Keeping Clients Informed During An Incident: One Story For Staff, Partners And Clients

keeping clients informed during an incident

When a consulting firm’s own systems are hit, it has two problems at once. The first is technical: contain the damage and get services back. The second is about people, because staff, the leadership team and every client with a live engagement all want to know what has happened.

Consider a UK management consultancy of around 1,200 people with 140 live client engagements. At 08:40 on a Tuesday, the security team finds ransomware in the document management system, where some client working files are stored. By 09:30 email and the document system are offline as a precaution. Three partners have already texted clients to say there is “a minor IT issue”, and a consultant at a retail bank is being asked by the bank’s CIO whether its data is safe.

The questions arrive faster than the answers. Who tells the clients, and what can anyone say before the firm knows whose files were touched? Should partners call now or wait for a central line? What does the consultant at the bank say in the next five minutes? And by lunchtime, which of the 140 clients have actually been told?

This is where keeping clients informed during an incident stops being a relationship skill and becomes a coordination task. The firm needs one agreed version of events, a named owner for every client conversation and a record of who has been told what.

For a consulting firm, the client relationship is the business. Client communication belongs inside the incident response from the first hour.

What Is Keeping Clients Informed During An Incident?

Keeping clients informed during an incident is the coordinated process of telling each affected client what has happened, what it means for their work and when they will hear more, through a named owner and from one agreed set of facts.

Each client can have a different conversation, but every conversation carries the same core facts. The National Cyber Security Centre’s guidance on effective communications in a cyber incident makes the same point: address the specific concerns of each group while keeping the core points consistent across them.

Why Does A Consulting Firm Incident Have Three Audiences?

A consulting firm incident has three audiences because staff, leadership and clients each need different information on a different timetable. Staff need instructions. Leadership needs decisions to make. Clients need to know whether their work and data are affected, and when they will hear more.

The risk is real for this sector. In the government’s Cyber Security Breaches Survey 2025, 55% of professional, scientific or technical businesses had identified a cyber breach or attack in the previous twelve months, against 43% of businesses overall (DSIT 2025).

Audience

What they need first

Who usually owns it

Staff

What to do, and what to say if a client asks

Incident lead, with HR and internal communications

Leadership

The facts so far and the decisions needed

Incident lead

Clients

Whether their work or data is affected, and when the next update comes

Engagement partner, working from the agreed line

The table looks tidy. In practice the three rows drift apart within an hour unless one person owns the facts that feed all of them.

Every Partner Will Want To Call Their Own Client

Engagement partners own their client relationships, so their instinct in the first hour is to pick up the phone. The instinct is sound. It’s also how a firm ends up with 140 slightly different accounts of one incident: “a minor IT issue” from one partner, “a cyber attack” from another, and a promise that no client data was affected from a third, before anyone knows.

Each version sounds reasonable on its own. The trouble comes later, when two clients in the same sector compare notes, or when the facts change and nobody can say which clients heard the earlier version.

Consultants On Client Sites Will Be Asked First

Consultants on client premises are often the first people from the firm to be asked about an incident, and the least prepared to answer. The bank’s CIO won’t wait for the engagement partner to ring.

Staff need a short, approved line and one place to send further questions. For example:

“Our firm is dealing with an IT incident affecting some internal systems. Your engagement partner will contact you today with an update. Until then, please send any questions to them.”

The articles on incident coordination for consulting teams and duty of care at client sites cover knowing who is on which client’s premises. Those people need the line first.

Leadership Needs Decisions, Not A Running Commentary

A leadership team in an incident needs a short list of decisions and the facts behind each, rather than every technical update. Telling directors is the step most firms already take: 76% of businesses that identified a breach or attack informed their directors or trustees (DSIT 2025). Being told is not the same as being ready to decide.

In the scenario, the 11:00 board call has three real decisions on it:

  • Whether to contact all 140 clients now, or only those whose files may be affected
  • What the firm’s position is: still investigating, or something firmer
  • Who speaks for the firm if a journalist or a regulator calls

The NCSC advises naming official spokespeople before an incident happens. Left to the day, that choice gets made by whoever answers the phone.

What Can A Firm Tell Clients Before It Knows Whose Data Is Affected?

A firm can tell clients what it knows, what it’s doing and when they will hear next, without guessing at what it doesn’t know. The NCSC warns against saying anything that may have to be retracted later, and notes there may be internal pressure to give assurance that everything is in hand.

There is often a legal thread as well. Where a consulting firm processes personal data on a client’s behalf, it is usually acting as a processor. The Information Commissioner’s Office guide to personal data breaches explains that under UK GDPR Article 33(2), a processor that suffers a breach must inform the controller without undue delay as soon as it becomes aware. The client, as controller, must then report a notifiable breach to the ICO without undue delay, and not later than 72 hours after becoming aware of it.

So clients whose personal data may sit in the affected systems hear first, and each call is logged. A holding message at this stage might read:

“We have identified a cyber incident affecting some of our internal systems. We are investigating whether any of your data is involved and will update you by 16:00 today, or sooner if we confirm anything that affects you.”

Whether a breach is notifiable, and what each client contract requires, is for the firm’s data protection lead and legal advisers to decide.

Keeping Clients Informed Means Owning Each Call

Once the order is set, each client conversation becomes an action with an owner, a deadline and a status. “Call the client” sitting in a partner’s head is not a status anyone else can see. A usable client communication list shows, for each client:

  • The engagement partner who owns the conversation
  • Whether the client’s data may be in the affected systems
  • The time of the last contact, and which version of the line was used
  • The next update promised, and when it is due
  • Any question the partner couldn’t answer, passed back to the incident team

The list also needs somewhere to live when the usual systems are down, because the NCSC notes that normal channels may not be available during a cyber incident. In the scenario, partners fall back on personal mobiles and WhatsApp, which is fast and leaves no shared record of client communication during a cyber incident. Emergency communication software can still reach staff with the approved line, but the client calls need tracking where the whole incident team can see them. A separate article covers tracking critical actions during an incident more generally.

Challenging The Assumption That Clients Only Need To Hear From Their Partner

The belief that clients should hear from their own partner is mostly right. Clients trust the person they work with, and a call from an unfamiliar central team can feel colder than the news deserves. It fails when the partner’s call is treated as enough on its own.
The 09:15 text about “a minor IT issue” now has to be corrected, and a correction costs more trust than a careful first message would have. Most firms haven’t written down how this should work: only 32% of businesses have guidance on when to report a cyber breach or attack externally (DSIT 2025). The fix keeps the partner as the voice and moves the content to the centre. The incident team owns the facts, partners own the call, and both work from the same list.

The assumption is mostly right about evacuation itself. Consultants should follow the client’s marshals without question. It breaks down on everything around the evacuation: who informs the firm, who gets counted and who looks after the people the client never registered.

The HSE leaflet Protecting lone workers expects employers to have systems in place to keep in touch with lone workers and respond to any incident. It also says emergency procedures should include guidance on how and when lone workers can contact their employer. A consultant placed alone at a client can fit that description, and the client’s fire plan doesn’t meet that expectation on the firm’s behalf.

A Practical Decision Framework For Client, Staff And Leadership Communications

Six steps, in the order they tend to matter on the day.

1. Name One Owner For The Facts

The incident lead, or a communications lead reporting to them, owns the agreed statement of what is known. Every message to every audience draws from it.

2. Tell Staff First, And Tell Them What To Say

No consultant should learn about the incident from a client. Send the approved line and the person to refer questions to.

3. Sort Clients By Exposure

Clients whose data may be in the affected systems come first. The data protection lead decides what the firm’s obligations as a processor mean for each.

4. Turn Each Client Call Into An Owned Action

One partner, one deadline and one status per client. Record the time of each call and the version of the line used.

5. Give Leadership Decisions, Not Updates

Brief the board on the decisions needed, the options and the time by which each must be made.

6. Update Every Audience When The Facts Change

When the line changes, find everyone who heard the earlier version on the list. Each of them hears the new one from the same owner.

How Crises Control Supports Client Communications During An Incident

Crises Control is an Operational Incident Coordination Platform that works with an organisation’s existing systems rather than replacing them. It addresses the gap the scenario exposes: communication tools send notifications, but they don’t coordinate the updates, acknowledgements and follow-up that come after them.

The module most relevant here is Task Manager, Crises Control’s incident task management software. Task Manager assigns tasks when a response plan is activated, to a named owner or team who can accept the task and update its status from any device. Authorised users can reassign tasks and adjust deadlines as the incident develops.

Escalation rules can notify a supervisor, reassign a task or alert the incident manager when a task isn’t accepted or completed in time. Workflow dependencies mean a task only unlocks once the tasks it relies on are complete, and the product page’s own example is stopping teams from notifying stakeholders before the impact has been assessed. Ownership, acceptance times, status changes and completion updates are recorded in the operational incident record.

For staff and leadership, the crisis communication software page describes sending tailored messages to audiences such as employees, response teams and leadership, with acknowledgements tracked. For a professional services parallel, see incident management software for legal services.

The software does not decide what a client should be told, or whether a breach is notifiable. Those remain decisions for the firm’s leadership, its data protection lead and its legal advisers. Its role is to make sure every agreed conversation has an owner, a deadline and a record.

Every Client Conversation Is Part Of The Response

A firm that can reach its people quickly has solved the first half of incident communication. The second half is coordination: one set of facts, an owner for every client conversation and a list showing who has been told what, and when. For a consulting firm, that list is how 140 partner calls end up telling the same story.

Request a free demo today!

Frequently Asked Questions

Keeping clients informed during an incident involves telling each affected client what has happened, what it means for their work and when they will next hear, from one agreed set of facts. Each conversation has a named owner, usually the engagement partner, and a record of when it took place.

The engagement partner is usually the right person to make the call, because the client knows and trusts them. The content of the call should come from the incident team, so every partner gives the same core facts. The firm’s legal and data protection advisers decide whether any formal notification is also required.

Consultants should give a short, approved line and refer further questions to the engagement partner. They should not speculate about the cause, or about whether client data is affected. Firms should send staff that line before clients start asking.

If the firm processes personal data on a client’s behalf, it is usually a processor, and under UK GDPR Article 33(2) it must inform the client without undue delay once it becomes aware of a breach. The client, as controller, must report a notifiable breach to the ICO without undue delay and not later than 72 hours after becoming aware of it. Contracts with individual clients may add further terms.

Emergency communication software helps a firm reach staff and response teams quickly with an approved message, and shows who has acknowledged it. Keeping clients informed during an incident also needs each client conversation tracked as an owned action, with a record of when it happened. That tracking is the job of incident task management rather than alerting alone.

This article was drafted with AI assistance and reviewed by the Crises Control team. Featured image: AI-generated.

Shalen Sehgal

CEO & Co-Founder

Since co-founding Crises Control, Shalen has focused on helping organisations strengthen operational resilience through coordinated incident management, emergency communication and business continuity. His work is centred on enabling organisations to respond to critical events with greater visibility, accountability and confidence.

← Blogs

How Crises Control Helps

From first alert to final report. One connected platform.

Crises Control combines incident alerting, response coordination, task management and automatic audit trail creation so organisations can manage every emergency while staying fully compliant.

Stop reacting. Start coordinating.

See how Crises Control gives your organisation control during every incident and defensible proof after it.

No commitment required. See the platform in action with your own use cases.