-
admitted the issue immediately
-
reassured users as to actual scope of breach, probable risk
-
provided recommended actions for users who think they may be impacted.
-
explained best-practices (enough for a laymen’s audience) and how they limited scope and impact.
-
did not deflect blame
My god…I’ve got to hand it to plex. This is the perfect incident response letter. Love 'em or hate 'em, this is a good example for other CISOs.
Fed to the rules, and I hit the ground running.