Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2761+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
NEWS

CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate

CISA, FBI, and Five Eyes partners publish joint crisis-comms guidance urging providers to drop PR spin and disclose outage root causes transparently.

Dylan H.

News Desk

September 12, 2026
8 min read

CISA, FBI, and International Partners Push for Transparent Outage Communications

On September 2, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom jointly published "Communicating Under Pressure: Best Practices for Service Providers" — a nine-page advisory treating crisis communication as a core pillar of incident response, on par with technical remediation. The guidance presses organizations to abandon "PR spin" during major IT and operational technology (OT) outages in favor of factual, iterative disclosure of what happened, what remains unknown, and what is being done about it.


Advisory Snapshot

AttributeDetail
Title"Communicating Under Pressure: Best Practices for Service Providers"
PublishedSeptember 2, 2026
Co-issuing agenciesCISA, FBI, Australian Cyber Security Centre, Canadian and New Zealand cybersecurity authorities, UK cybersecurity authorities
Length9 pages
Industry contributorsMicrosoft, Sophos, Cloudflare, American Water
Primary motivating incidentCloudflare outage, November 18, 2025 (~6 hours, roughly one-fifth of global web traffic affected)
Related initiativeCISA's CI Fortify program (launched May 2026)

What the Guidance Actually Says

The advisory frames its message bluntly: effective crisis communication is transparent, skips reputation-management language, and explains root causes so users can limit their own operational impact. As the document states, "service outages alone have the potential to cause enough damage, disruption, and societal panic without speculation and uncertainty from end users and the public as added factors."

The agencies define effective communication around five principles:

  • Immediate — address the problem promptly instead of waiting for full certainty
  • Technical — give actionable direction, not generic reassurance
  • Transparent — clearly separate confirmed facts from unknowns and items still under investigation
  • Accountable — accept organizational responsibility for outcomes
  • Iterative — post regular updates, including "no new information" status reports

Organizations are told to build an outage communications plan before an incident hits: defining incident thresholds, escalation paths, target audiences, and procedures for status pages, customer and partner notices, and regulatory filings, with named roles (incident lead, communications lead, single spokesperson, legal, compliance, government relations) so a chain of command exists the moment an outage begins.

A notable operational detail: the guidance tells providers to assume their own communication channels — email, collaboration platforms, customer portals, even status pages — may go down alongside the primary system. Organizations are told to test backup mechanisms, such as SMS phone trees, radios, satellite links, and secure out-of-band messaging, as part of routine business-continuity and incident-response exercises.

Distinguishing Attacks From Everything Else

The guidance applies broadly: it covers outages caused by cyberattacks, operator error, equipment failure, natural hazards, and deliberate defensive actions such as isolating systems mid-incident. That last category gets specific attention — organizations should make clear when an outage is a protective action taken to contain a threat, rather than evidence that recovery has failed. Analysts see the timing as deliberate: after a year of attacks against water utilities, ports, power generation, and PLC suppliers, CISA appears intent on preventing the next critical-infrastructure outage from triggering days of unfounded nation-state speculation before the facts are known.

Why Now: The Cloudflare Outage as Case Study

The advisory explicitly names the November 18, 2025 Cloudflare outage as its primary real-world reference point. That incident stemmed from a routine database permissions change that caused a bot-management configuration file to exceed a hard-coded size limit, triggering a cascading failure across Cloudflare's global network and disrupting roughly one-fifth of worldwide web traffic for close to six hours. Compounding matters, Cloudflare's own status page went down during the incident, and its response team reportedly misidentified the root cause early on — partly because of the same communication breakdown the new guidance targets.

Chris Butera, CISA's acting executive assistant director, said the guidance was informed directly by events like the Cloudflare outage and supports CI Fortify, the agency's initiative to help critical infrastructure operators isolate and recover OT systems during a major cyber incident.

Industry Reaction: Praise, With Reservations

Reaction has been broadly favorable but skeptical about enforcement. Analysts from Quadrum Advisors, Marsh Specialty, and Coalition described the advisory as addressing a deeper trust problem — legal and PR incentives have historically pushed companies toward minimal disclosure over customer-first transparency. Several experts offered more pointed critiques:

  • Joshua Marpet (Finite State) argued that companies routinely follow the advice of crisis-communications firms retained to minimize legal liability, and suggested that mandated timelines — comparable to the EU Cyber Resilience Act's 24-hour, 72-hour, and 14-day reporting windows — will ultimately be needed to force real change.
  • Denis Calderone (Suzu Labs) said the emphasis on testing backup communication channels highlights a gap most organizations overlook during tabletop exercises.
  • John Strand (Black Hills Information Security) said the guidance still needs to clarify who has the authority to make hard calls, such as shutting down a network, and what protections exist for the people who make that decision under pressure.

The consensus critique: the advisory carries no enforcement mechanism. Real behavioral change, experts say, will require regulatory pressure, board-level oversight, and contractual requirements — not voluntary best practices alone. Procurement teams, one analysis suggested, should start treating outage-communication commitments as a contract issue, since many SLAs specify uptime but say nothing about notice cadence, status channels, or post-incident reporting.

A Separate Regulatory Track

The transparency push is distinct from CISA's formal incident-reporting rulemaking. Under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), CISA has delayed finalizing its mandatory cyber incident reporting rule for critical infrastructure operators until May 2026 — nine months past the original deadline — reducing its scope in the process. The new communications advisory is voluntary and carries no legal reporting obligations of its own.

Impact Assessment

StakeholderImpact
CISOs and incident respondersBuild or revisit outage communications plans with defined roles, thresholds, and escalation paths
Communications and PR teamsPressure to drop vague "service degradation" language for factual, iterative updates
Regulated critical infrastructure operatorsReinforces CI Fortify expectations around OT isolation and recovery comms, without new binding requirements
Cloud and managed service providersHeightened scrutiny post-Cloudflare; customers may demand comms commitments in contracts and SLAs
Legal and compliance teamsMust reconcile transparency guidance against existing disclosure caution driven by liability concerns

Recommendations

For Security and Incident Response Teams

  • Build a written outage communications plan now, with incident severity thresholds, escalation paths, and named roles (incident lead, spokesperson, legal, compliance, government relations)
  • Establish and test backup channels — SMS phone trees, radios, satellite links, out-of-band messaging — assuming primary systems, including your own status page, may go down
  • Fold crisis-communication drills into existing tabletop exercises instead of treating comms as an afterthought
  • Pre-draft message templates per audience (customers, partners, regulators, media) so responders aren't writing from scratch under pressure

For Leadership and Legal Teams

  • Revisit legal/PR guidance that defaults to minimal disclosure; weigh liability caution against the cost of appearing to spin an outage
  • Clarify who has authority for high-impact calls, such as isolating systems, and ensure that authority has documented backing
  • Review vendor and service-provider SLAs for gaps around notice cadence, status-page commitments, and post-incident reporting — not just uptime
  • Track CIRCIA's mandatory reporting rule (now expected May 2026) separately, since binding obligations may follow on a different timeline

Key Takeaways

  1. CISA, the FBI, and authorities from Australia, Canada, New Zealand, and the UK jointly published "Communicating Under Pressure" on September 2, 2026, urging providers to prioritize transparency over PR spin during outages.
  2. The advisory was directly informed by the November 18, 2025 Cloudflare outage, where a status-page failure and root-cause misidentification compounded a roughly six-hour disruption affecting about one-fifth of global web traffic.
  3. Five principles anchor the guidance — immediate, technical, transparent, accountable, iterative — backed by calls for pre-built comms plans, tested backup channels, and defined incident-response roles.
  4. The guidance covers both malicious attacks and non-malicious outages, and tells organizations to clarify when a disruption is deliberate defensive isolation rather than a failed recovery.
  5. Experts including Joshua Marpet, Denis Calderone, and John Strand welcomed the guidance but flagged its lack of enforcement teeth, saying real change needs regulatory pressure, board oversight, or contractual mandates.
  6. The advisory is voluntary and separate from CISA's CIRCIA mandatory incident-reporting rule, which remains delayed until May 2026.

Sources

  • DarkReading — CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
  • Security Magazine — Avoid "PR Spin" in IT/OT Outages, CISA Advises
  • SecureWorld — CISA, Partners Issue Guidance for Critical Infrastructure Crisis Comms
#CISA#FBI#Incident Response#Critical Infrastructure#Cloudflare#Regulatory

Related Articles

Cisco SD-WAN Zero-Day CVE-2026-20127 Triggers Five Eyes

A CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN has been exploited since at least 2023. CISA issues Emergency Directive ED 26-03 as all Five...

3 min read

Microsoft Hit by Back-to-Back Outages: M365 Admin Center

Microsoft 365 admin center is experiencing degraded access across North America, just days after a major Azure infrastructure outage knocked out VMs, AKS,...

3 min read

Cloudflare BGP Routing Error Cascades Across AWS, X, and More

A routine configuration update at Cloudflare's Ashburn data center introduced a BGP routing error on February 16 that cascaded across the internet,...

4 min read
Back to all News