in Regulated Industries

A practical guide to what board accountability actually looks like in regulated sectors, beyond charters and attestations. Readers will finish with a clearer view of where accountability breaks down, and what to change to make it stick.

BoardsRegulatorsDecision defensibility
4 min readRead guide →

Where internal consensus may be mistaken for validation

Polar Insight's Decision Rooms bring outside challenge to a live decision, so blind spots and untested assumptions surface before commitment, not after.

Explore Decision Rooms