Why “no comment” is the worst two words in a crisis

no comment

Every lawyer’s instinct in a crisis is the same: say as little as possible, admit nothing, wait for the facts. It’s good legal advice and, according to actual research on the subject, close to the worst possible communications strategy available.

What the research actually found

Researchers at Northwestern’s Kellogg School ran a series of studies putting people in the position of customers reacting to a company crisis, then varied how the company responded: engaged and taking the issue seriously, defensive and self-justifying, or a flat “no comment.” An engaged response consistently made people think better of the company, and in one version of the study, people even rated the product as tasting better afterwards purely based on how the company had responded to unrelated bad news. The genuinely useful finding for anyone weighing legal risk against reputational risk: silence tested about the same as being confrontational. It isn’t neutral. People read it as guilt either way, and there’s a plain reason why: silence doesn’t just withhold information, it removes the one thing that might talk someone out of the worst explanation available. If there was an innocent version of events, the reasoning goes, surely someone would have said so by now. The longer that question goes unanswered, the more it hardens from a question into a conclusion, and everyone left waiting fills the gap with whatever story makes the most sense of the silence, which is rarely a generous one.

Facebook and the five days nobody could find Zuckerberg

On Friday 16 March 2018, reports broke that Cambridge Analytica, a political data consultancy, had improperly obtained data from tens of millions of Facebook users (Facebook later confirmed the real number was closer to 87 million). Most of those 87 million never downloaded anything themselves. It started with a personality quiz app called “thisisyourdigitallife,” built by Cambridge University psychologist Aleksandr Kogan and pitched to Facebook as academic research. Around 270,000 people actually installed it and knowingly handed over their own data, some were even paid a few dollars to take the quiz. But the app also quietly pulled data from every one of those users’ friends, none of whom had installed anything or agreed to anything, and that’s how a quiz taken by a few hundred thousand people turned into a dataset covering tens of millions. Kogan passed that data to Cambridge Analytica.

None of it had just been collected and sat on, either. It had been used to build detailed psychological profiles of individual voters, based on personality traits inferred from their Facebook activity, and then to target them with political advertising built around those specific traits, without any of those users agreeing to it or, in most cases, knowing it was happening. Whistleblower Christopher Wylie, a former Cambridge Analytica employee who helped build the system, later told journalists and testified to lawmakers in both the US and UK that the firm’s clients for this work included the 2016 presidential campaigns of Ted Cruz and Donald Trump.

The anger wasn’t really about a data breach in the technical sense, nothing had been hacked. Facebook had built a platform people used to post holiday photos and keep up with old classmates, and that same platform had quietly become the raw material for a covert campaign to influence how they voted, run without their knowledge and, for most of the 87 million, without them ever installing the quiz app that started it. Worse, Facebook had known about the core problem since 2015, when Cambridge Analytica’s data harvesting was first reported, and had responded by asking the company to delete what it had and taking its word for it, without ever verifying the data was actually gone. Mark Zuckerberg and chief operating officer Sheryl Sandberg said nothing publicly. When worried employees gathered the following Tuesday for an internal question and answer session about what was happening, neither of them turned up. Facebook sent its deputy general counsel instead.

Journalists asking Facebook to respond to specific claims during those days got the standard line: the company “declined to comment.” Not a denial, not a clarification, just the two words that turned “a data company has a problem” into “the leadership of one of the world’s biggest companies has gone missing.”

What that silence actually cost

By the time Zuckerberg finally posted a public statement on the Wednesday, five days after the story broke, Facebook’s stock had shed close to $50 billion in value, and the “Delete Facebook” movement had picked up a genuinely awkward endorsement: Brian Acton, co-founder of Facebook-owned WhatsApp, telling people to do exactly that. Zuckerberg’s statement, when it came, described a “breach of trust” and promised changes, but conspicuously didn’t include an apology. That only came a few hours later, in a live TV interview, once it was clear the written statement alone hadn’t landed.

The bill kept growing well past that first week. Zuckerberg spent two days in April testifying before Congress. In 2019 the US Federal Trade Commission fined Facebook $5 billion over privacy violations connected to the case, at the time the largest privacy penalty any regulator anywhere had ever imposed, and the Securities and Exchange Commission separately fined the company $100 million for misleading investors about the risk. None of that was a direct consequence of the data being taken in the first place. It was a consequence of how long Facebook had known and how little it had said, both in 2015 when it first found out, and in those five days in March when the world was waiting for an answer.

Nothing about those five days was a mystery Facebook was frantically trying to solve. The facts of what Cambridge Analytica had done were already public. What took five days wasn’t fact finding, it was deciding whether to say anything at all, and every hour of that decision doubled as its own answer to the question “does this company take this seriously.” With nobody from Facebook actually saying what had happened or why, journalists, lawmakers and users filled that gap themselves, and the story that formed in the silence, of a company that either didn’t understand the scale of what it had allowed or didn’t want to admit it, was worse than almost anything Facebook could have said out loud on day one.

Why the silence is the story

The pattern repeats often enough that it’s worth naming directly: the “no comment” period rarely buys goodwill for a more considered response later. It mostly just extends the window in which the only thing anyone has to go on is the silence itself, and the guilty and the merely disorganised end up looking identical from the outside. Facebook likely wasn’t hiding some darker secret those five days, it was probably just arguing internally about what to say and who should say it. Nobody watching could tell the difference, and nobody watching was inclined to assume the more charitable option.

There’s more on how this plays out across other companies and other decades in the wider roundup, if you haven’t already read it.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Loading…

0

What do you think?

Written by Keith Nallawalla

kfc fck bucket

The full story of the 2018 KFC UK chicken crisis

united scuffle

United Airlines’ Dr Dao crisis: what went wrong twice