When a service incident affects customers, I choose the first update by answering three things in the first few lines: what is affected, what customers should expect next, and when they will hear from us again. In my experience operating SaaS products, the first message should reduce uncertainty more than it should explain root cause. Customers mainly want to know whether the issue is on your side, whether their data or work is at risk, and whether they need to do anything right now.
One wording choice that consistently reduced confusion for us was replacing vague language like "We're aware of some issues and investigating" with a direct structure: "We're currently investigating an issue affecting [feature/service]. Your content and account data remain safe based on what we know now. You do not need to retry or change settings. We'll post our next update by [time]." That works because it removes the two biggest sources of customer stress: not knowing whether they caused the problem, and not knowing whether they should keep refreshing, resubmitting, or contacting support.
The timing choice that matters most is sending the first update early, even if you do not have a full diagnosis yet. I would rather send a clear holding statement within about 10 to 15 minutes than wait 40 minutes for a more polished explanation. Silence makes customers fill in the blanks themselves, and those assumptions are usually worse than the reality.
Another small but important detail is to avoid promising resolution times too early. I've found it is better to commit to the next update time than to commit to a fix time you may miss. "Next update in 30 minutes" creates trust. "Resolved soon" usually creates frustration.
The best first update is calm, specific, and operational: what's happening, what is not happening, what customers should do, and exactly when they will hear from you again.