Skip to main content

Internal Communication Templates

Staff alerts, board briefings, and management updates.

Internal Communication Templates

Effective incident response depends on clear, timely communication within your organisation. CrownSync Playbooks provides internal communication templates for every level of your organisation, from all-staff notifications to board-level briefings. These templates ensure consistent messaging, prevent information leakage, and keep all stakeholders informed at the appropriate level of detail.

Internal templates are personalised with your organisation name, incident reference number, and relevant contact details. They appear within your playbooks at the phases where internal communication is recommended and are also accessible from the Communications section.

All-Staff Notification

The all-staff notification template is designed for broad communication to everyone in your organisation. It provides a measured, factual summary of the situation without disclosing sensitive technical details that could cause unnecessary alarm or create a security risk if shared externally.

The template covers:

  • A brief description of what has happened in plain language
  • What the organisation is doing in response
  • What staff should and should not do (e.g. password changes, avoiding certain systems)
  • Who to contact with questions or concerns
  • When the next update will be provided
  • A reminder about confidentiality and not sharing details externally

Timing Matters

Send the all-staff notification early in the incident to prevent rumours and speculation. Staff who learn about an incident through unofficial channels are more likely to share inaccurate information externally. A prompt, honest communication builds trust and keeps your team aligned.

Board and Executive Briefing

The board and executive briefing template provides a structured summary for senior leadership and board members. It balances technical accuracy with business impact language that non-technical executives can understand and act upon.

The briefing includes the following sections:

  • Incident summary— What happened, when it was detected, and the current status
  • Business impact— Which services, systems, or operations are affected and the estimated duration of disruption
  • Customer and data impact— Whether personal data, customer accounts, or financial systems are involved
  • Regulatory obligations— Which notifications have been or need to be made, and their deadlines
  • Response actions— Key containment and recovery steps taken or planned
  • Decisions required— Any decisions that need board or executive approval
  • Next update— When the next briefing will be provided

This template is particularly important for organisations with regulatory obligations that require board-level awareness of cyber incidents, such as FCA-regulated firms and NHS trusts.

Management Update

The management update template sits between the all-staff notification and the board briefing in terms of detail. It is designed for department heads, team leaders, and middle management who need enough information to manage their teams effectively during the incident.

The template includes:

  • Current incident status and severity level
  • Which departments and systems are affected
  • Impact on normal business operations and workarounds in place
  • Actions managers should take within their teams
  • Key messages to relay to their direct reports
  • Escalation contact for department-specific questions

Management updates are typically sent more frequently than board briefings, often at regular intervals during an active incident (for example, every four hours or twice daily).

IT Team Technical Briefing

The IT team technical briefing template provides the detailed technical information that your IT and security teams need to carry out containment, eradication, and recovery actions. Unlike the other internal templates, this one includes technical specifics.

The briefing covers:

  • Indicators of compromise (IOCs) identified so far
  • Affected systems, IP addresses, and accounts
  • Attack vector and lateral movement observed
  • Containment actions taken and their status
  • Specific tasks assigned to team members
  • Tools and access required for the response
  • Evidence preservation requirements
  • Communication channels for the technical response team

Information

The IT technical briefing is tailored to your technology stack. If your organisation profile specifies particular SIEM, EDR, or cloud platforms, the template references those tools by name rather than using generic instructions.

Best Practices for Internal Communications

  • Establish a single source of truth — all updates should come from the incident commander or designated communications lead
  • Set a regular update cadence and communicate it to all stakeholders
  • Use the appropriate template for each audience — do not send technical details to all staff or high-level summaries to the IT team
  • Include clear next steps and a timeline for the next update in every communication
  • Remind all recipients that incident details are confidential and should not be shared outside the organisation

Was this page helpful?