Cyber Victim Notification Working Group

Robert Joyce • August 25, 2025

Adding detail to the concepts of the Cyber Safety Review Board

I was part of the working group on victim notification processes that was lead by Rob Knake sponsored by the Institute for Security and Technology (IST).


Timely victim notification is essential after cyber incidents, but today’s systems fall short. Companies often have only a single email address to reach victims, leaving messages distrusted or overlooked. Many recipients can’t tell a real alert from a phishing lure, and even when they do, they may lack the knowledge to act effectively.


The Cyber Safety Review Board (CSRB) recommended that cloud service providers explore an “‘amber alert’ style” system for high-impact incidents, delivered natively through mobile devices. While promising, such a system faces serious hurdles—technology integration, governance, and the need for broad industry cooperation. Given these challenges, adoption is unlikely unless the scope expands beyond narrow “high-impact” cases to cover a wider range of account compromises.


Some recommendations emerged for near-term actions while larger efforts are developed: Providers should refine current notification practices, develop middleware for private cross-platform delivery, and strengthen post-notification support. 


Download the full report here:



https://securityandtechnology.org/wp-content/uploads/2025/08/Amber_Alert_Report-08-25.pdf


By Robert Joyce August 23, 2025
Plan for security in your sprint to deploy.
By Robert Joyce August 16, 2025
This is a subtitle for your new post
By Robert Joyce August 11, 2025
This is a subtitle for your new post
By Robert Joyce June 6, 2025
China is embedding vulnerabilities into the very technologies Americans depend on.
By Rob Joyce March 14, 2025
The AI Productivity Revolution: How I Built a Custom App in 30 Minutes
By Rob Joyce March 7, 2025
China’s Cyber Threats to Critical Infrastructure & TP-Link Router Risk
By Robert Joyce June 20, 2024
My OpEd for the Hill
By Robert Joyce April 14, 2024
It takes a hacker to defeat a hacker.
By Robert Joyce April 6, 2024
Report on the Microsoft Online Exchange Incident from Summer 2023.
By Robert Joyce September 6, 2023
Criminal threats to industry are significant and continue to grow