Why this conversation goes wrong so often
Two failure modes show up constantly:
- Too technical. "We found a webshell injected via an outdated plugin's file upload vulnerability, remediated the compromised files, and rotated credentials." Accurate, and completely useless to someone who just wants to know if their business is okay.
- Too vague. "Everything's fixed, don't worry about it." This reads as either dismissive or like you're hiding something.
The right version sits in between: plain language, honest about what happened, clear about what you did, and specific about what they need to know going forward.
The structure that actually works
1. What happened (one sentence, no jargon). "A vulnerability in an older version of one of your plugins let someone add hidden code to your site." Not the CVE number. Not the file path.
2. What that code was actually doing. Translate the technical impact into business terms. "It was quietly redirecting some visitors to a spam site" lands. "It exploited a stored XSS vulnerability" does not.
3. What you did about it. A short list: found it, removed it, checked for anything else, updated the vulnerable plugin, tightened access. Confidence here matters — this is the part that rebuilds trust.
4. What it means for them, concretely. Was any customer data involved? Was checkout affected? Answer this directly — don't make them ask.
5. What's different going forward. One or two concrete changes that make this specific type of incident less likely to recur. This is what turns an incident into a reason to trust you more, not less.
Forwardable client report template
Copy this, fill in the brackets, and send as-is or adapt to your own letterhead:
SubjectSecurity Update — [Site Name]
Hi [Client Name],
I want to give you a clear, complete update on a security issue we found and resolved on [Site Name].
What happened: [One plain-language sentence — e.g., "An outdated plugin had a known security weakness that allowed unauthorized code to be added to the site."]
What it did: [One or two sentences on the actual impact — e.g., "This code was redirecting a portion of your visitors to an unrelated website. It did not affect your database or customer information."]
What we did:
— Identified and removed the unauthorized code
— Updated [plugin/theme name] to the current, secure version
— Checked the rest of the site for similar issues — none found
— [Any additional step taken, e.g., rotated admin passwords]
Was any of your data affected? [Direct answer — yes/no, and specifics if relevant.]
What we're doing to prevent this going forward: [e.g., "We've added automated monitoring that will alert us immediately if something like this happens again, rather than relying on discovering it manually."]
If you have any questions at all, I'm happy to walk through any part of this in more detail.
[Your name]
A note on timing
Send this as soon as you have real answers, not the moment you notice something's wrong. A client who hears "we found something, we're investigating, full update by end of day" and then gets the report above a few hours later trusts you more than one who gets silence followed by a vague "it's handled" days later.
Get findings explained in plain language automatically, so you're not translating from scratch every time.
Install free →