The Cybersecurity and Infrastructure Security Agency (CISA) has urged service providers to prioritize clear, timely, and transparent communication during major IT or operational technology (OT) outages. In newly published joint guidance, Communicating Under Pressure: Best Practices for Service Providers, CISA, the FBI, and international partners outlined how organizations should prepare for and manage outage communications affecting customers, critical-infrastructure operators, government entities, and the public. Published September 2, 2026, the guidance applies to disruptions caused by cyberattacks, human error, equipment failures, natural hazards, or defensive actions such as isolating systems during an incident.

Without reliable updates from providers, affected organizations and end users might base their understanding of the outage's scope and duration on incomplete information, social-media claims, or unverified reports.

Service providers should establish communication processes before an outage occurs, including designated decision-makers, approved escalation paths, alternate communication channels, and procedures for engaging customers and government partners. For instance, a provider may confirm connectivity failures are being investigated, outline restoration work is underway, identify available workarounds, and commit to a specific time for the next status report. The guidance aligns with CISA’s CI Fortify initiative, which offers resources to help critical infrastructure entities isolate and recover vital OT systems during major cyber incidents.