CISA, Partners Issue Guidance for Critical Infrastructure Crisis Comms
12:17
Thu | Sep 3, 2026 | 12:42 PM PDT

When a service goes down, the outage itself is only half the crisis. The other half is silence; or worse, a status page full of hedging and marketing language while customers, network defenders, and critical infrastructure operators are left guessing whether they're under attack. On September 2, 2026, six government agencies decided that guessing game has gone on long enough.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom jointly released "Communicating Under Pressure: Best Practices for Service Providers," a nine-page guide that treats crisis communication not as a PR afterthought but as a core pillar of incident response—on par with technical remediation itself. It's a notable move: for the first time, the same coalition of agencies that typically publishes indicators of compromise and patching timelines is now telling companies, in effect, how to talk during a crisis, not just how to fix it.

The guidance doesn't bury its inspiration. It opens by pointing to the November 18, 2025, Cloudflare outage—a roughly six-hour disruption that knocked out access to a wide swath of the internet, including major platforms and AI services, after a routine database permissions change caused a bot-management configuration file to balloon past a hard-coded size limit. The resulting crash cascaded across Cloudflare's global network, and because an estimated one-fifth of web traffic passes through the company's infrastructure, the failure of one internal file rippled into an internet-wide event.

Cloudflare's own post-incident review made clear the outage wasn't malicious—it was an internal engineering failure, not an attack. But in the anxious minutes and hours before that was confirmed, the absence of clear, authoritative information was itself a kind of damage: uncertainty bred speculation, and speculation bred more uncertainty. That dynamic, not the outage itself, is precisely what the new guidance is designed to prevent.

Notably, the acknowledgments section credits Microsoft, Sophos, Cloudflare, and American Water as industry partners who informed the document, suggesting the guidance draws on lessons from more than one high-profile incident, not just the Cloudflare incident.

The core problem the agencies are solving

The guidance identifies a specific failure mode that shows up again and again during major incidents: organizations either say nothing while they chase perfect certainty, or they say too much, too fast, and have to walk it back later. Both failures erode trust. Both also create a vacuum that gets filled—by the press, by social media, and increasingly, given what the document calls "evolving and heightened geopolitical tensions," by speculation about nation-state involvement that may or may not be warranted.

The agencies' answer is a five-part standard for what good outage communication looks like:

  • Immediate — Acknowledge the problem quickly, rather than waiting for full certainty.

  • Technical — Give audiences actionable guidance, not vague reassurance.

  • Transparent — State plainly what's known, what isn't, and what's still under investigation.

  • Accountable — Own the organization's responsibilities and the outcome.

  • Iterative — Keep updating, even when there's nothing new to report.

That last point is easy to overlook but central to the guidance's philosophy: a timestamped update that says "no change since our last report" is treated as more valuable than silence, because it signals the organization is still actively engaged.

The document is organized less as abstract principle and more as an operational playbook, and a few recommendations stand out as genuinely prescriptive rather than aspirational.

Build the team before you need it

The guidance calls for a cross-functional incident structure established well ahead of any crisis: an incident lead who orchestrates technical response, a communications lead who manages the flow of information internally and externally, and a single designated spokesperson—described as the sole public-facing voice authorized to answer reporter questions. Legal counsel, risk and compliance staff, and—where government stakeholders are affected—a government relations lead round out the team. The document is explicit that these roles need predefined approval paths and escalation criteria worked out in advance, not improvised mid-incident.

Assume your normal channels might be gone

Perhaps the most operationally significant recommendation is the call for backup communication methods—SMS trees, radios, out-of-band messaging, conference bridges—that are regularly tested for moments when primary systems are degraded or compromised. This isn't a throwaway line. It reflects a scenario the guidance takes seriously: an organization whose website, support portal, email, and single sign-on all depend on the very system that just failed may find itself unable to publish the message its customers most need to see. The guidance's broader warning that critical infrastructure operators should assume telecommunications may be unreliable during a crisis extends that logic sector-wide.

Lead with the bottom line, not the caveats

For actual messaging content, the guidance is blunt: front-load the facts, not the reassurances. It specifically flags vague language like "service degradation" as something to avoid, and asks organizations to state affected systems, what users experienced, and the scope and known cause—without speculation—right at the top of any update. Marketing language and generalities are called out explicitly as things to avoid front-loading.

Segment the message by audience

The guidance recommends organizations maintain distinct communications tracks for enterprise IT and security teams, affected customers and employees, government partners and regulators, critical infrastructure owners and operators, and the media and general public—each of whom needs different levels of technical detail and different calls to action.

To its credit, the document doesn't pretend transparency is unconditional. It draws a sharp line between non-malicious outages, where "forthcoming transparency should be the default," and active cyber incidents, where sharing too much detail—such as specific system configurations, indicators of compromise, or the state of an ongoing investigation—could tip off an attacker, compromise a law enforcement investigation, or expose other customers running similar setups to copycat targeting.

That's a genuinely difficult balance to strike in practice, and the guidance acknowledges as much: it asks organizations to use a "risk-informed approach" when deciding what technical detail to disclose, and to coordinate with government or law enforcement partners before making any public attribution statement about who caused an incident. For legal and communications teams, this is likely to be the hardest part of the guidance to operationalize; the document offers a principle, not a formula, for where exactly that line sits in a live incident.

Legal and regulatory guardrails—with a notable caveat for Australia

The guidance also walks through the legal obligations that outage communications can trigger: incident reporting disclosure rules, sector-specific mandates in industries like financial services and healthcare, and contractual service-level agreements. It recommends aligning all messaging with legal counsel and compliance teams and ensuring consistency between public statements and whatever eventually gets reported to regulators.

Worth flagging for any multinational service provider: despite carrying the Australian Cyber Security Centre's name among the co-authors, the document includes an explicit disclaimer that it reflects U.S. practice, not Australian law, and was not written with Australian reporting obligations in mind.

The guidance points readers toward separate resources—cyber.gov.au's incident reporting portal and guidance on Australia's Security of Critical Infrastructure (SOCI) Act—for that jurisdiction's specific requirements, and notes that information shared with the ACSC may be protected under Australia's "Limited Use" regime governing how the government can use incident data. It's a reminder that even a genuinely multinational guidance document can't fully paper over jurisdictional differences in breach notification law.

Where this fits: CISA's broader 'CI Fortify' push

The outage communications guidance doesn't stand alone. CISA explicitly connects it to CI Fortify, a nationwide initiative the agency unveiled earlier in 2026—and it's worth understanding CI Fortify to see the full strategic picture.

CI Fortify launched in May 2026 as a multi-year effort aimed at helping critical infrastructure operators across all sectors prepare to keep essential services running through a geopolitical crisis or conflict, even if adversaries manage to disrupt telecommunications, internet access, or the industrial control systems themselves. CISA Acting Director Nick Andersen framed it at the time as bolstering public health and safety, defense infrastructure, economic continuity, and national security by ensuring operators can isolate vital systems from harm, keep operating in that isolated state, and recover anything an adversary compromises.

The initiative rests on two pillars—isolation and recovery—and it was built against a specific threat backdrop: reporting around the launch tied it to concerns about nation-state groups like Volt Typhoon, which security researchers and government advisories have described as pre-positioning inside U.S. critical infrastructure networks rather than simply conducting espionage, raising the possibility of deliberate disruption timed to a future crisis. CISA also said it planned to add more than 300 positions to support the effort, with an emphasis on regional field operations and OT/ICS technical expertise.

The throughline to the September communications guidance is direct: CI Fortify asks operators to plan for isolating systems or losing connectivity altogether, and the new guidance supplies the communications playbook for exactly that scenario—how to keep customers and partners informed when the "outage" might be a deliberate defensive isolation rather than a failure. As the guidance itself puts it, changes in service availability—whether from an outage or from isolation as a defensive strategy—both require the same transparent, ongoing communication to help end-users limit speculation and preserve trust.

Coverage of the release has zeroed in on a genuinely underappreciated risk: the same infrastructure dependency that causes an outage often takes out an organization's ability to talk about it. If a company's status page, support portal, corporate email, and identity provider all sit behind the same failed system, a "communications plan" that lives entirely in that stack isn't a plan at all. IT teams routinely test backup infrastructure, failover, and disaster recovery: this guidance is a pointed reminder that far fewer organizations test whether they can actually reach customers and staff when the normal corporate stack is the thing that broke.

For service providers—particularly those in IT, energy, water, transportation, and communications, the sectors CISA explicitly names as the intended audience—the practical to-do list from this guidance is short but not trivial: write the outage communications plan now, name the spokesperson now, test the backup channels now, and pressure-test how legal, technical, and communications teams will actually coordinate under a countdown clock. The alternative, as the Cloudflare incident and the guidance's own framing suggest, is trying to build all of that for the first time while the outage is already underway.

Comments