The fallout from a major security flaw can take months, even years, to fully realize. The more complex the situation, the more carefully you need to plan and execute the disclosure. In the case of Meltdown/Spectre, the original plan was to embargo the disclosure until everyone had time to develop a fix. Be transparent, be honest, be consistent and dont invite people to question your motives by making unforced errors. A well-rehearsed incident response plan with an authorized manager and pre-assigned roles and responsibilities can help keep folks focused on the greater good.”]

