When the Systems Go Down: Communicating Through a Cyberattack
About this course
An advanced, self-paced course for government communicators on what to say, and how to say it, when a ransomware attack takes down the systems your organization and your office depend on.
It usually starts on an ordinary morning. Email won't load, the phones are dead, the payment portal is down and dispatch has gone to manual. IT is unplugging machines. A reporter already has a photo of the ransom note. And the tools you would normally use to tell the public what's happening, your website, your email lists, sometimes your social media logins, are part of what has been lost.
Cities, counties, 911 centers, school districts and hospitals have all been through this, from Atlanta and Baltimore to Dallas, Columbus and St. Paul. Their experience shows that a cyberattack is a communications incident from the first minute, and a trust test that runs for months. Investigators, lawyers and insurers will all have good reasons to say less. Residents will have urgent, practical questions: Can I still call for help? Can I pay my bill? Is my information safe?
This course follows the real sequence of an incident. It covers communicating without your own tools, working alongside IT, breach counsel, incident response firms, insurers, the FBI and CISA, handling the word "ransomware" and the ransom question, avoiding statements that later become false, managing breach notification and the call center, sustaining weeks of recovery updates, and preparing a cyber annex, go-kit and pre-approved holding statements before any of it happens.
Every lesson is built on named, linked cases and current US guidance, and each includes practical work for your own organization. The course ends with a final assessment in which you draft a first public statement and a 72-hour update plan for a realistic scenario.
Who This Course Is For:
- Government communicators at cities, counties, special districts and school districts who would be expected to speak for the organization during a cyberattack
- Communicators at 911 centers, public safety organizations and public hospitals, where a systems outage affects emergency services
- Communications leads who want a cyber annex and pre-approved statements in place before Cybersecurity Awareness Month ends
- Solo communicators who will be the organization's entire public voice on the day the network goes down
Read a sample from this course
Seven-fifteen, and the email won't load
Picture this. You get to your desk a little after seven and your laptop won't connect. You assume it's the Wi-Fi. Then a colleague leans into the doorway and says the phones are dead too, and the permit counter can't pull up anything, and someone in finance saw a strange text file on the shared drive with instructions for how to "restore your data." By eight, the IT director is walking the halls telling people to unplug their machines and not to turn anything back on.
Nobody has called you into a meeting yet. Nobody has told you what this is. But your phone is already buzzing, because a resident posted on a neighborhood Facebook group that the online bill payment page is down, a reporter has picked up a scanner comment about dispatch "going manual," and your city manager wants to know what you're going to say.
This is the moment this course is built around. Not the forensic analysis, not the insurance claim, not the rebuild of the network, all of which will be handled by people with very different skills from yours. This course is about the person who has to talk to the public while the systems that normally let them do that are down, the facts are thin, the investigators want silence, and the people you serve have urgent, practical questions that can't wait for the forensics.
It is an Advanced course because it assumes you already know how to run a crisis response. If you need the fundamentals, Crisis Communication: Planning, Response, and Recovery covers them. What makes a cyberattack different is that it attacks the communicator's own tools at the same moment it creates the crisis, and it drags in legal, investigative and insurance interests that shape every sentence you're allowed to say. The instincts that serve you well in a storm or a shooting can steer you wrong here, and this course is about recognizing where.
What you'll learn
Course Curriculum
Full access upon enrollment- 1.Seven-fifteen, and the email won't load
- 2.It has already happened to cities that thought they were ready
- 3.The public has three questions, and none of them is about ransomware
- 4.What you don't know yet, and what you do
- 5.Your own staff are the first audience
- 6.Try this: walk through your first hour
- 7.This is a communications incident from the first minute
- 8.Sources & further reading

Course Resources
Available after enrollment
Course details
- Self-paced
- Certificate of completion
- Lifetime access
- 8 lessons · 57 sections
- 4 downloadable resources

