Communicating Under Pressure: Best Practices for Service Providers
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts. CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis. Changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to help end users minimize operational impact, limit speculation, and preserve trust. For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and understand the type of communication they should expect from their service providers.
CSIRTS triage
- What
- Guidance document describing crisis communication practices during IT and OT outages.
- Who is affected
- Service providers and organizations managing critical infrastructure during outages.
- Urgency
- Not a vulnerability; this is operational guidance for incident communication and does not require technical remediation.
- Action
- No action required; this is advisory guidance on communication best practices.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.cisa.gov/resources-tools/resources/communicating-under-pressure-best-practices-service-providers
More from CISA Cybersecurity Advisories
- highCISA Adds Seven Known Exploited Vulnerabilities to Catalog2026-09-02
- criticalRockwell Automation Redundancy Module Configuration Tool2026-09-01
- criticalRockwell Automation FactoryTalk Activation Manager2026-09-01
- criticalRockwell Automation Logix Platform2026-09-01
- criticalRockwell Automation Historian ME2026-09-01