The golden hour is gone: David Whiteley on navigating cyber crises at AI speed

"The challenge isn’t that AI is creating entirely new crises. It’s that AI is compressing the time available to understand and respond to crises while also making it harder to know what is true."

Resilience Unfiltered Coffee Chat Series

Cyber attacks increasingly originate outside organizations – through a vendor, technology partner or link in the supply chain. And they unfold at a pace that leaves little time to think.

In this Resilience Unfiltered chat, David Whitely from Melbourne, Australia discusses why having a crisis plan is only the beginning of preparedness.

Managing director, FTI Consulting Australia, David brings more than 25 years of global experience in journalism and strategic communications across Europe, North America and Australia, specializing in crisis and issues management. He led a specialist media relations team at the UK’s financial services regulator at the height of the global financial crisis and was head of communications at London Gatwick Airport, managing its incident and crisis communications team. As vice president for marketing and communications at ACI World, David coordinated global advocacy and crisis response for Airports Council International as aviation was brought to a standstill by the COVID-19 pandemic. He was also senior adviser to the premier of Western Australia, playing a central issues-management role in the 2013 election campaign.

David and I first met at the International Association of Business Communicators (IABC) World Conference in Chicago in 2024 and collaborated on the crisis communications summit in Toronto this June. I’m delighted to continue the conversation on September 29, when David will facilitate a virtual cyber crisis simulation for the IABC crisis communications shared interest group I chair.

Natalia

How is AI changing the crisis risk landscape?

David

AI is creating new types of crises while changing the speed, scale and sophistication of existing threats. We are seeing a lot of deepfakes and social engineering – using deception to manipulate people into revealing information or compromising security. AI scans thousands of systems in minutes, identifying vulnerabilities faster than a human ever could. It can analyse social media and company websites to build highly targeted attacks against key staff, or help ransomware operators find the most critical systems to encrypt. Take phishing emails. They’ve been part of the risk landscape for years, but AI takes them to the next level. It can generate thousands of unique phishing emails and rapidly translate and localise scams, allowing the same attack to be launched across multiple countries at once. Cyber attacks move at AI speed.

Natalia

What does that mean for crisis response?

David

One of the biggest challenges is that AI is accelerating crises. It’s compressing the time we have to understand what’s happening, make decisions and respond. That means you need to be much better prepared to deal with crises as they unfold. Cyber attacks can hit from multiple directions at once. Misinformation can spread faster than organizations can validate facts. AI is also changing stakeholder expectations. They expect real-time answers, not next-day statements. Narratives can form before investigations even get up-to-speed, and the old idea of the golden hour is gone.

Natalia

In this new risk landscape, where do organizations get stuck?

David

When we see high-profile situations where an organization is in the news for a slow crisis response, it’s often because leaders haven’t experienced anything like that before. A crisis is a whole different kind of decision-making. You are working with limited information, under pressure and in very short time frames.

There’s an old saying that no battle plan survives first contact with the enemy. Very true. It doesn’t mean we don’t need a plan, but a plan on a shelf is only the beginning of preparedness. Training, exercises and simulations take your plan off the page and give you the confidence to respond in real time. They also expose blind spots. Who is empowered to make decisions? When do we escalate? What looks clear on paper can become confusing under pressure. The last thing you want is to be mapping key stakeholders or gathering customer information in the middle of a crisis.

I worked on a cyber incident involving a group of companies that shared many of the same systems. One company was breached, affecting the entire group, but each company responded separately. One breach, three different responses with inconsistent messaging to employees, customers and other stakeholders. Obviously, not ideal.

Natalia

How do you navigate those damned-if-you-do, damned-if-you-don’t dilemmas – communicate too early and risk overreacting, or wait too long and risk losing control?

David

People now accept that organizations will be victims of cyber attacks. Their reaction is less about what happened and more about how the organization responded. Often, it’s better to escalate, get into a crisis-response footing and be prepared to communicate what you know than keep waiting for that next piece of information.

Qantas in Australia is a relevant example. When the airline experienced a cyber incident last year, it took a couple of days to understand what had happened and then communicated across all its channels with customers and other stakeholders – what it knew, what it was doing and what those affected needed to know. It was a 24-hour news cycle, and then it was kind of done because they had communicated so fulsomely and quickly. People could see: they are on top of it, I don’t need to worry.

We’ve also seen organizations wait too long, lose control of the narrative and spend the rest of the crisis trying to catch up. It’s much easier to de-escalate when you need to than chase a story that’s getting away from you.

Natalia

What does good leadership look and sound like when the facts are still emerging?

David

Everyone needs to work as one team. Operations, legal, executives, communications. When does an issue become a crisis? Who needs to know? What can we say when we don’t yet have all the facts? To move swiftly, leaders need to work out the decision-making and communication framework in advance.

That brings us back to that damned-if-you-do, damned-if-you-don’t dilemma. You know there’s an issue. Is it a crisis? Do we need to communicate externally? The worst thing you can do is hold back, waiting for that extra fact. When the media finds out there’s an issue, the decision is made for you. Now you need to communicate, but you are reacting to a narrative set in motion by someone else.

A few years ago, a telecommunications company in Australia faced a major network outage and was slow to communicate with customers and stakeholders. Here’s what often happens in a situation like that. Leaders ask questions such as: What are we dealing with? How long will it take to fix? What are we doing about it? In a fast-moving, uncertain situation, the team leading the operational response may not have those answers. Someone in the room makes a decision that seems logical on the surface: if we don’t have the answers, we shouldn’t say anything.

But that’s the nature of a crisis. You are not going to have all the answers. It’s key to keep people informed as you respond rather than waiting for a solution and then communicating it. Stakeholders don’t expect perfect answers in the first hour. They need to see you are on top of the response. You care about those affected. You’ll keep them updated. That’s what leadership looks like in a crisis – not having all the answers, but showing you are in control of the response even when the crisis itself is not under control yet.

Natalia

How should organizations train for crises in this new risk landscape?

David

Historically, preparedness has been based on plans, playbooks and escalation procedures. That’s still where we start, but organizations need to be much faster at making decisions, responding and coordinating across different functions and teams.

Think back to CrowdStrike. A software update failure affected approximately 8.5 million Windows devices globally, disrupting airlines, banks, healthcare providers and governments. Many organizations had to communicate before they fully understood the technical root cause. That’s the kind of pressure you need to simulate in crisis training. Put leaders in situations where they don’t have all the answers but still have to communicate with employees, customers, media, investors, regulators and other stakeholders: “This is what we know. This is what we don’t know. This is what we are doing next.” The more AI enters the crisis scene, the more stakeholders will value this kind of human judgement – being able to make decisions and communicate with confidence before you have all the facts.

Natalia

How is AI changing the reputation landscape?

David

The crises of the future may involve two parallel events: the incident itself and the information environment around it, shaped by AI-generated content. There are two questions for crisis leaders: What is actually happening? And what do stakeholders believe is happening? Organizations can mistake online volume for public opinion, and AI-generated content is increasing that risk.

AI is making information easier to create, harder to verify and faster to spread. When you are monitoring social media, news coverage and stakeholder feedback, you have to ask: Is this genuine public concern? Coordinated activism? Synthetic amplification by bots? AI-generated misinformation? You need to assess the authenticity and credibility of information in real time.

For most of my career, crisis work was about managing information. Increasingly, it’s about managing uncertainty. The organizations that do this well will be able to make confident decisions even when they don’t have the full picture.

Natalia

What would you like our readers to take away from this conversation?

David

Having a plan is the first step. The second is making sure everyone understands their roles and responsibilities in a crisis. The third is practising and testing those roles. What are my duties when something happens? What decisions am I responsible for? You need to work that out before the crisis.

We recently ran a crisis exercise with a financial services organization, simulating a distributed denial-of-service attack. As we worked through what each member of the crisis team would need to do, one person put their hand up and said, “What I have to do in this situation overrides everything else.” They had a regulatory reporting requirement that no one else around the table knew about. It completely changed the sequence of what needed to happen. Discovering that during an exercise was incredibly valuable. Simulations surface things you don’t know you don’t know.

Natalia

Thank you, David. I’m looking forward to continuing this conversation at our cyber crisis simulation on September 29.

Earlier chats in the Resilience Unfiltered Series:

Edward Conley on disaster leadership: to gain control of a crisis, you need to give up control

From surviving to strengthening: Alison Arnot on meeting human and organizational needs through internal crisis communication

Margaret Brigley on evidence over echo chambers in crisis decisions

A coffee chat with Richard Brown: leading global comms across cultural divides

Dr. Matt Tidwell: crises, values and media readiness in a divided world

Anne Marie Aikins on proactive reputation management in ‘good and really bad times’

Coffee chat with Kim Clark: is there a way to get layoffs right?

A coffee break Q&A with Alexander Rau: “Cyber resilience is a marathon, not a sprint”

A coffee Q&A with Dr. Ian Mitroff: thinking systemically is the most critical skill in crisis planning

A coffee Q&A with Helio Fred Garcia: the agony of decisions and the power of patterns in a crisis

A coffee Q&A with Christal Austin: climate emergency & disaster preparedness

Coffee with Dr. Ian Mitroff: thinking the unthinkable

Natalia Smalyuk is an award-winning advisor and trainer specializing in strategic communication, crisis resilience and stakeholder engagement. She leads NBAU, a Women Business Enterprise (WBE) certified communication consultancy. What is NBAU? Not Business as Usual. Why NBAU? Because there’s no such thing as business as usual for leaders navigating volatility and risk across a complex global landscape. NBAU supports organizations in building resilience before, during and after adverse events through planning, training and scenario exercises that broaden the understanding of crises and enable positive action in an uncertain world. Our Resilience Unfiltered Series encourages open dialogue on tough issues that rarely makes it onto conference stages.

Next
Next

From improvisation to resilience: why progress beats perfection in crisis readiness