Incident communication should help people make a safe decision while the technical team investigates. It needs a clear owner, honest status, expected next update, and language appropriate to staff, customers, vendors, or leadership.

Define severity and audience

Classify impact by affected workflow, users, data, duration, revenue, safety, or contractual importance. Use the classification to decide who needs an update, how quickly, through which channel, and with what level of detail.

Assign communication ownership

Name the incident lead, technical investigator, business owner, support contact, customer communicator, and approver for external messages when those roles differ. Do not make the person debugging also responsible for every audience by default.

Write the first update

State what is affected, when it began or was detected, what users may experience, what the team is doing, the current workaround, and when the next update will arrive. Avoid guesses presented as facts.

The downtime plan and status page cost guide cover public and internal states.

Keep updates consistent

Use timestamps, status, impact, action, and next update in each message. Correct an earlier statement visibly when evidence changes, and avoid sending contradictory updates through several channels without an owner.

Protect private and security-sensitive details

Share enough for a safe action without exposing credentials, private records, exploit details, or individual customer information. Use the appropriate incident or security process for sensitive facts.

Close with recovery and follow-up

State when service is restored, what users should do, whether delayed work is being reconciled, and where questions go. Follow with a review that records impact, cause, detection, response, missing evidence, and improvements.

Test the communication path

Practice an outage, degraded service, data mismatch, provider failure, and false alarm. Confirm access to channels, contact lists, templates, status page, support script, escalation, and after-hours coverage.

Incident messages are improvised while the team is investigating? Ask Vertinus to document the communication roles and templates.