During a prolonged incident response, executives keep asking for status while analysts are still containing the threat. The incident commander asks you to define a communication cadence. Which practice best supports the response?
Select an answer to reveal the explanation.
Short Explanation
Think of incident updates like bus schedules: people worry less when they know the next one's coming. You don't need breaking news every time—just a predictable 'no change yet' message. The trap is waiting for perfect findings, which invites constant interruptions.
Full Explanation
A fixed update cadence works because it replaces uncertainty with a known expectation. During a prolonged incident, stakeholders often ask for status because they do not know when they will hear next. By publishing a schedule—such as hourly or every two hours—the analyst gives a reliable time for the next message, even if the content is only 'no material change.' This reduces pressure on responders and keeps leadership from sending ad hoc interruptions. Updating only after confirmed forensic findings is wrong because silence can be interpreted as inactivity, and confirmed findings may take hours; interim updates can share containment status without speculation. Escalating whenever a new indicator of compromise appears is wrong because it turns every technical detail into executive noise and creates unpredictable demand for attention. Delaying updates until containment is complete is wrong because a prolonged incident requires interim visibility into progress, risks, and next steps. Exam caveat: cadence should be proportional to incident severity and business impact, not a one-size-fits-all timer. Operational check: confirm the incident ticket or bridge notes include the next scheduled update time and who owns sending it.