Skip to main content

Communication Templates Overview

20+ pre-built templates for incident communications.

What Are Communication Templates?

CrownSync Playbooks includes over twenty pre-written communication templates designed for use during and after a cyber security incident. These templates cover every audience you may need to notify — from regulators and board members to customers, staff, and the press. Each template follows UK regulatory requirements and professional communication standards, ensuring your organisation responds quickly without scrambling to draft messages under pressure.

Communication templates are embedded within the relevant phase of each playbook. When you reach a step that requires a notification or briefing, the appropriate template is presented in context with pre-populated fields drawn from your organisation profile.

Template Categories

Templates are organised into five categories based on their intended audience and purpose:

  • Regulatory notifications — Formal notifications to regulatory bodies including the ICO, FCA, PRA, NHS DSPT, and SRA. These templates include the specific fields and formats each regulator expects, along with deadline tracking to ensure you meet mandatory reporting windows.
  • Internal communications — Messages for your own organisation, including all-staff notifications, board and executive briefings, management updates, and technical briefings for IT teams. These ensure consistent messaging across all levels of your organisation.
  • External communications — Customer-facing notifications, press statements, and FAQ documents. These templates help you communicate transparently with affected parties while managing reputational risk and meeting regulatory disclosure obligations.
  • Insurance notifications— Templates for notifying your cyber insurance provider, including initial incident alerts and detailed claim submissions. These are shown only if your organisation profile indicates active cyber insurance coverage.
  • Law enforcement referrals— Templates for reporting incidents to Action Fraud, the National Cyber Security Centre (NCSC), and law enforcement agencies. These include the reference numbers and formats expected by each body.

How Templates Are Personalised

Every communication template is automatically personalised with details from your organisation profile. When you open a template, the following fields are pre-populated:

  • Organisation name, registered address, and company number
  • Data Protection Officer name and contact details
  • ICO registration number
  • Incident reference number (when used during an active incident)
  • Relevant regulatory body names and submission URLs
  • Date and time stamps in UK format

Templates also adapt based on your sector. A financial services organisation sees FCA and PRA notification templates; an NHS trust sees DSPT reporting templates; a law firm sees SRA templates. Only the templates relevant to your regulatory profile are displayed.

Keep Your Profile Up to Date

Template personalisation relies on your organisation profile being accurate. If your DPO changes, your registered address moves, or you gain new regulatory obligations, update your profile in Organisation Settings so all templates reflect the correct details.

Using Templates During an Incident

During an active incident, communication templates appear at the relevant step within your playbook. For example, when you reach the containment phase and the playbook instructs you to notify the ICO, the ICO breach notification template is presented inline. You can review the pre-populated content, make any necessary adjustments, and copy the final text for submission.

Templates can also be accessed independently from the Communications section of the platform. This is useful when you need to send a follow-up communication or prepare a template outside of the normal playbook flow.

Customisation and Legal Review

All templates can be customised to match your organisation's tone and specific requirements. Edits are saved per organisation, so your customised versions persist across incidents. If you need to revert to the original template, a reset option is always available. For details on editing and managing templates, see Customising Templates.

Information

CrownSync recommends that all regulatory notification templates are reviewed by your legal team before first use. Templates provide a strong starting point, but your legal advisors should confirm that the language meets your specific obligations.

Was this page helpful?