Incident Communication Breakdowns
Seven Emails. Three Weeks. No Technical Detail. Exposure Assessment Incomplete.
6 min read · 21 June 2026 · Security
A healthcare insurer's incident response to a vendor breach notification was textbook , within one hour of receiving the notification, they had convened the IR team, activated the regulatory assessment process, engaged legal counsel, and sent a detailed technical inquiry to the vendor requesting specific information needed to scope their own exposure. The inquiry included twelve specific questions: the timeline of unauthorised access, the specific systems accessed, the data categories that were accessible, the authentication method used by the attacker, the technical indicators of compromise, the containment timeline, and the specific records that may have been exfiltrated. The vendor's first response arrived three days later , a single paragraph written in consultation with their legal team describing the incident as 'a cybersecurity event affecting certain IT systems' and confirming that the investigation was ongoing. The second response, seven days after the original inquiry, provided slightly more detail , the incident had been contained and the vendor was cooperating with relevant authorities. Ten weeks and seven communications later, the insurer had received enough information to complete their HIPAA breach risk assessment. Eighty-seven percent of the investigation timeline had been consumed by waiting for vendor communications that legal review delayed.
What are Incident Communication Breakdowns, Really?
Incident communication breakdowns in vendor relationships are the failures in the flow of specific, technically useful information from the vendor's IR team to the customer's IR team during a shared incident , breakdowns that impair the customer's ability to understand their own exposure, complete their own regulatory obligations, and conduct their own forensic assessment. These breakdowns arise from three sources: legal review cycles that delay and sanitise technical communications, communication channel limitations that funnel technical questions through account management rather than IR-to-IR channels, and content restrictions that limit what the vendor will communicate during active litigation preparation.
The legal-filtered communication problem is the dominant breakdown pattern. When a vendor's legal team controls breach communications, the communications are optimised for legal risk minimisation rather than customer information needs. Legal-reviewed communications tend to be temporally vague ('the incident occurred in Q2'), technically non-specific ('systems containing certain customer information were affected'), and legally hedged ('we cannot confirm or deny specific data access at this time'). These communications satisfy the vendor's legal team's requirements for minimising specific factual admissions. They are nearly useless for the customer's IR team, whose exposure assessment requires specific timeline, specific systems, specific data categories, and specific attack vectors.
The account management communication channel problem compounds the legal review delay. Vendor breach communications often flow through account management teams , the relationship managers who handle day-to-day customer interaction , rather than directly between the vendor's IR team and the customer's IR team. Account managers who relay technical inquiries to engineering and legal teams introduce additional delays and translation layers that reduce the specificity of information received and the speed of its delivery. Direct IR-to-IR communication , established before incidents occur , bypasses the account management relay and reduces the communication path length.
- Legal-filtered communications providing non-specific legally hedged information
- Account management communication channel introducing delays and translation
- No IR-to-IR direct communication channel established before incident
- Communication content requirements not contractualised , what specific information vendor must provide
- No communication SLA , timeline for specific technical detail provision
Why this matters
Incident communication breakdowns matter for TPRM because the customer's ability to complete their own regulatory obligations , HIPAA breach risk assessment, GDPR notification, financial services incident reporting , depends on obtaining specific technical information from the vendor within the applicable regulatory timelines. A customer who cannot obtain the technical details needed for their breach risk assessment within the regulatory timeline is not compliant, regardless of whether the vendor provided general notifications that satisfied their own contractual obligations.
The HIPAA breach risk assessment dimension is specifically consequential. HIPAA requires covered entities to conduct a breach risk assessment , a formal evaluation of the probability that PHI was compromised , to determine whether notification is required. The risk assessment requires specific information about the nature of the incident, the type of PHI involved, and whether the data was actually accessed rather than merely potentially accessible. A vendor whose communications do not provide this specific information in time for the assessment makes HIPAA compliance dependent on the vendor's communication timeline rather than the covered entity's own diligence.
Where most teams get this wrong
The most consistent failure is not establishing IR-to-IR communication channels and communication content requirements before incidents occur. When the first contact between IR teams happens during an active incident, the communication challenges described above are discovered in real time , at the worst possible moment.
- No IR-to-IR communication channel pre-established
- Communication content requirements not in contract , what must be provided and when
- Account management as incident communication channel , IR-relevant communications routed through non-IR staff
- No communication SLA for specific technical detail
- Legal review cycle not addressed in communication requirements
What good looks like
Mature incident communication programmes establish IR-to-IR communication channels before incidents, contractualise communication content requirements including specific technical details to be provided within defined timelines, and require that legal review does not prevent provision of specific technical information needed for customer regulatory obligations.
- IR-to-IR communication channel established , direct contact before incident
- Communication content requirements contractualised , specific technical details within defined timelines
- Legal review not an excuse , contract provision requiring specific technical detail regardless of ongoing legal review
- Communication SLA , timeline for technical detail provision from notification
- Joint communication protocol , pre-defined communication format and frequency
Tooling
Secure Communication , Signal, encrypted email, shared IR workspace
Secure communication platforms provide encrypted channels for IR-to-IR technical communication during incidents. Establishing secure communication channels with critical vendor IR contacts before incidents provides the direct technical communication pathway that account management channels cannot. For TPRM practitioners, establishing an encrypted communication channel with the vendor IR contact as part of joint IR planning provides both the channel and the relationship.
Governance challenges
The governance challenge with incident communication is the legal review tension. Vendors with significant breach liability have strong incentives to filter communications through legal review to avoid creating specific factual admissions. The governance resolution is contractualising specific technical communication requirements that exist alongside the vendor's right to legal counsel , the vendor can still have legal review, but the contract specifies that specific technical information must be provided within defined timelines regardless of the review cycle.
- Establish IR-to-IR contact before incident , exchange emergency contact details
- Contractualise technical communication content , twelve specific questions and required timeline
- Include legal review exception , contract requires specific technical detail regardless of review
- Set communication SLA , specific timeline for technical detail provision
- Test communication channel , annual communication exercise
If you are a small team
For your highest-risk vendor, exchange emergency IR contact details now , not account manager contacts, but the actual security or IR lead who would manage the communication during an incident. Send an introductory email confirming the contact relationship. Then add one clause to your next contract amendment: in the event of a security incident involving the customer's data, the vendor will provide the following twelve specific details within twenty-four hours of the customer's written request, regardless of ongoing internal legal review. The list of twelve details costs five minutes to draft. The relationship and the clause cost thirty minutes. Both prevent three weeks of legally-filtered non-communication.
- Exchange IR-to-IR emergency contact details with critical vendors now
- Draft twelve specific technical details required within 24 hours of request
- Add communication content clause to next contract amendment
- Test communication channel annually
What to require
Ask directly:
"In the event of a security incident affecting our data, what is the specific process for our IR team to receive technical details , timeline of access, systems affected, data categories, attack vector , directly from your IR team rather than through your legal team, and can we establish that communication channel now?"
Expect as evidence
- Named IR contact for technical communication during incidents
- Commitment to provide specific technical details within defined timeline
- Process for IR-to-IR communication bypassing legal review delay
- Communication content requirements acknowledgment
A vendor who confirms incident communication procedures should be asked specifically whether technical details can be provided directly to the customer's IR team and what the timeline is. The procedure describes what happens. The direct channel and the content requirements determine whether what happens is useful.
How to evidence it
- IR-to-IR communication channel documentation
- Communication content requirements in contract
- Communication SLA records
- Annual communication exercise records
Key Takeaway
Seven emails. Three weeks. No technical detail. The information existed in the vendor's IR investigation. The legal team's review cycle filtered the specific technical content that would have enabled the customer to complete their exposure assessment. Legal-reviewed communications satisfied contractual notification obligations. They did not enable regulatory compliance. The IR-to-IR channel, established before the incident, bypasses the account management relay. The communication content clause, negotiated before the incident, requires specific technical detail regardless of ongoing legal review. Both are straightforward to establish. Both are infinitely harder to establish after the incident that requires them has begun.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association