skip to content

How do you tell 4,000 staff to stop using the company chat when the intruder is reading it?

level: seniorimportance: nice to knowfreq 40%

answer

  1. three audiences read every internal message
  2. write it as though it will be published
  3. instruction, not explanation
  4. no links, no attachments
  5. silence is filled with rumour

basics

~20 s

Send a short instruction that changes behaviour, carries no findings, and can be verified without clicking anything, through a path the adversary does not control. Write it assuming the intruder and the press both read it.

solid answer

~50 s

Assume three audiences: staff, the intruder, and whoever leaks it to a journalist. That means the message asserts nothing you would not publish - no actor, no scope, no cause, no count - and says only what people must do differently: stop using this platform for X, use Y instead, expect a call from your manager, and here is when you will hear more. It must also survive the phishing problem you have just created: you are about to train four thousand people to trust an unusual instruction to move to a new channel, so include a verification path that does not depend on a link or an attachment, and push it through managers and a phone tree rather than one broadcast email. Do not lie about the reason; "we are investigating a security issue" is the floor. Silence with no explanation produces rumour that is usually worse than the truth.

go deeper

for a junior

Remember that anything sent to the whole company is effectively public, and that an incident notice should tell people what to do rather than what you found.

for a middle

Explain why the notice must contain no findings and no links, and why the delivery path must not be the platform you are asking people to stop using.

for a senior

Show you designed for imperfect compliance at scale, prepared manager-level answers to the obvious questions, and refused to buy calm with a false explanation.

for a principal

Own the standing position: what internal comms may assert during a live intrusion, who signs it off, and the credibility cost of ever having misled staff for convenience.

## Three audiences, one message A company-wide instruction during a live intrusion is read by more people than you addressed it to. Write it knowing that: 1. **Staff** need to change what they do in the next ten minutes. 2. **The intruder** may be among the recipients, or reading the platform it is sent through. 3. **A journalist, a customer or a regulator** will very likely see it, because a message to four thousand people is a public message with a delay of about an hour. Every word has to be acceptable to all three readers at once. That constraint is what makes the task harder than it looks, and it is why the natural draft - which explains the situation to reassure people - is the wrong one. ## What the message must achieve - **A behaviour change, stated as an instruction.** "Do not discuss the incident in company chat; if you are contacted about it, use the number your manager gives you." Concrete, checkable, immediately actionable. - **Verifiability.** You are asking people to accept an unusual instruction to move to a new channel. That is exactly the shape of a phishing campaign, and if you normalise it without a verification path, you have handed an adversary a template. The message should contain **no links and no attachments**, name a person or an internal path people already trust, and be echoed through a second route - managers in person, a phone tree - so recipients can corroborate it. - **A time for the next update.** People fill silence with speculation. One sentence saying when they will hear more is enough. ## What the message must not contain - **Findings.** Not the account, not the host, not the technique, not how you found it, not what you are about to do. Anything operational tells a reading adversary what you know and how much time they have. - **Assertions you cannot yet stand behind.** No actor name, no "no customer data was affected", no number of systems. Everything you assert becomes a thing you may have to retract in public, and retractions cost more credibility than the original caution ever did. - **A lie.** You may say very little; you should not say something untrue. "Scheduled maintenance" is tempting because it explains the disruption without alarming anyone, but if the truth comes out - and in an incident of any size it does - you have taught your own staff that internal comms are unreliable at exactly the moment you need them to follow instructions. "We are investigating a security issue and are taking precautionary steps" costs you almost nothing and is true. ## Delivery The channel matters as much as the wording. Sending it *through* the platform you are telling people to stop using is both self-defeating and, if the adversary holds administrative rights over that platform, unreliable: messages can be seen, and in some circumstances altered or removed, before they land. Prefer a path the adversary does not control - SMS to personal numbers, a phone cascade through managers, or a briefing delivered by team leads in person or by voice. In practice you will use several, because no single one reaches everybody. A cascade through managers has a second benefit: it lets a human answer the immediate questions, which a broadcast cannot, and it gives you an audit of who has actually been told. ## The scale problem With four thousand people you cannot verify who complied, and a proportion of them will ignore the instruction. Design around that: the instruction should be a **default that fails safe** (say less in chat, take calls from managers), not a task that requires everyone to do something correctly. Assume some fraction of the workforce continues as normal and keeps talking, and let the response plan tolerate it rather than depend on universal compliance. ## Rehearsing the questions you will get Within minutes, staff will ask: is my own account affected, is my personal data involved, should I change my password, can I still do my job? Have short answers ready for the managers who will be asked, and make sure those answers are also things you would publish. "We will contact you individually if your account is involved" is honest, calming and reveals nothing. ## What good looks like A candidate who reaches for the wording is thinking at the right level. The strongest answers say the quiet part explicitly: *this message is public the moment it is sent, so I write it as a public statement that happens to be addressed internally* - and then show they have solved the second-order problem, which is that a mass instruction to trust a new channel is itself an attack surface.

  • Why not send the notice as a maintenance message to avoid alarming people?
    Because it is untrue and it will not hold. In any incident large enough to require a company-wide instruction, the real reason surfaces, and staff who were misled once discount the next instruction - which may be a more urgent one. "We are investigating a security issue and are taking precautionary steps" is vague enough to reveal nothing and true enough to survive the day it becomes public.
  • What second-order risk does a mass instruction to move to a new channel create?
    It trains thousands of people to accept an unexpected instruction to switch communication channels, which is precisely the pretext an adversary would use. Mitigate it inside the message: no links, no attachments, name a trusted internal path, echo the instruction through managers so recipients can corroborate it, and tell people explicitly that no genuine notice will ask for credentials.
  • Staff immediately ask whether their own accounts are compromised. What do you have managers say?
    A prepared line that asserts nothing unproven: we are contacting individually anyone whose account is involved, and if you have not been contacted there is nothing you need to do beyond the instruction you were given. It is honest, it discloses no scope, and it prevents four thousand people from independently deciding to reset credentials in a way that would swamp the service desk mid-incident.

saying these in an interview costs you the question

  • Explains the findings to reassure staff
  • Sends the notice through the platform being abandoned only
  • Frames the disruption as scheduled maintenance
  • Includes a link to the new channel, teaching people to click
  • Asserts no customer data was affected before it is known

context