The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation, and international partners published new guidance on Wednesday that describes how service providers can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and OT (operational technology) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm.
The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.
Titled ‘Communicating Under Pressure: Best Practices for Service Providers,’ the document recommends service providers develop a service outage communications plan that defines triggers, escalation paths, and procedures and includes templates for status pages; customer and partner notices; and regulatory communications.
To communicate effectively during an outage, service providers should establish and exercise key structures before a crisis occurs. A cross-functional incident team should be formed that includes engineering and operations, communications and public affairs, legal, risk and compliance, and customer support and sales, with primary and alternate points of contact designated for each function. In cases where government stakeholders are affected by incidents, service providers should consider including a government relations lead as a point of contact to help ensure that messaging to government agencies and other officials remains consistent with public communications.
Clear roles and authority must be established by designating an incident lead who orchestrates the organization’s response to the cyber incident, a communications lead who functions as the orchestrator and manages information coordinated internally and externally, and a spokesperson who functions as the sole public-facing representative to deliver approved statements or respond to questions from reporters. All three roles should have predefined approval paths and escalation criteria to guide decision-making.
Service providers should establish parallel, synchronized workstreams where technical teams diagnose and remediate the root cause, communications manage public messaging and stakeholders, and leadership drives strategy and regulatory outreach. Designated liaisons, scheduled syncs, and a single intake path should be used to align facts and shield engineers from external interruptions. The legal team plays a critical role in helping ensure that communications, regulatory obligations, contractual considerations, and risk management activities are appropriately aligned throughout the incident.
Service providers must establish and regularly test backup communication methods for informing both internal and external stakeholders, such as backup email and messaging, SMS and phone trees, radios, out-of-band communications, and conference bridges, for moments when primary systems are degraded or compromised.
Communication plans should have defined triggers, escalation paths, and procedures that are reviewed and refreshed regularly, and plans should be executed regularly through periodic training such as simulated tabletop exercises to help ensure communications teams can respond effectively under pressure. Messaging to internal audiences should be consistent with external communications whenever possible, and all staff should be provided with approved talking points or instructions to direct questions to designated communications channels.
The document also outlined that effective outage communication requires clear, timely, and audience-appropriate messaging that supports rapid decision-making during high-pressure events. It detailed couple of elements how service providers can maintain trust, deliver actionable information, and uphold transparency throughout an incident response cycle.
During widespread outages, organizations need immediate, accurate, and concise information to limit harm and preserve trust. Service providers should communicate confirmed facts early and clearly state what the issue is and what it is not. If the root cause remains under investigation, service providers should avoid premature conclusions. When malicious cyber activity is suspected or confirmed, external communications must protect operational security and align with law enforcement and containment efforts.
Service providers should segment communications for each audience, such as technical teams, executives, and the public, so they can act on relevant information effectively. Maintained contact lists ensure rapid engagement with appropriate offices during crises. Key audiences include enterprise IT teams and security operations centers, affected employees and customers, government partners and regulators, critical infrastructure owners and operators, and media and the general public. Since critical infrastructure operators make real-time mitigation decisions based on provider guidance, communications should prioritize technical specificity and operational relevance, providing impact statements rather than symptoms.
During outages, customers, network defenders, and critical infrastructure operators need information quickly to aid rapid response and recovery. Communications should lead with a ‘bottom line upfront’ that works for both general and technical audiences, including affected systems, user impact, scope, and the known cause without speculation. Avoid vague language like ‘service degradation’ and instead use concise headings and prioritized information to enable rapid comprehension under pressure.
The document also noted that service providers can build trust by being transparent about outages and incidents, even when information is incomplete. They should state clearly what they know and what remains unknown, as honest admissions of uncertainty are more effective than silence or speculation. However, transparency must align with the incident type: active cyber incidents require limited detail sharing to protect detection and investigation, while non-malicious outages should default to forthcoming transparency.
Moreover, service providers should maintain a single source of truth, such as a status webpage, for all public updates and focus communications on actionable information rather than reputation management. This means providing clear guidance on specific customer actions or explicitly stating when no action is necessary. Communications should avoid leading with reassurances, generalities, or marketing language, and instead acknowledge the impact while committing to fixes and restoration.
Regular, time-stamped updates are critical during incidents to limit speculation and demonstrate active response. Communications should include a clear timeline of the incident, document actions taken and recovery milestones, and timestamp all updates even when no new information is available. Maintaining a single source status page ensures consistent information across all channels.
Service providers must coordinate externally communicated information with legal counsel and compliance teams, as outage communications may trigger incident reporting disclosure rules, sector-specific mandates such as those in financial services or healthcare, and contractual service level agreements. Messaging must remain consistent across public statements and regulatory findings, and any public attribution statements should be coordinated appropriately with government or law enforcement partners beforehand.
Post-incident communications should explain how service providers will use lessons learned to enhance products and processes, including their commitment to Secure by Design principles and products configured with enhanced safety features by default. Service providers should also transparently discuss their vulnerability management and patching practices.
Lastly, the document identifies that effective outage communications should be immediate, with service providers acknowledging issues quickly to limit speculation and customer uncertainty. Communications must be technical in nature, providing actionable guidance that enables customers and infrastructure operators to respond effectively. Service providers should be transparent by sharing what they know and clearly stating what remains unknown, building trust through honest communication. They must be accountable by owning their responsibilities and the outcomes of incidents rather than deflecting blame. Finally, communications should be iterative, with continuous updates that demonstrate active response and progress toward resolution.
In May, CISA launched CI Fortify, a new initiative to strengthen the resilience of America’s critical infrastructure against disruptive cyber threats. The program provides strategic guidance to help organizations across sectors prepare for crises or conflicts, ensuring they can sustain essential operations even while under attack. It prioritizes baseline service continuity and operational resilience during cyber incidents designed to disrupt critical services.


