Course overview
When a data breach is confirmed, the technical work of containment runs alongside a second, equally demanding task: deciding what to say, to whom, and by when. This course concentrates on that communication side of a breach. It treats notification and messaging as a coordinated discipline that connects the security team, legal counsel, the data protection officer, and communications, so that the organization speaks accurately and on time instead of guessing under pressure.
Aimed at an international audience of communications, security, and governance professionals, the course follows a breach from the first internal alert through regulatory notification, customer messaging, and the slow work of rebuilding trust afterwards. Throughout, delegates examine how incident response coordination and communication planning depend on each other, and why a message released too early, too late, or with the wrong detail can compound the damage a breach has already done.
Why this matters
Regulatory expectations have made breach communication a timed obligation, not a discretionary act. Under the GDPR, for example, a personal data breach that meets the relevant threshold must be reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, with affected individuals informed when the risk to them is high. Many other jurisdictions impose their own duties, and organizations operating across borders often face several regulators and several clocks at once.
Beyond the legal duties, breaches are trust events. Customers, staff, and partners judge an organization less by the fact that a breach happened and more by how honestly and competently it responded. Poorly worded breach notification letters, silence while rumors spread, or promises that later prove false can turn a contained incident into a lasting reputational problem. This course helps delegates get the communication right while the facts are still emerging.
What you will be able to do afterwards
By the end of the course, participants will be able to:
- Map roles and decision rights across security, legal, DPO, and comms
- Explain the GDPR 72-hour duty and cross-jurisdiction variations
- Prepare honest holding statements during an ongoing investigation
- Draft clear, non-technical breach notification letters
- Liaise with forensic investigators so messaging reflects verified facts
- Coordinate messaging to regulators alongside public statements
- Decide when to offer measures such as credit monitoring
Course outline
Unit 1: Understanding data breaches and their impact
- Types of personal and confidential data exposure
- Human, financial, and reputational impact
- Why breach handling needs cross-function coordination
- Common failures: delayed disclosure, over-reassurance, jargon
Unit 2: Breach detection, containment, and recovery coordination
- Detection and containment milestones as verified facts
- Forensic liaison: scope, timeline, confidence levels
- Keeping messaging aligned with the incident playbook
- The speed-versus-accuracy tension under scrutiny
Unit 3: Legal and regulatory notification obligations
- GDPR 72-hour notification duty and high-risk threshold
- Overlapping authority obligations across jurisdictions
- Required contents of breach notification letters
- ISO/IEC 27035 incident management structure
Unit 4: Crisis communication and reputation management
- Holding statements and tiered audience messaging
- Aligning internal and external communication
- Communicating remediation and credit-monitoring offers
- Consistent tone and facts across every channel
Unit 5: Building long-term breach response resilience
- Structured post-incident communication review
- Updated playbooks, contact trees, and templates
- Defined roles, decision rights, and escalation paths
- Sustaining trust through transparency and follow-through
How the course is delivered
The course is expert-led and centered on analysis and drafting, not acted scenarios. Delegates work through facilitated case analysis of documented breaches, guided walkthroughs of notification timelines, and structured group discussion of messaging decisions. A significant part of the time is spent drafting and critiquing templates, including holding statements and breach notification letters, so delegates leave with documented materials they can adapt for their own organizations.
Who should attend
This course suits professionals who would help decide what an organization says when a breach occurs, and how it says it.
- Communications and public relations professionals with incident responsibilities.
- Data protection officers and privacy team members.
- Information security and incident response managers.
- Legal, compliance, and risk professionals involved in breach handling.
- Customer service and operations leaders who manage affected-customer contact.
- Senior managers who approve breach disclosures and public statements.
About EuroQuest International Training
Founded in 2015, EuroQuest International Training has delivered more than 1000 courses to over 15,000 participants worldwide. Delivery is international, with hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris, and Geneva. Delegates who want to deepen the technical crisis side of this subject often combine it with our course on incident response and cyber crisis management, which pairs naturally with the communication focus taken here.
Frequently asked questions
Does this course tell me exactly what my organization must legally do after a breach?
No. The course is educational and is not legal advice. Breach-notification duties vary by jurisdiction, and the specifics that apply to your organization depend on where you operate and what data is involved. Delegates should consult qualified legal counsel and their own data protection officer before acting. What the course gives you is a clear understanding of how these duties are structured, so you can work with counsel more effectively and prepare communication that fits your obligations.
Is any of the course a live breach exercise or acted scenario?
No. There is no live lab and no acted performance of a breach. The learning comes from facilitated case analysis of real incidents and from drafting and critiquing communication templates such as holding statements and notification letters. This keeps the focus on the reasoning and wording you will actually need, in a setting where you can test ideas without time pressure.
Will I receive a formal certification?
The course does not provide certification. Delegates receive a certificate of attendance from EuroQuest International Training, and the lasting benefit is the set of frameworks, templates, and judgment you take back to your incident response planning.
Related courses
- Crisis Communication and Reputation Management
- Crisis Management in Digital Marketing
- Crisis Communication and Public Safety Strategies
- Digital Transformation in Public Relations
Register for this course
If your organization wants to be ready to communicate calmly and correctly when a breach occurs, we invite you to register for this course or contact EuroQuest International Training to discuss dates and group bookings.
All Course Dates & Locations
30 dates · 12 cities · Sep 2026 – Jun 2027