Cosmonova's Kyiv data center was hit by a drone strike on 25 September, knocking its services offline and disrupting TV broadcasts and internet access for subscribers.24 The company has stated the data center will no longer operate, customer data is preserved via redundancy, and restoration will require substantial time.19 The disruption is severe, affecting public broadcaster video players and Starlink support, but the exact cause and subscriber impact remain unconfirmed.3578 This is a victim crisis—the company is a casualty of an external attack—requiring a posture that acknowledges the harm while defending its resilience and recovery.24 The brand must rebuild trust by taking responsibility for the restoration timeline, communicating transparently about progress, and compensating affected customers.679
THREATProlonged service disruption erodes customer trust and may trigger contractual penalties or regulator scrutiny.679
THREATInadequate communication about restoration timeline fuels speculation and damages brand reputation as unreliable.79
OPPORTUNITYDemonstrating robust geographic redundancy and transparent recovery can strengthen customer loyalty and industry standing.1
Best response strategy
REBUILD The strike is an external attack the company could not prevent, making this a victim crisis where stakeholders assign no duty-of-care failure.24 However, the severe disruption and lack of restoration timeline create a duty to rebuild trust through transparent communication and corrective action.79 The company's early statement on data preservation sets a foundation for focusing on recovery rather than defensiveness.1
Who is watching, and what each expects from the response:
customersService disruption, data safety, and when connectivity will be restored.679
mediaReporting on the severity of the outage, its impact on broadcasts and internet access, and Cosmonova's response.3
publicRelying on Cosmonova-supported services (Starlink, public broadcaster video) for information and connectivity.35
regulatorMonitoring the incident's impact on critical communications infrastructure and data protection.4
Suggested response plan
T+0-4h
Phase 1 — Contain & verify
Outcome: All internal comms are frozen, a single source of truth is established, and a holding statement is ready for publication.127
comms
The comms lead convenes the crisis team, confirms the latest service-impact assessment with operations, and drafts a holding statement acknowledging the incident, confirming data safety via redundancy, and promising a restoration timeline within 24 hours.
Freeze all external social media and support-channel posts.
Brief customer-support teams with a script acknowledging the outage and directing inquiries to the upcoming statement.
Prepare a regulator notification outlining the incident and preservation of customer data.
Done when: No uncoordinated external comms have gone out in 2 hours, and the holding statement is approved and loaded.
T+4-12h
Phase 2 — Respond
Outcome: The public statement is live, customers and the regulator are directly notified, and media inquiries are routed to a single spokesperson.134
comms
The comms lead publishes the statement on the website and social media, emails affected enterprise customers directly, and notifies the regulator via formal letter.
Publish the statement on the company website and all social channels.
Send a direct email to enterprise customers with the statement and a dedicated contact for urgent issues.
Submit the regulator notification letter and confirm receipt.
Brief a designated spokesperson and respond to all media inquiries with the statement.
Done when: The statement is live on the website and social channels, enterprise email is sent, and regulator acknowledgement is received.
“Our Kyiv data center was damaged on 25 September, disrupting services for some customers.2 Customer data remains safe, preserved through our geographic redundancy system.1 We are working to restore services as quickly as possible and will provide a restoration timeline within 24 hours.7 We apologize for the disruption and are committed to keeping you updated on our progress.9” website statementdirect outreachsocial media
T+1-3 days
Phase 3 — Manage
Outcome: Restoration progress is communicated daily, customer compensation is outlined, and media coverage shifts from the outage to the recovery effort.679
operations
The operations lead provides daily restoration updates to comms, which publishes them via a dedicated outage page and social media, and customer support rolls out a compensation policy for affected subscribers.
Provide comms with a daily 9 a.m. update on restoration progress, areas back online, and estimated time for remaining services.
Update the website outage page with the latest restoration map and timeline.
Deploy a customer-support script outlining compensation (e.g., service credits) for disrupted subscribers.
Pitch a follow-up story to trade media on the redundancy system that preserved customer data.
Done when: No new media outlet is reporting on the outage without also noting the restoration progress, and customer inquiries about compensation drop by 50%.
T+2-4 weeks
Phase 4 — Recover
Outcome: The incident is closed with a published post-mortem, customer trust is rebuilt through transparency, and the brand's resilience story is institutionalized.1
executive
The executive team approves and publishes a post-mortem report on the incident, launches a case study on geographic redundancy for sales enablement, and hosts a webinar for customers on lessons learned.
Finalize and publish a post-mortem report on the website detailing the incident, response, and improvements.
Create a sales-enablement case study highlighting how redundancy protected customer data.
Host a customer webinar with the CTO discussing the recovery and future resilience investments.
Done when: The post-mortem is published and cited in two trade articles, and the case study is used in three sales conversations.
Evidence sources (9)
Everything this briefing cites — ANCHOR started the story, CONTEXT backs it without naming the brand.
Your crisis desk is ready — claim it to respond. Claiming is free — your response strategy & plan become collaborative, and you get the option to display your response & status updates on this page.
One short, factual update when this story develops — nothing else, from over:heard.
Email updates
By subscribing you consent to receive email updates about this story. Double opt-in: nothing is sent until you confirm from your inbox. Unsubscribe anytime — one click in every email.
Push notifications
No email needed — alerts appear on this device.
Not nrm.se? See what over:heard would flag for your brand.
Start free →
Independent media-monitoring briefing compiled by over:heard radar from public coverage. Assessments are decision support —
not statements by, or affiliation with, the brands mentioned. · Built from public sources, cited.
Every brand has a free, permanent right of reply —
editorial policy
· Powered by over:heard by wise:able