Tell them once you know enough to be accurate, in plain language, saying what happened, what of theirs was involved, what the risk is, and what you have done. Send it directly rather than posting a notice.

What is actually being judged

Customers do not generally expect a small business to be impossible to compromise.

What they judge is whether you told them, how quickly, and whether the message treated them as adults.

A business that notifies promptly and plainly usually keeps its customers. One that says nothing and is discovered, or sends something evasive, frequently does not.

This is a general description rather than legal advice, and the thresholds, timing requirements, and regulator obligations depend on where you operate and what happened.

The timing question

Two pressures pull against each other and both are legitimate.

Telling people quickly matters, because they may be able to act, and because the value of a warning decays.

Telling people accurately matters, because a first message that is later corrected undermines everything after it, and initial assessments of these incidents are frequently wrong in both directions.

The resolution is to notify once you know who was affected and what was involved, which is usually a small number of days rather than either hours or weeks.

Where somebody is at immediate risk, such as a fraudulent invoice already circulating, that warning goes out straight away and separately, without waiting for the full picture.

What the message has to contain

The fourth is worth including where accurate, because people assume the worst about what is unstated, particularly regarding payment information.

Write it as a person

The register decides how it is received more than the content does.

Say we, not the organisation. Say what happened, not that an incident occurred involving unauthorised access.

Do not open with reassurance about how seriously you take security, which is what every such message says and which reads as preparation for bad news.

Do not blame a supplier in the first paragraph, even where a supplier is responsible, because the customer's relationship is with you.

And do not describe it as a sophisticated attack, which reads as an excuse regardless of whether it is true.

Short sentences, direct statements, and an apology where one is warranted.

Send it directly

Method matters, because a notice nobody sees is not a notification.

Email the affected people individually rather than posting a page and hoping.

Use a subject line that says what it is, since anything vague will be ignored or mistaken for marketing.

Send from an address people recognise, and be aware that if email was the compromised system, some recipients will reasonably distrust an email from you, which is an argument for a phone call or a letter in serious cases.

A page on your site is a useful supplement, holding the detail and any updates, and it is not a substitute for reaching people.

A worked example

A firm whose booking system had been accessed notified about four hundred customers.

The message was six sentences: what happened, when they discovered it, that names, phone numbers and appointment dates were involved, that no payment details were held in that system, that they had secured it and reported it, and that anybody contacting them claiming to be the business and asking for payment should be treated with suspicion.

It gave a phone number and named the person answering it.

They received about twenty replies, almost all of them supportive, and three people asked to be removed from their records.

Two customers said afterwards that the message was the reason they stayed, because a competitor had handled something similar by saying nothing.

The specific warning about impersonation was the part that did the actual protective work.

Prepare for the replies

The operational half that gets forgotten.

Expect a proportion of recipients to respond, mostly with reasonable questions, some with anger, and a few asking to be deleted.

Decide before sending who answers, what they say, and what they do about deletion requests, because an unanswered reply to a breach notification undoes the goodwill the notification earned.

Write three or four short answers in advance to the questions you know will come: how did this happen, what about my payment details, are you sure it is fixed, and what are you doing differently.

And tell whoever answers the phone that this is going out, on the day it goes out, so nobody is taken by surprise by the first call.

Say what changed

The element that converts an apology into something credible.

People are more forgiving of an incident than of the sense that nothing has been learned from it.

Name one or two specific things you have changed: two-factor enabled everywhere, a system replaced, access reviewed, a supplier changed.

Specific and modest beats a general commitment to reviewing security, which reads as nothing.

If a follow-up is warranted a few weeks later saying what you have completed, that is worth sending, and almost nobody does it.

The counter-case

Notifying is not automatically the right call in every situation.

Where an assessment concludes there is no real risk of significant harm, a notification can cause alarm disproportionate to the facts and can devalue the notices that genuinely matter.

Regulators have consistently warned against notification fatigue for exactly that reason.

There is also a difference between notifying affected individuals and announcing publicly, and a business is not obliged to publicise an incident that affected eleven people to its entire customer base.

Where the assessment is genuinely marginal, that is the point to take advice rather than to decide on instinct in either direction, and to document whichever way you go.

The notification

  1. Warn anybody at immediate risk straight away.
  2. Notify once you know who and what, in days not weeks.
  3. Say what was and was not involved.
  4. Give one specific action they should take.
  5. Name one or two things you have changed.
  6. Send it directly, with a clear subject line.
  7. Decide who answers replies before sending.

Step seven is the one that determines whether the notification helps or becomes a second problem.

Containment comes first, covered in what to do in the first hour of a breach.


Frequently asked questions

How quickly should I notify?

Once you know who was affected and what was involved, usually a small number of days. Anybody at immediate risk, such as from a circulating fraudulent invoice, gets warned straight away.

What should the message contain?

What happened, when, what information was involved, what was not involved if that is true, the practical risk, what you have done, what they should do, and a real route to ask questions.

What tone works?

Plain and direct. Do not open with how seriously you take security, do not blame a supplier first, and do not call it a sophisticated attack, all of which read as preparation for bad news.

Is a notice on my website enough?

No. Email affected people individually with a subject line that says what it is. A page is a useful supplement holding detail and updates, not a substitute for reaching people.

What makes an apology credible?

Naming one or two specific things you changed. People forgive an incident more readily than the sense that nothing was learned, and a general commitment to reviewing security reads as nothing.

Should I always notify?

No. Where the assessment concludes there is no real risk of significant harm, notification can cause disproportionate alarm and devalue the notices that matter. Document the decision either way.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Drafting a notification?

Decide who answers the replies before you press send. An unanswered reply undoes everything the message earned.

Start a Conversation