- CISA, FBI and international partner agencies have issued outage communications guidance
- The guidance details crisis-readiness structures and messaging best practices
- The 2026 Homeland Security Summit will explore AI, edge capabilities and more
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, the FBI and cybersecurity agencies of Australia, Canada, New Zealand and the U.K. have released guidance outlining best practices for communicating with stakeholders during IT and operational technology outages.

Disruptions to critical systems can quickly erode public trust and complicate recovery efforts when communication lags behind the response itself. Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 10 will feature panel discussions on building cyber talent alongside fielding unmanned systems, as well as protecting the homeland from complex security threats. The event will also explore artificial intelligence, counter-unmanned aircraft systems, federated data and identity, and edge capabilities. Register now to join the conversation.
CISA said Wednesday the document draws on lessons from real-world incidents and emphasizes transparency, clarity and accountability as core principles for service providers responding to major service disruptions, whether caused by malicious activity, human error, equipment failure or natural hazards.
How Should Organizations Prepare a Service Outage Communications Plan?
The guidance calls on service providers to build a communications plan that defines triggers, escalation paths and procedures, supported by templates for status updates and stakeholder notices. It identifies several structures organizations should put in place before a crisis occurs:
- Cross-functional incident team. Bring together engineering, communications, legal, compliance and customer support staff, with backup points of contact identified in advance.
- Government relations lead. Assign a contact to keep messaging to government stakeholders aligned with public statements.
- Defined roles and authority. Designate an incident lead, a communications lead and a single spokesperson with clear approval paths.
- Synchronized workstreams. Keep technical, communications and leadership teams working in parallel through designated liaisons and scheduled syncs.
- Legal team involvement. Ensure legal counsel reviews messaging for regulatory and contractual alignment throughout an incident.
- Backup communication channels. Test alternative methods, such as SMS, phone trees and out-of-band systems, for use when primary systems are unavailable.
- Rehearsed playbooks. Review and exercise communication procedures regularly, including through tabletop exercises.
- Internal-external consistency. Provide staff with approved talking points to keep messaging aligned across audiences.
What Are the Key Elements of Effective Messaging?
The guidance also details how service providers should structure the content of their communications once an incident occurs:
- Understand the issue. Share confirmed facts early and avoid premature conclusions while a root cause remains under investigation.
- Know the audience. Tailor messaging separately for technical teams, executives, customers, regulators and the general public.
- Lead with a concise summary. Present a bottom-line-upfront statement covering affected systems, user impact and known cause, without speculation.
- Practice transparency and accountability. State what is known and unknown, use a single source of truth for updates, and avoid marketing language.
- Provide continuous, time-stamped updates. Share a clear timeline of the incident and recovery milestones, even when there is no new information to report.
- Maintain regulatory compliance. Align messaging with legal counsel and coordinate with government or law enforcement partners before making attribution statements.
- Incorporate security improvements. Address lessons learned in post-incident communications, including vulnerability management and secure-by-design commitments.
The guidance was informed by contributions from industry partners, including Microsoft, Sophos, Cloudflare and American Water.
How Does the Guidance Align With CISA’s Other Cybersecurity Efforts?
CISA has announced several cybersecurity initiatives this year. Earlier in 2026, the agency issued a logging reference architecture to improve visibility across federal networks, followed by a risk-based vulnerability patching directive directing agencies to prioritize the flaws that pose the greatest risk.
CISA has also moved on the critical infrastructure side, releasing a red team advisory to sharpen defensive practices and launching the CI Fortify initiative to strengthen sector-wide security.
In parallel, the agency issued a directive addressing risks tied to unsupported edge devices, reflecting a broader push to close gaps across federal and critical infrastructure networks.






