The cyber-incident playbook — what the contact centre does in hour one
When a data breach or ransomware event hits, the contact centre becomes the public face of a crisis it did not cause and does not control. Worried customers surge the queues, agents face questions nobody has answered yet, and a regulatory clock starts ticking. The cyber playbook is narrower than the others — and the discipline it demands is stricter.
Hour one — a narrow and disciplined role
In a cyber incident the contact centre is not the investigator, not the decision-maker, and not the spokesperson. Its hour-one role is deliberately narrow: connect to the organisation’s incident-response structure through one named route, follow instructions about which systems to stop using — immediately and without debate, because in this incident class IT’s instruction to disconnect is not negotiable the way a normal outage workaround might be — and establish a single source of truth for what agents may say. The playbook’s first page is therefore mostly names: who connects to incident response, who owns the approved script, who briefs the floor, who decides when anything changes.
The characteristic hour-one failure is well-meaning improvisation. A team leader drafts a reassuring line for their team; an agent confirms a detail to a journalist posing as a customer; someone keeps using a system the response team needed isolated. None of it is malicious; all of it makes the incident worse. The discipline that prevents it is the same one that runs every other playbook — pre-named decisions and one voice — applied with less tolerance, because in this incident class the cost of freelancing is legal, regulatory and forensic, not just operational.
Scripting and disclosure discipline
In the early hours of an incident, the honest position is usually we are investigating, we will contact affected customers, here is where updates will appear. The approved script says exactly that — drafted with legal and communications, version-numbered, and replaced wholesale whenever the position changes. Agents say what the script says: no speculation about cause, scope or blame; no confirming whether an individual’s data is affected before the organisation has formally established and communicated it; no off-script reassurance, however kind the impulse, because I’m sure your details are fine is a sentence that can be wrong in a way the organisation answers for later.
This discipline has to be framed honestly to the floor: it is not about hiding things from customers, it is about not telling them things that are not yet true. Premature reassurance that later unravels does customers more harm than a candid we don’t know yet. The playbook pairs the script with a what-not-to-say list and a clean escalation route for the contacts that exceed it — the journalist, the lawyer, the distressed customer reporting actual fraud — each routed to a named team, never busked at the front line.
The surge of worried customers — and the regulatory clock
A disclosed incident produces a demand surge with a particular character: one dominant question (am I affected, what should I do?), high anxiety, elevated handle times, and a meaningful share of genuinely vulnerable callers for whom the worry is acute. The surge playbook applies — publish the approved answer on the website and IVR, route the dominant question to a briefed team, work the lever ladder — with one strict difference: every deflection message and FAQ is the approved wording and nothing else. The vulnerable-customer pathway is protected absolutely; an elderly caller frightened about their savings is exactly who must reach a calm human quickly.
Above the operational layer sits a regulatory one. Under UK GDPR, personal-data breaches meeting the risk threshold must be reported to the ICO within 72 hours of the organisation becoming aware, and affected individuals informed where the risk to them is high — decisions owned by the organisation’s data-protection and legal functions, not the contact centre (and none of this is legal advice; the obligations turn on specifics that belong with your own advisers). The contact centre’s job against that clock is operational: capture and route customer reports that may be evidence, log contact volumes and themes for the incident team, and be ready to scale when formal notification letters land — because every letter is a phone call, and that wave, at least, can be forecast almost to the day.
Agent wellbeing — the load nobody briefs for
Cyber incidents place a distinctive load on agents. They absorb fear and anger about something they did not do and cannot fix, hold a tight script under pressure to break it, work amid genuine uncertainty — and, often overlooked, they may be affected individuals themselves, taking calls about a breach that includes their own personal data. An operation that briefs the script but not the support has planned half the incident.
The playbook names the supports in advance: honest floor briefings at a fixed cadence, so agents hear developments from their leaders before they read them in the news; explicit permission to escalate hostile contacts without it touching their numbers; quality and AHT expectations formally relaxed for incident contacts and announced as such; shorter stints on the incident line with deliberate rotation; and a visible route to employee support, plus a separate, clearly signposted channel for agents’ own questions as affected individuals. Team leaders carry most of this, so the playbook briefs them first and hardest.
Standing down and learning
Cyber incidents end gradually — notification waves, media echoes, and a long tail of customer anxiety that can run for months. The playbook plans the descent: criteria for stepping the surge structure down, scripts that evolve from we are investigating through here is what happened to here is what we have done, and the displaced ordinary work recovered deliberately. The contact data the centre logged throughout — volumes, themes, vulnerable-contact patterns — feeds the organisation’s formal post-incident review, where the contact centre deserves a seat it does not always get.
Then the operation reviews its own performance against its own playbook: how fast the approved script reached the floor, whether the single source of truth held, how the surge structure coped, what the incident did to the people. The honest answer usually improves the playbook in a dozen small ways. That is the quiet justification for the whole document — you write it hoping never to use it, you rehearse it annually anyway, and the first hour of a real incident repays every minute of that rehearsal.
The closing principle
In a cyber incident the contact centre’s power lies in the narrowness of its role: one voice, an approved script, a protected pathway for the vulnerable, and agents who are briefed, supported and rotated. Everything else belongs to the incident team — and knowing that in advance is the playbook.
See also
- The system-outage playbook operating when the technology doesn t
- realtime-communication
- planning-for-vulnerable-customers