CISA, FBI, and International Partners Push for Transparent Outage Communications
On September 2, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom jointly published "Communicating Under Pressure: Best Practices for Service Providers" — a nine-page advisory treating crisis communication as a core pillar of incident response, on par with technical remediation. The guidance presses organizations to abandon "PR spin" during major IT and operational technology (OT) outages in favor of factual, iterative disclosure of what happened, what remains unknown, and what is being done about it.
Advisory Snapshot
| Attribute | Detail |
|---|---|
| Title | "Communicating Under Pressure: Best Practices for Service Providers" |
| Published | September 2, 2026 |
| Co-issuing agencies | CISA, FBI, Australian Cyber Security Centre, Canadian and New Zealand cybersecurity authorities, UK cybersecurity authorities |
| Length | 9 pages |
| Industry contributors | Microsoft, Sophos, Cloudflare, American Water |
| Primary motivating incident | Cloudflare outage, November 18, 2025 (~6 hours, roughly one-fifth of global web traffic affected) |
| Related initiative | CISA's CI Fortify program (launched May 2026) |
What the Guidance Actually Says
The advisory frames its message bluntly: effective crisis communication is transparent, skips reputation-management language, and explains root causes so users can limit their own operational impact. As the document states, "service outages alone have the potential to cause enough damage, disruption, and societal panic without speculation and uncertainty from end users and the public as added factors."
The agencies define effective communication around five principles:
- Immediate — address the problem promptly instead of waiting for full certainty
- Technical — give actionable direction, not generic reassurance
- Transparent — clearly separate confirmed facts from unknowns and items still under investigation
- Accountable — accept organizational responsibility for outcomes
- Iterative — post regular updates, including "no new information" status reports
Organizations are told to build an outage communications plan before an incident hits: defining incident thresholds, escalation paths, target audiences, and procedures for status pages, customer and partner notices, and regulatory filings, with named roles (incident lead, communications lead, single spokesperson, legal, compliance, government relations) so a chain of command exists the moment an outage begins.
A notable operational detail: the guidance tells providers to assume their own communication channels — email, collaboration platforms, customer portals, even status pages — may go down alongside the primary system. Organizations are told to test backup mechanisms, such as SMS phone trees, radios, satellite links, and secure out-of-band messaging, as part of routine business-continuity and incident-response exercises.
Distinguishing Attacks From Everything Else
The guidance applies broadly: it covers outages caused by cyberattacks, operator error, equipment failure, natural hazards, and deliberate defensive actions such as isolating systems mid-incident. That last category gets specific attention — organizations should make clear when an outage is a protective action taken to contain a threat, rather than evidence that recovery has failed. Analysts see the timing as deliberate: after a year of attacks against water utilities, ports, power generation, and PLC suppliers, CISA appears intent on preventing the next critical-infrastructure outage from triggering days of unfounded nation-state speculation before the facts are known.
Why Now: The Cloudflare Outage as Case Study
The advisory explicitly names the November 18, 2025 Cloudflare outage as its primary real-world reference point. That incident stemmed from a routine database permissions change that caused a bot-management configuration file to exceed a hard-coded size limit, triggering a cascading failure across Cloudflare's global network and disrupting roughly one-fifth of worldwide web traffic for close to six hours. Compounding matters, Cloudflare's own status page went down during the incident, and its response team reportedly misidentified the root cause early on — partly because of the same communication breakdown the new guidance targets.
Chris Butera, CISA's acting executive assistant director, said the guidance was informed directly by events like the Cloudflare outage and supports CI Fortify, the agency's initiative to help critical infrastructure operators isolate and recover OT systems during a major cyber incident.
Industry Reaction: Praise, With Reservations
Reaction has been broadly favorable but skeptical about enforcement. Analysts from Quadrum Advisors, Marsh Specialty, and Coalition described the advisory as addressing a deeper trust problem — legal and PR incentives have historically pushed companies toward minimal disclosure over customer-first transparency. Several experts offered more pointed critiques:
- Joshua Marpet (Finite State) argued that companies routinely follow the advice of crisis-communications firms retained to minimize legal liability, and suggested that mandated timelines — comparable to the EU Cyber Resilience Act's 24-hour, 72-hour, and 14-day reporting windows — will ultimately be needed to force real change.
- Denis Calderone (Suzu Labs) said the emphasis on testing backup communication channels highlights a gap most organizations overlook during tabletop exercises.
- John Strand (Black Hills Information Security) said the guidance still needs to clarify who has the authority to make hard calls, such as shutting down a network, and what protections exist for the people who make that decision under pressure.
The consensus critique: the advisory carries no enforcement mechanism. Real behavioral change, experts say, will require regulatory pressure, board-level oversight, and contractual requirements — not voluntary best practices alone. Procurement teams, one analysis suggested, should start treating outage-communication commitments as a contract issue, since many SLAs specify uptime but say nothing about notice cadence, status channels, or post-incident reporting.
A Separate Regulatory Track
The transparency push is distinct from CISA's formal incident-reporting rulemaking. Under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), CISA has delayed finalizing its mandatory cyber incident reporting rule for critical infrastructure operators until May 2026 — nine months past the original deadline — reducing its scope in the process. The new communications advisory is voluntary and carries no legal reporting obligations of its own.
Impact Assessment
| Stakeholder | Impact |
|---|---|
| CISOs and incident responders | Build or revisit outage communications plans with defined roles, thresholds, and escalation paths |
| Communications and PR teams | Pressure to drop vague "service degradation" language for factual, iterative updates |
| Regulated critical infrastructure operators | Reinforces CI Fortify expectations around OT isolation and recovery comms, without new binding requirements |
| Cloud and managed service providers | Heightened scrutiny post-Cloudflare; customers may demand comms commitments in contracts and SLAs |
| Legal and compliance teams | Must reconcile transparency guidance against existing disclosure caution driven by liability concerns |
Recommendations
For Security and Incident Response Teams
- Build a written outage communications plan now, with incident severity thresholds, escalation paths, and named roles (incident lead, spokesperson, legal, compliance, government relations)
- Establish and test backup channels — SMS phone trees, radios, satellite links, out-of-band messaging — assuming primary systems, including your own status page, may go down
- Fold crisis-communication drills into existing tabletop exercises instead of treating comms as an afterthought
- Pre-draft message templates per audience (customers, partners, regulators, media) so responders aren't writing from scratch under pressure
For Leadership and Legal Teams
- Revisit legal/PR guidance that defaults to minimal disclosure; weigh liability caution against the cost of appearing to spin an outage
- Clarify who has authority for high-impact calls, such as isolating systems, and ensure that authority has documented backing
- Review vendor and service-provider SLAs for gaps around notice cadence, status-page commitments, and post-incident reporting — not just uptime
- Track CIRCIA's mandatory reporting rule (now expected May 2026) separately, since binding obligations may follow on a different timeline
Key Takeaways
- CISA, the FBI, and authorities from Australia, Canada, New Zealand, and the UK jointly published "Communicating Under Pressure" on September 2, 2026, urging providers to prioritize transparency over PR spin during outages.
- The advisory was directly informed by the November 18, 2025 Cloudflare outage, where a status-page failure and root-cause misidentification compounded a roughly six-hour disruption affecting about one-fifth of global web traffic.
- Five principles anchor the guidance — immediate, technical, transparent, accountable, iterative — backed by calls for pre-built comms plans, tested backup channels, and defined incident-response roles.
- The guidance covers both malicious attacks and non-malicious outages, and tells organizations to clarify when a disruption is deliberate defensive isolation rather than a failed recovery.
- Experts including Joshua Marpet, Denis Calderone, and John Strand welcomed the guidance but flagged its lack of enforcement teeth, saying real change needs regulatory pressure, board oversight, or contractual mandates.
- The advisory is voluntary and separate from CISA's CIRCIA mandatory incident-reporting rule, which remains delayed until May 2026.