Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
CISA and the FBI have released joint guidance urging service providers to communicate facts without marketing filters during IT and OT outages. The document, titled Communicating Under Pressure: Best Practices for Service Providers, was issued in collaboration with the cybersecurity agencies of Australia, Canada, New Zealand, and the United Kingdom. It marks a turning point: dysfunctional communications during technical crises are now treated as systemic risk, not a public relations problem.
- The "Communicating Under Pressure" guidance was released by CISA and the FBI with support from four allied agencies, spanning five countries.
- The agencies recommend that providers "lead with facts" and avoid marketing language or "PR spin" in incident communications.
- The document defines three key roles — incident lead, communications lead, and spokesperson — with parallel workstreams for technical and communications teams.
- Communications must be segmented for six audience categories, from IT/SOC teams to government partners, media, and the general public.
From "Reputation Management" to "Actionable Guidance"
The shift in tone is stark. According to the cited source, the guidance urges service providers to "focus communications on actionable guidance rather than reputation management." This is not stylistic advice; it is an operational redefinition of priorities during an outage.
The message is that every minute spent crafting defensive narratives is a minute diverted from technical mitigation and user protection. The recommendation applies to any disruption involving IT or OT systems, with particular attention to scenarios where the root cause is still under investigation.
An Organizational Framework with Fixed Roles and Audiences
The document does not stop at principles. It defines an organizational structure with three key roles: the incident lead, the communications lead, and the spokesperson. Technical and communications teams must operate in parallel, not sequentially, to prevent information gathering from slowing disclosure, or vice versa.
The audience is segmented into six precise categories: IT and SOC teams, employees and customers, government partners and regulators, critical infrastructure owners and operators, media, and the general public. Each segment receives information calibrated to its level of action: technical teams need operational details, while the general public needs concrete instructions on how to protect themselves.
Single Source of Truth and Timestamped Updates
The guidance recommends establishing an outage communications plan before an incident occurs, with activation thresholds, escalation paths, and predefined target audiences. During the event, service providers must use a "single source of truth" — typically a status page — with continuous, timestamped updates showing the incident timeline, actions taken, and recovery milestones.
Timestamping is not a formal detail; it serves to make the chronology of statements verifiable and to prevent the spread of obsolete or contradictory information through unofficial channels.
Balancing Transparency with Operational Security
A point of tension emerges when an outage may be linked to malicious activity. The guidance requires balancing transparency and operational security: communicate enough to enable defense and recovery, but not enough to provide intelligence to attackers. The dossier does not detail specific criteria for this balance.
"effective communication is critical to limiting operational impact when IT and OT outages affect customers, network defenders, critical infrastructure owners and operators, and the public" — CISA/FBI guidance
What to Do Now
Service providers must act on four concrete fronts derived from the guidance:
1. Audit the outage communication plan. Verify whether an outage communications plan exists with activation thresholds, escalation paths, and defined target audiences before an incident. If absent, drafting one is a priority.
2. Define the three key roles. Explicitly assign the incident lead, communications lead, and spokesperson, with documented parallel workstreams to avoid priority conflicts during a crisis.
3. Segment the six audiences. Map the actual recipients of communications — IT/SOC teams, employees/customers, government partners, critical infrastructure operators, media, public — and prepare calibrated templates for each.
4. Implement the single source of truth. Activate a status page as the primary source for timestamped updates, with the incident timeline, actions taken, and recovery milestones visible and verifiable.
Why It Matters
The document contains no technical patching requirements, specific vulnerabilities, or indicators of compromise. It is pure governance guidance for communication, a domain CISA traditionally did not regulate with this granularity. The fact that the agency is doing so now, co-branded with the FBI and four Five Eyes allies, suggests that communication dysfunctions observed in recent global-scale outages have been judged systemic recurrences, not exceptions.
The guidance does not specify whether it is mandatory for federal entities or voluntary for the private sector. The dossier does not document corrective measures for service providers that do not adhere, nor concrete case studies included in the original document.
Frequently Asked Questions
Is the guidance mandatory for all service providers?
The dossier does not specify the level of mandatory versus voluntary adoption for non-federal entities. The document is presented as best practice, not as a binding regulation.
Which systems does the guidance cover?
IT and OT systems, with a focus on disruptions impacting customers, network defenders, critical infrastructure owners and operators, and the general public.
What does "PR spin" mean in the context of the guidance?
Marketing language or defensive narratives that prioritize reputation management over concrete actionable guidance for users affected by the outage.
Information is based on the cited source and current as of publication.
Sources
- https://thecyberexpress.com/cisa-fbi-issue-outage-communications-guidance/
- https://www.securitymagazine.com/articles/102563-avoid-pr-spin-in-it-ot-outages-cisa-advises
- https://www.cisa.gov/news-events/cybersecurity-advisories
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cve.org/CVERecord?id=CVE-2026-85706
- https://www.cisa.gov/staying-secure-large-scale-events
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.