// 1 CRITICAL · 1 ZERO-DAY · 3 CVE · 4 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CISA and the FBI released joint guidance on September 8, 2026, urging service providers to replace PR spin with technical transparency in post-outage communications. Experts are divided on its practical effectiveness, with some questioning its authority and enforceability while others highlight its operational value for worst-case scenarios.

CISA and the FBI published joint guidance on September 8, 2026, titled Communicating Under Pressure: Best Practices for Service Providers, which urges service providers to replace "PR spin" with technical transparency in post-outage communications. The document arrives amid an escalation of actively exploited known vulnerabilities, documented in the CISA KEV Catalog updated September 14, and fits within the regulatory framework of Binding Operational Directive 26-04 issued in June. The guidance imposes no obligations; its effectiveness depends on voluntary adoption.

Key Takeaways
  • The CISA/FBI guidance requires a "factual summary tailored to predefined audiences" and explicitly prohibits PR/marketing language in post-incident communications.
  • The document prescribes sharing "what is known, unknown, and under investigation" with frequent iterative updates.
  • Operational actions include audience segmentation (technical, executive, public), public root cause analysis, and out-of-band channels established before a crisis.
  • Experts John Strand, Joshua Marpet, and Denis Calderone offer divergent reactions, ranging from critiques of decision-making authority to praise for operational aspects.

The Guidance Content: Four Operational Pillars

According to the source reporting the document, the CISA/FBI guidance rests on four key actions. The first is developing a communication plan with predefined activation thresholds. The second is practicing transparency, which excludes PR and marketing language. The third mandates providing technical information and root cause analysis. The fourth requires aligning messaging with legal and regulatory requirements.

The guidance specifies a sharp distinction among audiences: technical communication goes to operational teams, executive communication to internal decision-makers, and public communication to users and customers. Vague language such as "service degradation" is prohibited; the source cites this as an example of a euphemism to eliminate. The recommendation on out-of-band channels is particularly detailed: service providers must establish them before primary infrastructure is compromised.

Context: Expanding KEV Catalog and BOD 26-04

The guidance release is not isolated. On September 14, 2026, CISA updated the Known Exploited Vulnerabilities Catalog with multiple new entries, including products from GitLab, JFrog, ConnectWise, MikroTik, Cisco, Fortinet, and Citrix. This volume of actively exploited vulnerabilities drives the need for clear, rapid communication when incidents materialize.

In parallel, Binding Operational Directive 26-04, issued June 10, 2026, establishes forensic triage and security update prioritization requirements for federal agencies. The communication guidance sits within this framework, though it remains distinct from the BOD: the former is advisory, the latter binding on agencies. The source does not clarify whether the guidance also applies to non-federal service providers.

Expert Critique: Authority, Mandates, and Real-World Scenarios

John Strand, founder of Black Hills Information Security, raised a point the guidance does not address: who holds authority for critical decisions such as a network shutdown. According to the source, Strand stated: "When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls". This critique separates the communication protocol from the decision-making structure: a document can prescribe what to say, but not who decides.

Joshua Marpet of Finite State shifted the critique to the regulatory plane. Citing a personal "law," he called the guidance "useless" without binding mandates: "Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great". Marpet's position highlights a gap between recommendation and enforcement: transparency is desirable, but without consequences for non-compliance it remains optional.

Denis Calderone of Suzu Labs instead emphasized the operational value of the guidance, particularly for edge scenarios. According to the source, Calderone linked the release to the CISA CI Fortify initiative for deliberate disconnection of OT systems from third-party networks during geopolitical crisis. His quote describes a concrete failure point: "Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for".

Why It Matters

The CISA/FBI guidance documents an approach to post-incident communication that many organizations do not apply. The source does not specify how many service providers had adopted the guidance at release, nor is the full text available outside the cited reporting. No enforcement or adherence monitoring mechanisms emerge.

The dossier does not clarify whether the guidance is binding on non-federal service providers, leaving a significant area of legal uncertainty for the private sector. The distinction between recommendation and mandate, raised by Marpet, remains the most significant open point: without consequences for non-adoption, the guidance risks being followed only by organizations already inclined toward transparency.

The documented value from the source lies in structuring operational protocols for compromised-communication scenarios, where ordinary channels are unavailable. This aspect, underscored by Calderone, has technical merit independent of regulatory enforceability.

"Effective communication begins with a factual summary tailored to predefined audiences, avoids PR spin, and adheres to regulatory requirements. Service providers should be transparent by sharing what is known, unknown, and under investigation, while providing frequent, iterative updates as new information emerges or circumstances change"

The guidance sits within a broader trend: regulatory pressure on incident-response communication is intensifying, but the tools remain largely soft law. For service providers, the choice between reputation management and technical transparency is not neutral: it implies revising incident-response plans, training communication teams, and redefining relationships with customers and regulators. Critical infrastructure operators must evaluate whether to adopt the CISA/FBI protocols even absent obligation, considering the source documents no alternative guidelines with the same level of operational detail.

Frequently Asked Questions

Is the CISA/FBI guidance mandatory for private service providers?

The dossier does not clarify the binding scope for non-federal service providers. The document is published by CISA and FBI as best practice, but the source reports no specific enforcement mechanisms for the private sector.

What is the relationship between this guidance and BOD 26-04?

They are distinct documents. BOD 26-04, issued June 10, 2026, imposes requirements on federal agencies for forensic triage and patch prioritization. The communication guidance is advisory and sits within the same regulatory-operational framework, without repeating or modifying BOD requirements.

Why is John Strand's critique relevant?

Because it separates two problems often conflated: what to communicate and who decides. The guidance prescribes the content of communications, but does not address the decision-making structure that authorizes critical actions such as a network shutdown. Absent clarity on this point, even the most transparent communication can be delayed by internal uncertainty.

Sources

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. cisa.gov
  2. news.clearancejobs.com
  3. cve.org