Back to Intelligence

CISA & FBI Crisis Communications Guidance: How Service Providers Should Communicate During IT and OT Outages

SA
Security Arsenal Team
September 3, 2026
9 min read

When a ransomware event, equipment failure, or misconfigured change takes a service provider offline, the technical response is only half the battle. The other half — the half that determines whether customers panic, regulators escalate, and downstream partners make bad decisions — is communication. CISA, the FBI, and international partners have now published joint guidance, Communicating Under Pressure: Best Practices for Service Providers, aimed squarely at this problem: how organizations should plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages.

Having led incident response engagements where the outage itself was survivable but the communications vacuum was catastrophic, I can tell you this guidance lands on a real operational gap. Most IR plans I've reviewed over 15 years have detailed technical runbooks and a single bullet point that says "notify stakeholders." That is not a communications plan. This post breaks down what the guidance says, why it matters for defenders, and how to build it into your incident response program before you need it.

What the Guidance Covers and Why It Was Published

The joint guidance — developed by CISA, the FBI, and international partners — addresses a scenario every service provider will eventually face: an outage that affects customers, partners, or the public, regardless of root cause. The guidance is deliberately cause-agnostic. Outages can stem from:

  • Cyber threat actors — ransomware, destructive wiper attacks, DDoS campaigns, or supply-chain compromises
  • Human error — a bad push, a misconfigured firewall rule, an expired certificate nobody tracked
  • Equipment failure — hardware faults, failed updates, infrastructure degradation
  • Natural hazards — severe weather, flooding, power loss affecting data centers or OT environments

The core insight driving the guidance is one every IR veteran recognizes: the outage itself is rarely what creates societal disruption — the information vacuum does. When end users and the public can't get authoritative information, they speculate. Speculation fills social media within minutes. And when one provider's outage cascades across interconnected systems — a managed service provider feeding dozens of downstream clients, an OT vendor supporting multiple utilities, a cloud region supporting thousands of tenants — that uncertainty multiplies at each dependency layer.

The guidance establishes three core principles for crisis messaging:

  1. Clarity — Say what you know, what you don't know, and what you're doing about it, in plain language.
  2. Accountability — Own the outage. Deflection and vague corporate-speak erode trust faster than the outage itself.
  3. Transparency — Communicate proactively on a cadence, even when the update is "we don't have new information yet."

It also details the key elements of effective crisis messaging and emphasizes aligning communications with legal and regulatory obligations — a point that matters enormously for providers subject to breach notification statutes, sector-specific reporting requirements, or contractual SLAs.

Why This Matters to Defenders: The Communications Failure Pattern

In every major incident I've worked — ransomware against a healthcare system, a nation-state intrusion at a managed provider, a supply-chain compromise rippling through downstream customers — the same failure pattern emerges:

Hour 0–4: Technical teams are heads-down on containment. Nobody owns external messaging. Customers start calling. Support staff have no script and either say nothing or say something wrong.

Hour 4–24: Social media fills the gap. Screenshots of error messages circulate. Reporters call. A rumor that "it's ransomware" (whether true or not) becomes the accepted narrative because the provider hasn't said anything authoritative.

Day 2+: Regulators and lawyers get involved. Now every statement is being drafted by committee, reviewed by counsel, and delayed further — while downstream partners make consequential decisions (failing over, notifying their own customers, invoking contract clauses) based on incomplete information.

The cascade effect the guidance highlights is real and measurable. During major MSP and SaaS provider incidents, I've watched downstream organizations burn hundreds of analyst-hours chasing ghosts because the upstream provider's status page said only "we are investigating an issue" for eighteen hours. That silence forced every dependent organization to assume the worst and activate their own IR procedures — some unnecessarily, some too late.

Key Elements of Effective Crisis Messaging

Based on the guidance and hard-won field experience, effective outage communications share common structural elements. Build these into your templates now:

1. Acknowledge fast, even with incomplete information. The first message doesn't need root cause. It needs: confirmation that you're aware of the issue, the scope of what's affected (services, regions, customer segments), what you're doing, and when the next update will come. "We are aware of an outage affecting X service. Our teams are actively investigating. Next update by 14:00 UTC" is infinitely better than silence.

2. Commit to a cadence and keep it. State when the next update will arrive and hit that deadline even if the update is "no material change." Breaking a promised cadence signals loss of control.

3. Segment your audiences. The guidance emphasizes audience-appropriate messaging, and this is where most providers fail. Your audiences have different needs:

  • Direct customers need scope, impact, workaround options, and expected restoration timelines
  • Downstream/dependent organizations need enough technical detail to make their own risk decisions — including whether they should activate their own contingency plans
  • Regulators and legal stakeholders need notifications aligned with statutory timelines and requirements
  • The general public/media need plain-language impact statements without technical jargon or speculation
  • Internal staff need approved talking points so support teams, sales, and executives don't freelance contradictory messages

4. Be precise about what you know versus don't know. "The cause is under investigation" is acceptable. Speculating publicly that it's "not cyber-related" before forensics confirms it is how providers end up issuing humiliating corrections — which destroy credibility permanently.

5. Align with legal obligations from minute one. Involve counsel early, but don't let legal review become an excuse for silence. Pre-draft and pre-approve message templates with counsel before an incident so review cycles take minutes, not days.

The OT Dimension

The guidance explicitly covers operational technology outages, which carry elevated stakes. An OT outage at a utility, manufacturer, or transportation provider isn't an inconvenience — it can affect physical safety and essential services. Communications during OT incidents must account for:

  • Safety-critical messaging — if there's any potential physical safety implication, that communication obligation is immediate and non-negotiable
  • Interdependency notification — OT environments frequently sit upstream of other critical services; cascading failure warnings need to reach dependent operators fast
  • Coordination with government partners — for critical infrastructure providers, CISA and sector-specific agencies should be in your communications tree, and establishing those contact paths before an incident is a core preparedness step

Executive Takeaways

For CISOs, service provider leadership, and IR program owners, here is how to operationalize this guidance:

  1. Build a crisis communications annex into your IR plan — this quarter. If your IR plan doesn't include pre-approved message templates (initial acknowledgment, status update, service restoration, and post-incident summary), audience-segmented distribution lists, and defined spokesperson roles, you are not prepared. Write templates for cyber, error, equipment failure, and natural hazard scenarios since the guidance is cause-agnostic.

  2. Assign a communications owner with the same authority as your technical incident commander. During declared incidents, the comms lead must have a seat at the response bridge, real-time access to verified facts, and authority to publish on the committed cadence without multi-hour approval chains.

  3. Pre-clear legal review pathways. Work with counsel now to pre-approve template language and define what triggers regulatory notification in your jurisdictions and sectors. The goal is a legal review measured in minutes during an incident, not a drafting process that starts from a blank page at hour twelve.

  4. Map your downstream dependencies and their notification expectations. If you're an MSP, SaaS provider, or OT vendor, document who depends on you, what detail they need to make their own continuity decisions, and how you'll reach them if your primary channels (email, status page, portal) are themselves degraded by the outage. Out-of-band communication channels are essential — if your status page runs on the infrastructure that's down, you have no voice.

  5. Run communications injects in your tabletop exercises. Every IR tabletop should include a scenario where the technical team is three hours from answers and the comms team must produce a public statement anyway. Exercise the cadence discipline: updates at promised intervals even with no new information. Most organizations discover their comms gaps in a real incident because tabletops only test technical response.

  6. Adopt the clarity-accountability-transparency standard as measurable criteria. After every incident and exercise, evaluate your messaging against the guidance's three principles: Was it clear to a non-technical audience? Did it demonstrate ownership? Was it proactive rather than reactive? Treat communications performance as a post-incident review item equal in weight to detection time and containment time.

The Bottom Line

The CISA/FBI guidance formalizes what seasoned responders already know: in a major outage, your technical recovery and your communications recovery run on parallel tracks, and a failure on either track compounds the other. Interconnected service providers carry an outsized responsibility — your silence becomes your customers' crisis.

The organizations that handle incidents well aren't the ones that never have outages. They're the ones whose customers say, afterward: "They told us what was happening, when they'd update us next, and they did." That outcome is engineered in advance — through templates, exercised cadences, pre-cleared legal pathways, and a communications owner with real authority. This guidance gives you the framework. Build it into your IR program before the outage, not during it.

Related Resources

Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.