CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
The CISA, in collaboration with the FBI and international partners, released an advisory emphasizing the need for more transparent and accountable communication during cybersecurity outages and incidents. The goal is to shift away from PR spin and legal maneuvering towards providing actionable information to users and stakeholders, particularly in the context of increasingly complex and disruptive outages, including those stemming from supply chain attacks and AI-powered propagation. Experts believe this shift reflects a growing recognition that vague or misleading communications erode trust and can amplify panic and operational impact. The advisory highlights the importance of cross-functional teams, pre-defined authority, and synchronized communication workflows to ensure timely and accurate information sharing, acknowledging that simply providing ‘good’ communication isn’t enough – organizations need to prioritize accountability and demonstrate a genuine understanding of the impact on stakeholders.
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. A user tries to start their workday, but their laptop is stuck in a ‘blue screen of death’ loop. Halfway across the world, someone tries to post on X—nothing loads. These are the real-world ripple effects of a global outage where users know there’s a problem, but details are limited.
Despite more breaches and incidents triggering mandatory disclosures, users are often still left in the dark because companies prioritize liability protection over helping people understand what really happened. The problem compounds when those incidents lead to widespread and highly disruptive outages that can last for days or weeks, whether they stem from threat actors or internal errors.
Issues with ‘effective communication’ during IT and operational technology (OT) service outages led the Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI and international partners, to publish a "Communicating Under Pressure: Best Practices for Service Providers" advisory this month. The authoring agencies defined effective crisis communication as transparent, one that skips the PR spin and explains the root cause analysis to help users minimize operational impact.
"Service outages alone have the potential to cause enough damage, disruption, and societal panic without speculation and uncertainty from end users and the public as added factors," the advisory stated.
Key takeaways urged providers to communicate immediately, provide actionable guidance, be transparent and share what they do and do not know, and be accountable and iterative with continuous updates; all while maintaining compliance and reporting requirements. All 50 U.S. states have laws mandating reporting of data breaches and many federal agencies, from CISA to the Securities and Exchange Commission to the U.S. Department of Health, require prompt reporting.
Technical vs. Practical
Attack transparency is an ongoing issue across the industry, even as the industry consensus has shifted from “If you’ll be breached” to “When you’ll be breached.” Companies worry about how disclosures will affect their reputations, customer relations, and finances.
The advisory represents a deliberate effort to reframe breach communications where candid disclosure becomes a more expected standard. But CISA is responding to an even broader problem: trust, explains Chris Novak, partner and co-founder of Quadrum Advisors.
Novak found it interesting how CISA worded the advisory. The agency didn’t tell companies to simply communicate more, but rather called for clarity, accountability, and transparency. The advisory even warned organizations to focus on actionable information rather than reputation management, and to avoid leading with generic reassurances or marketing language, he adds.
"That language suggests to me that policymakers have seen incidents where technically accurate corporate communications were nevertheless not particularly useful," Novak tells Dark Reading.
Traditionally, organizations treat incident communications as something to be managed primarily through legal, communications, and public-relations processes. This naturally creates incentives to minimize statements, avoid attribution, reduce liability, and say as little as possible until all the facts are established, he explains.
Novak observed this trend more times than he can count over the course of the last two decades of helping clients navigate data breaches.
The objectives may be legitimate. However, they conflict with what customers, boards, regulators, investors, employees, and the public actually need during a major disruption, he warns.
“Communication Gaps Amplify Panic”
The timing of the advisory aligns with how outages have become more visible, more interconnected, and more disruptive across both IT and OT environments, explains Meredith Schnur, U.S. and Canada cyber practice leader for Marsh Specialty.
Schnur has noticed that recent incidents highlighted how when critical services go down, the technical issue is only part of the problem. Communication gaps are the other, and they can amplify confusion, panic, and operational impact, the same concerns CISA outlined in the advisory.
Schnur believes it is likely that CISA published the advisory at this time due to a recurring communication pattern: inconsistent updates, vague statements, delayed disclosure, and mismatched messaging between technical teams, leadership, legal, and public affairs.
"We feel that it reflects a need to improve communications, but it is better read as ‘best practices and readiness are uneven’ rather than ‘everyone is doing it badly’,” Schnur tells Dark Reading.
While the advisory can raise expectations, it is not a substitute for accountability, says Schnur. Broader change will likely require a combination of regulatory enforcement, board oversight, contractual and insurance requirements, litigation exposure, and customer pressure.
Now that CISA and the FBI have established best practices for effective communication, it will change the standard against which companies are judged. Expectations moving forward may shift from “disclose what companies are legally required to disclose” toward “communicate what company stakeholders reasonably need to manage their own risk,” and that’s a considerably higher bar, says Novak.
“That’s more important than most people realize,” he says. “For perspective, one of the most common questions our team hears in the boardroom is: ‘What are other organizations similar to us doing?’”
While the advisory may improve transparency at the margins, it is not a substitute for accountability, says Schnur. Now that CISA and the FBI have established best practices for effective communication, it will change the standard against which companies are judged.
Experts Weigh in On Key Recommendations
Novak, Schnur, and Reynolds agree that effective communication needs to start before organizations suffer an attack. Organizations need to decide who will be in charge and include preparations during tabletop exercises.
It's essential that decisions are made prior to an attack, and that’s why the advisory emphasizes cross-functional teams, predefined authority, synchronized technical, legal, and communications workstreams, and prewritten playbooks, says Novak.
“Even before the advisory was released, we had been seeing a slow but steadily increasing demand from customers looking for help in these areas,” Novak reveals. “I expect we will see the pace continue to accelerate. It will be interesting to reassess in six months or a year.”
Empathy without spin is another key ingredient frequently missing from communications, he adds, pointing back to the broader trust problem. If a customer's manufacturing line is stopped, hospital operations are impaired, or employees can't work, telling them that the company is “committed to delivering world-class service” isn’t particularly helpful.
Instead, acknowledge the impact, explain next steps, tell them what they should do, and when they will receive updates, he recommends.
“Trust isn’t preserved by pretending the incident isn’t serious,” he says. “It’s often preserved by demonstrating that you understand how serious it is.”
Balance is also key. Don’t share too much too soon, warns Schnur. Key facts can change as an incident unfolds and it may look worse to correct earlier statements. CISA focused on external communications in the advisory, but internal communications matter just as much, she adds.
Attacks on service providers and suppliers can be particularly damaging because of the supply chain scope. The situation is made worse by threat actors leveraging artificial intelligence to propagate their access downstream drastically faster than they could before, warns Jake Reynolds, head of security engineering at Coalition.
For Cloudflare, good incident communication starts with being timely, clear, and transparent. In the November outage, the company quickly acknowledged the incident and apologized to users.
“During incidents, we always aim to provide ongoing updates and publish a detailed post-mortem within about 12 hours, outlining what went wrong and how we responded,” Grant Bourzikas, chief security officer at Cloudflare, tells Dark Reading. “It’s also important to lay out the safeguards that are being put in place moving forward, and the ways you intend to hold yourself accountable to customers moving forward. Outages and bugs happen, but being transparent about them and sharing lessons learned is critical to maintaining customer trust.”
Cloudflare adds that it is dedicated to transparency and accountability to its customers, and that they are excited to see this reinforced by the CISA advisory, “as it’s an approach we hope to see adopted across the industry.”
In a statement to Dark Reading on the timing of the advisory, Chris Butera, acting CISA executive assistant director said that changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to minimize operational impact, limit speculations, and preserve trust.
Butera reiterated that the guidance was informed by real-world events, like the Cloudflare outage, and supports the CI Fortify initiative, which “provides information and resources that help critical infrastructure organizations prepare to isolate and recover their vital OT systems during a major cyber incident or crisis.”
