YUDU Sentinel Blog

Questions Boards Should Ask the CISO about Out-of-Band Communications

Written by Edward Jones | 20 Aug 2026

When a major cyberattack takes systems offline, the board needs to know more than whether those systems can be recovered.

Can the organisation still communicate, coordinate and lead while they are unavailable?

Ransomware can disrupt email, Microsoft Teams, corporate networks, identity services and shared documents simultaneously. If crisis communications depend on those same systems, the people responsible for managing the incident may lose the ability to communicate when they need it most.

That is where out-of-band communications becomes critical.

But having a crisis communications platform isn't enough. Boards should ask their CISO whether it would still work when the organisation's primary technology environment doesn't.

Here are eight questions to ask.

1. What happens to our crisis communications if Microsoft 365 is unavailable?

Many organisations have built their day-to-day communications around Microsoft 365. Email, Teams, SharePoint and identity services can sit at the centre of normal operations.

That is perfectly reasonable for everyday business.

The problem arises when those same dependencies become part of the crisis communications chain.

If Microsoft 365 is unavailable because of a ransomware attack, service outage or compromised identity environment, can the crisis team still communicate?

The question isn't simply whether the organisation has a separate crisis platform. It is whether that platform is genuinely independent of the systems most likely to be affected by the incident.

Boards should ask their CISO to map the dependencies.

Does the crisis platform rely on:

  • Microsoft 365 or another corporate productivity suite?
  • Corporate email?
  • Teams or another collaboration platform?
  • The corporate network?
  • Corporate identity and single sign-on?
  • Internal DNS or other infrastructure?
  • Devices that may themselves be unavailable?

If several of these dependencies exist, the organisation may have a crisis communications platform without having true out-of-band resilience.

The board question: If our primary IT environment went offline tomorrow, what communication capability would remain?

2. Can we still authenticate if our corporate identity system is compromised?

Identity is an often-overlooked dependency in crisis communications.

Single sign-on is convenient. It reduces passwords, simplifies administration and improves the everyday user experience.

But resilience requires a different question: what happens when the identity provider itself is unavailable or compromised?

If access to the crisis communications platform depends entirely on corporate credentials or SSO through the organisation's identity environment, a cyberattack against that environment could potentially prevent the crisis team from accessing the very system they need to manage the incident.

Boards should therefore ask:

  • Can authorised users access the crisis platform independently of corporate SSO?
  • What happens if the organisation's identity provider is unavailable?
  • What happens if corporate credentials have been compromised?
  • Are emergency access arrangements already established?
  • Have those arrangements actually been tested?

This isn't an argument against SSO for normal business applications. It is a recognition that the system controlling access to your crisis communications capability should not become a single point of failure during an identity incident.

For a genuinely out-of-band capability, independent authentication and access arrangements are an important part of the resilience model.

The board question: If our corporate identity system was compromised, could our crisis team still securely access its communications environment?

3. Can we communicate if email and Teams are down?

A crisis communications strategy ultimately has to answer a simple question:

How do we contact people when our normal communications channels don't work?

Email may be unavailable. Teams may be unavailable. Corporate phones may be affected. Users may be unable to authenticate to normal business applications.

An out-of-band capability should provide alternative routes to communicate, potentially including SMS, voice, mobile applications and independent web access.

It should also support two-way communication where the situation requires it.

This matters because crisis communications isn't simply about sending an instruction.

Leadership may need to:

  • alert key personnel;
  • establish a crisis team;
  • request status updates;
  • coordinate technical and operational teams;
  • communicate with staff;
  • issue instructions;
  • receive responses;
  • escalate an incident;
  • communicate with people outside the affected environment.

The board should therefore look beyond whether an organisation can send an emergency notification.

It should ask whether it can continue a conversation and coordinate a response.

The board question: If email and Teams disappeared during an incident, what independent channels would our crisis team use to communicate?

4. Who can communicate with whom?

A crisis doesn't necessarily involve the entire organisation.

Different incidents require different groups of people to work together. The executive team may need a private channel. IT and security may need their own operational workspace. Business continuity teams may need to coordinate with facilities or regional teams.

This makes segmentation an important part of crisis communications.

A platform that simply creates one large emergency group may not provide the control required during a complex incident.

Boards should ask whether the organisation can establish separate, controlled communications environments around different:

  • incidents;
  • business functions;
  • workstreams;
  • locations;
  • leadership groups;
  • response teams.

This is particularly important where sensitive information is being discussed.

Sentinel Spaces are designed to provide segregated environments for different crisis teams and workstreams, allowing organisations to control who has access to particular communications and information.

The principle is straightforward:

Out-of-band should not mean uncontrolled.

The organisation needs a communications capability that remains available outside its primary environment while still maintaining appropriate security and access control.

The board question: Can we control exactly who communicates with whom during a crisis, without relying on our normal corporate collaboration environment?

5. Can we access critical information when our normal systems are unavailable?

Communication is only part of crisis management.

People also need information to make decisions.

If a ransomware attack takes shared drives, SharePoint, document management systems or other corporate repositories offline, can the crisis team still access the information it needs?

Consider the documents that might be required during the first few hours of an incident:

  • business continuity plans;
  • crisis management plans;
  • emergency contact information;
  • recovery procedures;
  • site information;
  • technical recovery documentation;
  • supplier and third-party contacts;
  • escalation procedures;
  • decision-making authorities.

If those documents are stored only within the corporate environment, they may be inaccessible precisely when they are needed most.

An out-of-band communications environment can therefore provide more than an alternative messaging channel. It can provide an independent location for critical crisis information and documents.

The board should also consider access controls. Making everything available to everyone isn't resilience; it is a security problem.

The objective is to make the right information available to the right people at the right time, independently of the systems affected by the incident.

The board question: If our normal document repositories were unavailable, could the crisis team still access the information required to make decisions and coordinate recovery?

6. Can leadership establish a secure crisis room remotely?

Major incidents increasingly require distributed decision-making.

Executives may be in different locations. Crisis managers may be working remotely. Technical teams may be operating from recovery sites. External specialists may need to join the response.

Under normal circumstances, Microsoft Teams or another corporate collaboration platform may provide the meeting environment.

But what happens when that environment is unavailable?

Boards should ask whether leadership has an independent means of establishing a secure crisis meeting.

That means looking beyond simply having a video conferencing capability.

Consider whether the organisation can:

  • establish a crisis meeting independently;
  • authenticate participants securely;
  • restrict access to authorised attendees;
  • share information;
  • coordinate decisions;
  • communicate with multiple response teams;
  • retain an appropriate audit record.

The distinction matters.

A general-purpose video conferencing service may allow people to hold a meeting. A dedicated crisis environment can provide a controlled space for incident decision-making, integrated with the wider crisis communications capability.

This becomes particularly important when the incident itself affects the organisation's ability to trust its normal technology environment.

The board question: If Teams was unavailable or compromised, where would our executive team meet securely to make critical decisions?

7. How quickly can we switch to out-of-band communications?

Resilience is partly about technology, but it is also about readiness.

A crisis communications platform that technically exists but requires significant configuration before it can be used isn't providing the same level of resilience as a capability that is already established and tested.

Boards should ask:

  • Are users already provisioned?
  • Are critical contact groups already configured?
  • Are crisis spaces already established?
  • Are key documents already available?
  • Are alternative communication channels ready?
  • Do crisis teams know how to access them?
  • Can communications be initiated immediately?
  • Has the process been exercised?

The first minutes of a major incident are rarely the time to start building the response environment.

The organisation should already know who needs to communicate, how they will access the platform and which channels they will use.

This is why out-of-band communications should be treated as an operational capability rather than an emergency purchase.

It needs to exist before the incident. It needs to be understood before the incident. And, most importantly, it needs to be tested before the incident.

The board question: How quickly could we move our crisis communications out of the affected environment — and have we proved it?

8. When was it last tested under realistic conditions?

This may be the most important question of all.

It isn't enough to demonstrate that the platform works when everything else is working. The organisation needs to understand what happens when its normal technology environment doesn't.

A meaningful exercise should simulate the conditions under which out-of-band communications are actually required.

For example:

  • What happens if Microsoft 365 is unavailable?
  • What happens if corporate email is unavailable?
  • What happens if Teams is unavailable?
  • What happens if the corporate identity provider is compromised?
  • What happens if users cannot access the corporate network?

Then test the response:

  • Can the board and executive team communicate?
  • Can the crisis team be assembled?
  • Can IT and security coordinate?
  • Can critical documents be accessed?
  • Can secure meetings be established?
  • Can notifications be sent?
  • Can recipients respond?
  • Can the organisation maintain an auditable record of its actions?

Testing under these conditions exposes dependencies that may otherwise remain invisible.

It also changes the conversation from “we have a crisis communications system” to “we have demonstrated that our crisis communications capability remains operational when our primary systems are unavailable.”

That is a much stronger position for a board to take.

What should the board expect from the CISO?

These eight questions shouldn't be treated as a technology checklist. They are really questions about organisational resilience. A robust out-of-band communications capability should demonstrate six characteristics.

Independence

It should not depend on the same infrastructure, identity systems or collaboration tools that may be affected by the incident.

Accessibility

Authorised users should have a reliable way to access it even when corporate systems are unavailable.

Segmentation

Different crisis teams and workstreams should be able to communicate securely without creating unnecessary exposure.

Speed

The capability should be ready before the incident, with users, groups, channels and critical information already established.

Security

Operating outside the corporate environment shouldn't mean compromising security or access control.

Evidence

The organisation should be able to demonstrate that its communications capability has been tested under realistic failure conditions.

These are the characteristics that turn an alternative communications channel into a genuine resilience capability.

The board's final question

Boards don't need to become experts in crisis communications technology. But they do need to challenge the assumptions behind their organisation's crisis response.

The most important question may therefore be the simplest:

If our primary technology environment failed today, could our leadership team still communicate, coordinate and make decisions?

Don't ask your CISO simply whether the organisation has a crisis communications platform.

Ask them to demonstrate that it still works when the systems the organisation normally relies on do not.

That is the real test of out-of-band resilience.

How YUDU Sentinel supports out-of-band crisis communications

YUDU Sentinel provides an independent communications environment designed to keep crisis teams connected when primary corporate systems are unavailable or compromised.

Sentinel brings together secure crisis spaces, messaging, mass notification, voice communications, critical document access and secure video conferencing within a dedicated resilience platform.

The objective is simple:

When your network goes down, your crisis response doesn't have to.

Explore YUDU Sentinel