When a company experiences a cyberattack, it must consider not only its customers but also its suppliers, connected systems, and business partners in its response. According to a guide on crisis communication for small and medium-sized enterprises, companies should avoid publishing messages before the facts are confirmed, as this can be as risky as ignoring the incident. Legal requirements also play a role, particularly in setting deadlines for public communication. Underestimating the impact of a cyberattack can damage a company’s credibility. For example, after a cyberattack on Free on October 25, 2024, the company initially warned customers but did not mention customer IBANs (International Bank Account Numbers). Three days later, a hacker released 100,000 of these IBANs on the darknet, increasing the ransom demand from 10,000 to 65,000 euros. Free later admitted that 5.11 million accounts were affected, and customers felt misled from the start. A lack of transparency can lead to doubt between a company and its customers. If a company is silent for several days, provides conflicting messages across different channels, or delays fixes without explanation, trust can erode. On January 1 of last year, La Banque Postale limited its first message to a factual statement about a temporary unavailability of its mobile app and online banking, avoiding unnecessary technical details or unrealistic deadlines. This approach aligns with recommendations to clearly state the situation, affected people, actions taken, and the date of the next update. The communication strategy for suppliers and partners differs from that for customers. While customers need immediate instructions—such as changing passwords or monitoring bank statements—suppliers need to know whether shared technical access could have been an entry point. According to the General Data Protection Regulation (GDPR), suppliers are considered subcontractors if they process data on behalf of the company, and they must determine if their own customers need to be warned. Business partners, such as distributors or resellers, are more concerned with the date when operations will resume than the details of the attack. A phone call to explain the situation, reassure them about implemented measures, and provide schedules for deliveries and orders is recommended. The GDPR sets a 72-hour deadline to notify the CNIL (French Data Protection Authority) of a data breach that poses a risk to individuals. Failure to meet this deadline can result in fines up to 10 million euros or 2% of global turnover, and up to 20 million euros or 4% if the failure involves data security. The CNIL adjusts these amounts based on the company's response speed and cooperation. Managers are personally responsible for failing to notify and could face up to five years in prison and a fine of 300,000 euros under the penal code. Since 2023, an additional requirement from insurers mandates that a complaint be filed within the 72-hour period, or they will refuse to cover the losses of operations. For example, France Travail, the former National Agency for Employment, followed all steps after a cyberattack on March 13, 2024, by notifying the CNIL, filing a complaint, and individually warning each affected person by email or through their personal account. A dedicated phone line and a simplified complaint form were also made available. To prepare for a cyber crisis, companies should designate one person for external communication and another for technical matters, while creating a shared document that is updated as the incident unfolds. Standard messages tailored to customers, suppliers, and partners should be prepared using practical guides from the new ANSSI (National Cybersecurity Agency of France) guide on cyber crisis communication. Management teams should also be trained through simulation exercises to ensure everyone knows their role before a real crisis occurs. Communication should be conducted in stages rather than with a single message followed by silence. Updates should be provided even in the absence of major progress to prevent people from seeking information elsewhere or spreading harmful rumors. The incident should be reported to the CNIL and a complaint filed within 72 hours, without waiting for all technical issues to be resolved. Individuals whose data pose a high risk should be informed directly through a private channel, such as email or a customer portal, rather than a public statement.