Impersonating reporters on panels has become one of my favorite past times. After the annual American Bankers Association meeting, where I played a reporter on a panel examining how to handle a computer hack/cyber-attack, the ABA invited me to recreate my performance at their annual meeting for Risk Managers. The panel was titled: “Incidence Response and Recovery: Is the Response Worse than the Attack?” The scenario was similar: your bank has been hacked. In this mock scenario, the institution in the hot seat was a billion dollar bank in the South named Lucky Bank, and the media outlet I represented was “UOMe” TV.
The first news of the hack came from credit card companies reporting that customers were complaining en masse about unauthorized charges and cancelled charges. Updates from the annual meeting panel included a plaintiffs law firm, Dewey Cheatum & How (borrowed from NPR’s Car Talk) trolling the internet looking for bank customers for a class action suit, and a well-connected, disgruntled blogger, Bankerbabe. In addition, Lucky Bank received word that the hackers were selling information allowing criminals to access ATMs so bank personnel were physically reprogramming ATMs outside their branches. Internet savvy customers noted the workmen and posted pictures of them on Instagram. Bankerbabe called them to my attention at the television station.
My role was to ask the questions the media would ask and to illustrate how social media platforms such as Facebook and Twitter complicate the communication challenge.
Experts speaking at the conference were virtually unanimous: it’s not if you’ll experience a hack, it’s when; so it’s wise to prepare. The conference covered the technical, legal and operational issues–and there were many. Although bank executives may feel they have quite enough to contend with in those areas, don’t forget that communication, both internal and external, is needed across the entire enterprise. And, you will undoubtedly have to communicate with key audiences before you have all the facts. Typically, you will not have any of the key facts confirmed when you get word through third parties or social media.
Are you prepared? Create a timeline beginning with taking the first phone call or reading the first tweet. How would you handle the questions below after the first hour? day? week? Hint: we’re not advising you be able to “answer” the questions, but you must have credible responses which convey confidence and inspire trust. And, you’ll have to deal with these questions from reporters, customers and the general public. If you’re lucky, the reporter or customer will call customer service, but they may also be trading rumors on social media.
Our reporter in this scenario had recently read a lengthy article about security procedures so she had some specific technical questions:
The panel’s scope did not encompass formulating the responses. That’s a topic for another conference, but grappling with the question will give you a snapshot of your preparedness.
So, are you prepared to respond? Ready, set, go!
You May Also Like
As readers of our BIMBO Memo know, convincing someone not to panic isn’t achieved by saying “Don’t panic.” This is fast becoming one of the top denial mistakes in recent history. It’s understandable. When there’s great uncertainty and… more
Has Pro Football Hall of Fame wide-receiver Randy Moss found a path out of the tricky situation the NFL finds itself in? The issue, of course, is the situation with the national anthem and Old Glory, the American… more
A recent news story tells the tale of government workers in a small Alaskan town who became dependent upon typewriters to do their jobs after cyber criminals infected their computer systems with ransomware. How are your typewriter skills?… more