figma guide
Designing breach media relations and press statement UI in Figma: approved quotes, embargo workflow, and FAQ sync
Design breach media relations and press statement UI in Figma with versioned press kits, embargo controls, spokesperson scripts, journalist FAQ sync, and handoff for comms and legal teams.
- Published
- Updated
- Aug 21, 2026
- Read time
- 8 min
- Level
- Intermediate
Quick answer
Breach media relations and press statement UI keeps external comms aligned with legal-approved facts when journalists, regulators, and social channels amplify a privacy incident—without ad hoc quotes or contradictory narratives. Design a versioned press kit synced to notice FAQ NL-* versions, embargo and hold-for-release controls, spokesperson scripts with approved quotes only, and media inquiry triage linked to call center scripts and war room status. Connect to individual notification, regulatory archive, status page, and trust center. Start from the Figma guides hub and pair with Dev Mode handoff.
Who this is for
- Product designers building internal comms tooling—not generic CMS pages—for regulated incident response.
- Corporate communications and PR teams who need one press kit version stamped to each public disclosure wave.
- Legal and privacy counsel who must approve every external quote before it reaches journalists or social posts.
Press kit workspace and statement versioning
PressKitWorkspace — Incident VIN-992 · Press kit PK-992-v2 · Synced to FAQ NL-992-v3
├── Header: Incident reference (public-safe) · Embargo until 2026-08-26 14:00 UTC · Status: Approved / Hold / Live
├── Core assets:
│ ├── Press statement (short) — 3–5 paragraphs · Plain language · No forensic detail
│ ├── Press statement (long) — Background, timeline (public-safe), remediation summary
│ ├── Approved quotes — Named spokesperson only · Max 2 quotes per version
│ ├── Fact sheet — Bullets: what happened, data categories, affected geographies, actions taken
│ ├── FAQ for journalists — Extends [notice FAQ](/designing-breach-faq-and-notice-landing-page-ui-in-figma/) with media-specific Q&A
│ └── Boilerplate — Company description · Privacy contact · Trust center link
├── Embargo controls:
│ ├── Hold for release datetime · Timezone-aware
│ ├── Distribution list: wire services, key outlets, investor relations
│ └── Unlock requires: Legal ✓ · Comms ✓ · CEO office ✓ (configurable)
├── Version history:
│ ├── v1 — Initial embargo draft with IND-441 timing
│ ├── v2 — Updated affected count range after forensic confirmation · Current approved
│ └── Changelog row per version · Snapshot hash for [regulatory archive](/designing-regulatory-authority-correspondence-and-breach-filing-archive-ui-in-figma/)
└── Sync indicator: PK-992-v2 ↔ NL-992-v3 · Warning if FAQ material change pending press refresh
| Element | Purpose |
|---|---|
| Embargo datetime | Prevents premature release before individual notification or regulatory filing window |
| Approved quotes block | Spokesperson cannot ad lib beyond pre-cleared sentences |
| Fact sheet vs statement | Reporters get scannable bullets; statement carries narrative |
| Journalist FAQ | Answers “how many affected?” without exposing exact forensic counts in headline |
Verdict: Press kit UI is the external voice control plane—if comms edits Word docs outside the versioned system, journalists will cite stale numbers within hours.
Spokesperson script and interview guardrails
SpokespersonScriptPanel — PK-992-v2 · Interview mode · Read-only approved content
├── Opening framing:
│ ├── Acknowledge concern · Express commitment to transparency
│ └── Redirect to fact sheet for numbers · Do not speculate on attribution
├── Approved talking points (from FAQ v3):
│ ├── What happened — Category-level data description only
│ ├── What we are doing — Mitigation customers can understand
│ └── What affected individuals should do — Link to [notice landing page](/designing-breach-faq-and-notice-landing-page-ui-in-figma/)
├── Bridge phrases (when question is out of scope):
│ ├── "That detail is part of our ongoing investigation"
│ ├── "We have published our latest information at [canonical notice URL]"
│ └── "I cannot comment on individual accounts"
├── Forbidden topics (red banner):
│ ├── Exact attacker TTPs · Unpatched vulnerability names
│ ├── Individual victim names or sample records
│ ├── Litigation strategy · Insurance coverage
│ └── Speculative breach scope beyond approved range
├── Escalation:
│ ├── Legal on-air flag → Mute · Counsel join line
│ ├── Regulator question → Route to [regulatory correspondence](/designing-regulatory-authority-correspondence-and-breach-filing-archive-ui-in-figma/)
│ └── Media inquiry logged → [Privacy queue](/designing-privacy-request-queue-and-case-management-ui-in-figma/) tag MEDIA-*
└── Post-interview: Log outlet, journalist, quotes used, PK version cited
Design interview mode as a simplified, large-type view—spokespersons should not hunt through a 12-tab admin console on live TV.
Media inquiry intake and triage
MediaInquiryInbox — VIN-992 · 34 open · SLA: respond within 4h (business hours)
├── Intake form (public + internal):
│ ├── Outlet · Journalist · Deadline · Story angle
│ ├── Questions submitted (free text) · Attachment upload (press credential)
│ └── Preferred response channel: email · phone · on-record / background
├── Triage lanes:
│ ├── Tier A — National wire / tier-1 tech press → Comms lead + legal review
│ ├── Tier B — Regional / trade → Standard template from PK-992-v2
│ ├── Tier C — Duplicate / already answered → Auto-link to notice FAQ
│ └── Tier D — Sensitive (litigation, regulator leak) → Legal hold · No auto-reply
├── Response builder:
│ ├── Insert approved blocks from press kit · No free-form body without approval
│ ├── Attach fact sheet PDF (tagged, accessible)
│ └── CC [war room](/designing-security-operations-shift-handover-and-war-room-ui-in-figma/) comms channel on Tier A only
├── Linkage:
│ ├── Same FAQ index as [call center script](/designing-breach-call-center-and-agent-script-ui-in-figma/)
│ └── Status page cross-check — no contradiction with [customer status UI](/designing-customer-incident-status-page-and-communication-ui-in-figma/)
└── Audit: inquiry_id · pk_version · responder · approval_chain[] · sent_at
| Pattern | Best for | Skip when |
|---|---|---|
| Template-first responses | High volume after mass notification | Investigative piece requiring bespoke legal review |
| Embargoed pre-brief | Coordinated disclosure with key outlets | Jurisdiction requires simultaneous public notice first |
| No-comment default | Active law enforcement involvement | Never leave Tier A inquiries unanswered past SLA |
Publish workflow and channel coordination
PressPublishWorkflow — PK-992-v2 · Embargo lift 2026-08-26 14:00 UTC
├── Pre-lift gates:
│ ├── ☐ [Individual notification](/designing-affected-individual-breach-notification-and-communication-ui-in-figma/) IND-441 sent or scheduled
│ ├── ☐ [Notice landing page](/designing-breach-faq-and-notice-landing-page-ui-in-figma/) NL-992-v3 live at public URL
│ ├── ☐ [Status page](/designing-customer-incident-status-page-and-communication-ui-in-figma/) reviewed — service vs data breach separation
│ ├── ☐ Regulatory filing window respected (if applicable)
│ └── ☐ Social copy variants approved (character limits per platform)
├── Lift actions:
│ ├── Release press kit to distribution list · Stamp PK-992-v2 live
│ ├── Push approved social posts from linked variants
│ └── Export snapshot to [regulatory archive](/designing-regulatory-authority-correspondence-and-breach-filing-archive-ui-in-figma/) FIL-883 bundle
├── Post-lift updates:
│ ├── Material fact change → PK-992-v3 · Issue correction notice template
│ └── Retire kit → Archive PDF on [trust center](/designing-trust-center-and-security-documentation-ui-in-figma/)
└── Metrics (aggregate): inquiries by tier · response SLA · quotes cited in coverage (manual tag)
Verdict: Coordinate press lift with individual notice timing—announcing to journalists before affected people receive email destroys trust and may violate regulatory sequencing in some jurisdictions.
Comparison: press kit vs adjacent surfaces
| Surface | Focus | This UI adds |
|---|---|---|
| Notice FAQ | Affected individuals | Journalist-oriented fact sheet, embargo, quotes |
| Call center scripts | Voice support | External narrative control, media inquiry triage |
| Status page | Service uptime | Data breach story for press, not component health |
| Regulatory archive | Authority correspondence | Press kit snapshots as disclosure evidence |
| War room | Internal coordination | Embargo clock, Tier A inquiry alerts |
Handoff checklist (Dev Mode)
- PressKit — incident_id, pk_version_id (PK-), embargo_until, status, linked_faq_version_id (NL-), published_at.
- PressStatement — variant (short, long), body_richtext, locale, approval_chain[].
- ApprovedQuote — spokesperson_name, quote_text, pk_version_id, sort_order.
- FactSheet — bullets[], affected_count_range, geography[], data_categories[].
- MediaInquiry — inquiry_id, tier, deadline, status, pk_version_used, response_template_id.
- EmbargoRelease — pk_version_id, lift_at, distribution_list[], unlock_approvals[].
- SocialVariant — platform, character_limit, body, link_to_notice_url, pk_version_id.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Press release ahead of individual notice | Victims learn from news, not you | Embargo gates tied to IND-* schedule |
| Exact victim count in headline | Re-traumatizes; may be wrong | Publish ranges until forensic sign-off |
| Spokesperson improvises scope | Legal exposure; contradicts FAQ | Read-only approved quotes |
| Separate Word press kit from FAQ | Drift within hours | PK-* synced to NL-* version |
| Status page language in press statement | Conflates outage with data breach | Separate templates and reviewers |
| Auto-reply with investigation detail | Helps attackers | Template blocks from approved kit only |
| No media inquiry audit trail | Cannot prove what was told to press | Log inquiry_id, pk_version, responder |
| Social posts without version stamp | Cannot retract coordinated message | Link social variants to PK-* |
Recommended workflow
- Draft press kit v1 after privacy triage confirms external disclosure is likely.
- Sync fact sheet bullets to notice FAQ blocks—single source of truth for numbers and data categories.
- Run legal and comms approval on quotes, embargo datetime, and journalist FAQ.
- Schedule embargo lift after or simultaneous with individual notification per jurisdiction playbook.
- Train spokesperson on script panel and forbidden topics before first Tier A interview.
- Archive PK- snapshot* to regulatory correspondence and monitor inquiry themes for FAQ updates.
FAQ
Should we hold a press conference UI in the same kit?
Optional. Add a live briefing mode with the same read-only talking points and a timer—do not create a separate unversioned slide deck.
Can we give journalists exclusive numbers?
Only if legal approves a range or statistic in PK-* and the exclusive is logged in the inquiry audit trail.
How do we handle leaked breach news?
Open crisis lane: shorten approval path for PK-* correction, prioritize notice page update, and log all outbound media responses under incident VIN-*.
Background vs on-record in the UI?
Tag each response template with attribution level—agents and spokespeople must select before send; default to on-record for written email.
What about social media employee posts?
Link employee comms hold banner to war room status—outside press kit, but embargo workflow should block internal social until PK-* lift.
Next steps
- Design breach FAQ and notice landing page UI in Figma — canonical public text press kit syncs to
- Design breach call center and agent script UI in Figma — shared FAQ index for media and voice
- Design affected individual breach notification and communication UI in Figma — coordinate timing with embargo lift
- Design regulatory authority correspondence and breach filing archive UI in Figma — archive PK-* with FIL-* threads
- Design customer incident status page and communication UI in Figma — separate service impact from data breach narrative
§ Keep reading