Amber's Blog

Home  »  Blog   »   Always be prepared: Qantas is the latest but not the last business be hacked

Always be prepared: Qantas is the latest but not the last business be hacked

Amber Daines | 3 July, 2025

 

The gloomy news earlier this week that up to six million Qantas customers could be impacted by a breach of their data via a contact centre working with the Australian airline, and Qantas expects a “significant” proportion of the data to have been stolen, really hit hard.

Not again, right? Familiar stories for many Australians who recall the last few years of similar (same same but different) cyber attacks affecting thousands of their customers from big-name companies, Medibank and Optus.

This kind of online hack or cyberattack is no longer a matter of if, but when. For public relations leaders, the stakes are high. A swift, strategic, and sincere response can preserve a company’s reputation, while a misstep can damage stakeholder trust for years to come.

Having worked on numerous crises for major companies over the past decade, here are my top five ways PR leaders must manage a cyberattack to safeguard their reputation and maintain public confidence.

1. Always Prepare Before the Storm Hits

Crisis comms really can’t start when the breach happens—ideally, that begins long before.

PR leaders must:

  • Develop a crisis communications plan specifically for cyber incidents.
  • Create templated holding statements and FAQs that can be adapted quickly.
  • Coordinate with IT, legal, HR, and customer service to ensure alignment of messaging.
  • Conduct regular simulations or “war rooms” to test your readiness and response capabilities.

Why it matters: Preparation ensures you’re not scrambling when every minute counts. It also builds internal muscle memory for real-time response.

2. Be on the Front Foot

When a cyberattack is discovered, time is of the essence—but accuracy still matters.

The PR team’s first task is to:

  • Acknowledge the issue publicly (if confirmed) with a brief, non-speculative holding statement.
  • Reassure stakeholders that the organisation is investigating and prioritising data protection.
  • Update regularly, even if there’s little new information—silence breeds suspicion.

Pro tip: The first message sets the tone. Lead with transparency, accountability, and calm.

3. Put People First

Customers, clients, employees, and partners want to know how the incident affects them and what you’re doing about it.

PR leaders should:

  • Explain the breach in plain, jargon-free language.
  • Provide clear instructions on steps affected individuals can take (e.g., password changes, credit monitoring).
  • Show empathy. Use human-centred messaging that acknowledges frustration, inconvenience, or fear.

Avoid using: Defensive language, overpromising timelines, or unrealistic resolutions. Empathy and realism win trust faster than ignoring such communications.

4. Coordinate Across Channels and Stakeholders

During a cyber crisis, communication must be consistent, cross-functional, and cross-channel.

PR leaders should:

  • Use a centralised message bank to keep all spokespeople aligned.
  • Monitor traditional media, social media, and internal channels for misinformation or rising concerns.
  • Brief executives, the board, customer service reps, and employees on talking points and next steps.

Why it matters: A fractured or contradictory response causes confusion, and it looks like you’ve lost control.

5. Nail the Recovery Narrative

Once the immediate threat is contained, the real work of rebuilding one’s reputation begins.

PR leaders must:

  • Share what was learned, what’s changing, and how the organisation will prevent future breaches.
  • Highlight improvements in cybersecurity infrastructure, staff training, and third-party risk management.
  • Engage with media, regulators, and customers proactively to demonstrate leadership, not just damage control.

Recovery is your best opportunity to showcase resilience, responsibility, and long-term commitment to stakeholders.

The reality is that cyberattacks are now a PR inevitability, not a hypothetical.

The best PR leaders or agents treat cybersecurity as much of a communications issue as a technical one.

How you respond can either define your organisation as transparent and trustworthy, even in its most challenging moments.