AI is supercharging cybercrime. Boards must treat crisis comms as a frontline defence
Cyberattacks have long been a boardroom concern, but AI is changing the nature of the threat and increasing the pressure on leadership teams. For companies, the danger is no longer limited to whether systems can be restored. It is whether the business can keep confidence intact while the facts are still emerging. That makes crisis communications part of cyber resilience, not a bolt-on once the technical clean-up has begun. Recent attacks affecting major names including Marks & Spencer and Jaguar Land Rover showed how quickly disruption can become headline news. When online sales stall and customer-facing systems go down, silence is quickly filled by speculation, doubt, mistrust and in some cases the PR tactics of the attackers themselves. AI is changing the cyber threat AI is changing the cyber threat because it gives attackers a faster way to scale familiar tactics. CrowdStrike’s 2026 Global Threat Report shows that this is already being felt, with AI-enabled adversary activity rising 89 per cent year-on-year and average eCrime breakout time falling to just 29 minutes. At the same time, the launch of Anthropic’s Claude Mythos Preview sharpened concern among policymakers and financial institutions about how quickly AI-enabled capability is developing. Taken together, these signals point in the same direction. Cyber incidents are becoming faster and harder for leadership teams to control. For boards, that means the communications response must be prepared before a breach happens, not assembled once speculation has already taken hold. A cyberattack is a reputation event A cyberattack becomes a reputation event in more ways than one. It affects the way customers judge the business, the way employees understand leadership’s grip on the situation and the way investors assess resilience. The M&S cyberattack showed how quickly operational disruption can become a public confidence issue, with online orders suspended and customers left looking for reassurance while the company worked through the impact. In that gap, the communications response matters as much as the recovery effort. If people do not understand what has happened or what the business is doing next, trust starts to weaken. A company without a prepared communications plan can lose control of the story before it understands the attack. Silence can also create legal risk Communication is not just about managing headlines. In a cyber incident, legal considerations need to be built into the crisis response from the start. Under the UK GDPR, organisations must have appropriate technical and organisational measures in place to keep personal data secure. If a personal data breach occurs, they may also need to notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it. In high-risk cases, affected individuals may also need to be informed. That notification timeline can itself become a trigger for the incident to enter the public domain, so communications teams need to work with it in mind. Crisis managers can help by coordinating closely with legal counsel, so public statements and customer updates reflect the organisation’s obligations while still being delivered in a timely, considered manner when scrutiny is highest. When systems fail, the message still must get out Many attacks hit the same systems companies rely on to communicate. Email platforms, customer databases, intranets and internal messaging tools can be taken offline or encrypted. When that happens, even basic updates become harder to issue. Rumours move quickly, threat actors fill the vacuum, and stakeholders are left wondering who is in control and what damage they may suffer personally. Boards should not wait until a breach to ask how they would reach customers, employees, regulators or the media if normal channels are unavailable. Crisis plans should include practical contingencies: offline contact lists, pre-approved holding lines, temporary communications platforms, the ability to publish a holding web page at pace, and a clear view of which unaffected channels could be used for stakeholder updates. The aim is not to say everything immediately. It is to make sure the organisation can say enough, through trusted channels, while the facts are still being established. A plan that has not been tested is not a plan Cyber incidents expose weak processes quickly. Information is often partial and systems may be unavailable, while leadership teams must make difficult calls under pressure. Crisis simulations help boards understand where decisions will get stuck and whether the right people can act at the right moment. Rehearsal matters because a live incident is the worst possible time to discover that approval chains are unclear. People are still central to cyber resilience. Employees need to recognise phishing attempts and deepfakes. Help‑desk teams need to know what to do when attackers impersonate customers or staff. Senior leaders also need to resist the temptation to overstate certainty. In a cyber crisis, cautious clarity is far safer than confident guesswork. Boards need to own the communications response Boards can no longer treat cyber incidents as remote operational risks. AI is changing the scale and speed of the threat, making sophisticated attacks easier to build and deploy. Claude Mythos has added to concern among policymakers and financial institutions about how quickly AI-enabled cybercrime could develop. Detection tools are vital, but they cannot protect confidence on their own. When systems are down and uncertainty is spreading, people look to leadership for reassurance, honesty and direction. Insurance may soften any immediate financial blow, and many policies include crisis PR support. But no policy can repair trust if communication is slow or evasive. Internal communication matters too. Many breaches begin with human error, so staff must understand both the threat and their role in the response. As AI raises the stakes, the board’s role becomes more important, not less. Cyber resilience is no longer only about stopping an attack. It is about protecting the trust that allows a business to recover. The organisations that prepare now will be better placed to speak clearly, act decisively and hold the confidence of the people who matter most. For practical steps on preparing for and communicating during a data breach, download Infinite’s data breach checklist.