figma guide

Designing breach media relations and press statement UI in Figma: approved quotes, embargo workflow, and FAQ sync

Design breach media relations and press statement UI in Figma with versioned press kits, embargo controls, spokesperson scripts, journalist FAQ sync, and handoff for comms and legal teams.

Published
Updated
Aug 21, 2026
Read time
8 min
Level
Intermediate

Quick answer

Breach media relations and press statement UI keeps external comms aligned with legal-approved facts when journalists, regulators, and social channels amplify a privacy incident—without ad hoc quotes or contradictory narratives. Design a versioned press kit synced to notice FAQ NL-* versions, embargo and hold-for-release controls, spokesperson scripts with approved quotes only, and media inquiry triage linked to call center scripts and war room status. Connect to individual notification, regulatory archive, status page, and trust center. Start from the Figma guides hub and pair with Dev Mode handoff.


Who this is for

  • Product designers building internal comms tooling—not generic CMS pages—for regulated incident response.
  • Corporate communications and PR teams who need one press kit version stamped to each public disclosure wave.
  • Legal and privacy counsel who must approve every external quote before it reaches journalists or social posts.

Press kit workspace and statement versioning

PressKitWorkspace — Incident VIN-992 · Press kit PK-992-v2 · Synced to FAQ NL-992-v3
├── Header: Incident reference (public-safe) · Embargo until 2026-08-26 14:00 UTC · Status: Approved / Hold / Live
├── Core assets:
│   ├── Press statement (short) — 3–5 paragraphs · Plain language · No forensic detail
│   ├── Press statement (long) — Background, timeline (public-safe), remediation summary
│   ├── Approved quotes — Named spokesperson only · Max 2 quotes per version
│   ├── Fact sheet — Bullets: what happened, data categories, affected geographies, actions taken
│   ├── FAQ for journalists — Extends [notice FAQ](/designing-breach-faq-and-notice-landing-page-ui-in-figma/) with media-specific Q&A
│   └── Boilerplate — Company description · Privacy contact · Trust center link
├── Embargo controls:
│   ├── Hold for release datetime · Timezone-aware
│   ├── Distribution list: wire services, key outlets, investor relations
│   └── Unlock requires: Legal ✓ · Comms ✓ · CEO office ✓ (configurable)
├── Version history:
│   ├── v1 — Initial embargo draft with IND-441 timing
│   ├── v2 — Updated affected count range after forensic confirmation · Current approved
│   └── Changelog row per version · Snapshot hash for [regulatory archive](/designing-regulatory-authority-correspondence-and-breach-filing-archive-ui-in-figma/)
└── Sync indicator: PK-992-v2 ↔ NL-992-v3 · Warning if FAQ material change pending press refresh
ElementPurpose
Embargo datetimePrevents premature release before individual notification or regulatory filing window
Approved quotes blockSpokesperson cannot ad lib beyond pre-cleared sentences
Fact sheet vs statementReporters get scannable bullets; statement carries narrative
Journalist FAQAnswers “how many affected?” without exposing exact forensic counts in headline

Verdict: Press kit UI is the external voice control plane—if comms edits Word docs outside the versioned system, journalists will cite stale numbers within hours.


Spokesperson script and interview guardrails

SpokespersonScriptPanel — PK-992-v2 · Interview mode · Read-only approved content
├── Opening framing:
│   ├── Acknowledge concern · Express commitment to transparency
│   └── Redirect to fact sheet for numbers · Do not speculate on attribution
├── Approved talking points (from FAQ v3):
│   ├── What happened — Category-level data description only
│   ├── What we are doing — Mitigation customers can understand
│   └── What affected individuals should do — Link to [notice landing page](/designing-breach-faq-and-notice-landing-page-ui-in-figma/)
├── Bridge phrases (when question is out of scope):
│   ├── "That detail is part of our ongoing investigation"
│   ├── "We have published our latest information at [canonical notice URL]"
│   └── "I cannot comment on individual accounts"
├── Forbidden topics (red banner):
│   ├── Exact attacker TTPs · Unpatched vulnerability names
│   ├── Individual victim names or sample records
│   ├── Litigation strategy · Insurance coverage
│   └── Speculative breach scope beyond approved range
├── Escalation:
│   ├── Legal on-air flag → Mute · Counsel join line
│   ├── Regulator question → Route to [regulatory correspondence](/designing-regulatory-authority-correspondence-and-breach-filing-archive-ui-in-figma/)
│   └── Media inquiry logged → [Privacy queue](/designing-privacy-request-queue-and-case-management-ui-in-figma/) tag MEDIA-*
└── Post-interview: Log outlet, journalist, quotes used, PK version cited

Design interview mode as a simplified, large-type view—spokespersons should not hunt through a 12-tab admin console on live TV.


Media inquiry intake and triage

MediaInquiryInbox — VIN-992 · 34 open · SLA: respond within 4h (business hours)
├── Intake form (public + internal):
│   ├── Outlet · Journalist · Deadline · Story angle
│   ├── Questions submitted (free text) · Attachment upload (press credential)
│   └── Preferred response channel: email · phone · on-record / background
├── Triage lanes:
│   ├── Tier A — National wire / tier-1 tech press → Comms lead + legal review
│   ├── Tier B — Regional / trade → Standard template from PK-992-v2
│   ├── Tier C — Duplicate / already answered → Auto-link to notice FAQ
│   └── Tier D — Sensitive (litigation, regulator leak) → Legal hold · No auto-reply
├── Response builder:
│   ├── Insert approved blocks from press kit · No free-form body without approval
│   ├── Attach fact sheet PDF (tagged, accessible)
│   └── CC [war room](/designing-security-operations-shift-handover-and-war-room-ui-in-figma/) comms channel on Tier A only
├── Linkage:
│   ├── Same FAQ index as [call center script](/designing-breach-call-center-and-agent-script-ui-in-figma/)
│   └── Status page cross-check — no contradiction with [customer status UI](/designing-customer-incident-status-page-and-communication-ui-in-figma/)
└── Audit: inquiry_id · pk_version · responder · approval_chain[] · sent_at
PatternBest forSkip when
Template-first responsesHigh volume after mass notificationInvestigative piece requiring bespoke legal review
Embargoed pre-briefCoordinated disclosure with key outletsJurisdiction requires simultaneous public notice first
No-comment defaultActive law enforcement involvementNever leave Tier A inquiries unanswered past SLA

Publish workflow and channel coordination

PressPublishWorkflow — PK-992-v2 · Embargo lift 2026-08-26 14:00 UTC
├── Pre-lift gates:
│   ├── ☐ [Individual notification](/designing-affected-individual-breach-notification-and-communication-ui-in-figma/) IND-441 sent or scheduled
│   ├── ☐ [Notice landing page](/designing-breach-faq-and-notice-landing-page-ui-in-figma/) NL-992-v3 live at public URL
│   ├── ☐ [Status page](/designing-customer-incident-status-page-and-communication-ui-in-figma/) reviewed — service vs data breach separation
│   ├── ☐ Regulatory filing window respected (if applicable)
│   └── ☐ Social copy variants approved (character limits per platform)
├── Lift actions:
│   ├── Release press kit to distribution list · Stamp PK-992-v2 live
│   ├── Push approved social posts from linked variants
│   └── Export snapshot to [regulatory archive](/designing-regulatory-authority-correspondence-and-breach-filing-archive-ui-in-figma/) FIL-883 bundle
├── Post-lift updates:
│   ├── Material fact change → PK-992-v3 · Issue correction notice template
│   └── Retire kit → Archive PDF on [trust center](/designing-trust-center-and-security-documentation-ui-in-figma/)
└── Metrics (aggregate): inquiries by tier · response SLA · quotes cited in coverage (manual tag)

Verdict: Coordinate press lift with individual notice timing—announcing to journalists before affected people receive email destroys trust and may violate regulatory sequencing in some jurisdictions.


Comparison: press kit vs adjacent surfaces

SurfaceFocusThis UI adds
Notice FAQAffected individualsJournalist-oriented fact sheet, embargo, quotes
Call center scriptsVoice supportExternal narrative control, media inquiry triage
Status pageService uptimeData breach story for press, not component health
Regulatory archiveAuthority correspondencePress kit snapshots as disclosure evidence
War roomInternal coordinationEmbargo clock, Tier A inquiry alerts

Handoff checklist (Dev Mode)

  • PressKit — incident_id, pk_version_id (PK-), embargo_until, status, linked_faq_version_id (NL-), published_at.
  • PressStatement — variant (short, long), body_richtext, locale, approval_chain[].
  • ApprovedQuote — spokesperson_name, quote_text, pk_version_id, sort_order.
  • FactSheet — bullets[], affected_count_range, geography[], data_categories[].
  • MediaInquiry — inquiry_id, tier, deadline, status, pk_version_used, response_template_id.
  • EmbargoRelease — pk_version_id, lift_at, distribution_list[], unlock_approvals[].
  • SocialVariant — platform, character_limit, body, link_to_notice_url, pk_version_id.

Common mistakes

MistakeWhy it hurtsFix
Press release ahead of individual noticeVictims learn from news, not youEmbargo gates tied to IND-* schedule
Exact victim count in headlineRe-traumatizes; may be wrongPublish ranges until forensic sign-off
Spokesperson improvises scopeLegal exposure; contradicts FAQRead-only approved quotes
Separate Word press kit from FAQDrift within hoursPK-* synced to NL-* version
Status page language in press statementConflates outage with data breachSeparate templates and reviewers
Auto-reply with investigation detailHelps attackersTemplate blocks from approved kit only
No media inquiry audit trailCannot prove what was told to pressLog inquiry_id, pk_version, responder
Social posts without version stampCannot retract coordinated messageLink social variants to PK-*

  1. Draft press kit v1 after privacy triage confirms external disclosure is likely.
  2. Sync fact sheet bullets to notice FAQ blocks—single source of truth for numbers and data categories.
  3. Run legal and comms approval on quotes, embargo datetime, and journalist FAQ.
  4. Schedule embargo lift after or simultaneous with individual notification per jurisdiction playbook.
  5. Train spokesperson on script panel and forbidden topics before first Tier A interview.
  6. Archive PK- snapshot* to regulatory correspondence and monitor inquiry themes for FAQ updates.

FAQ

Should we hold a press conference UI in the same kit?

Optional. Add a live briefing mode with the same read-only talking points and a timer—do not create a separate unversioned slide deck.

Can we give journalists exclusive numbers?

Only if legal approves a range or statistic in PK-* and the exclusive is logged in the inquiry audit trail.

How do we handle leaked breach news?

Open crisis lane: shorten approval path for PK-* correction, prioritize notice page update, and log all outbound media responses under incident VIN-*.

Background vs on-record in the UI?

Tag each response template with attribution level—agents and spokespeople must select before send; default to on-record for written email.

What about social media employee posts?

Link employee comms hold banner to war room status—outside press kit, but embargo workflow should block internal social until PK-* lift.


Next steps

Share on X

§ Keep reading

Related guides.