Communicating Under Pressure: Best Practices for Service Providers (2026-09-02)
CISA, FBI, and international partners published guidance on crisis communications during IT and OT outages. The guidance emphasizes clarity, accountability, and transparency to manage stakeholder expectations during service disruptions caused by cyber incidents or other hazards. It recommends critical infrastructure organizations prepare backup communication methods, assuming telecom services may be unreliable.
Detection / Hunteropenrouter
What Happened
Government and international cybersecurity agencies released a guide on how to communicate clearly during IT and operational technology outages. The guide is for service providers and critical infrastructure operators who need to inform stakeholders and the public when services go down due to cyberattacks, accidents, or natural disasters. This matters because poor communication during outages can cause panic and erode trust, especially when outages cascade across interconnected systems. Organizations should review the guidance to build crisis communication plans that include backup communication methods in case primary networks fail.
Key Takeaways
- Guidance covers planning and executing communications during IT and OT outages caused by cyber threats, human error, or natural hazards.
- Core principles for crisis messaging are clarity, accountability, and transparency.
- Outages at one organization can cascade across interconnected systems, increasing uncertainty and alarm.
- Critical infrastructure organizations should assume telecommunications services may be disrupted during a major cyber incident.
- Organizations need crisis communications plans that integrate backup communication methods and align with legal, operational security, and law enforcement requirements.
Affected Systems
- Operational Technology (OT) systems
- IT systems
- Critical infrastructure telecommunications services
Vulnerabilities (CVEs)
None identified.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules are provided in this article.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | None | The article is a communications guidance document and does not discuss endpoint detection or technical threat indicators. |
| Network Visibility | None | The article does not discuss network monitoring or technical network indicators of compromise. |
| Detection Difficulty | N/A | The article does not cover technical detection of threats. |
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| N/A | N/A | N/A | N/A |
Control Gaps
- The article highlights a potential gap in crisis communications planning rather than technical security controls.
False Positive Assessment
N/A
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider reviewing the CISA guidance to assess whether your current crisis communications plan covers IT and OT outage scenarios.
Infrastructure Hardening
- Evaluate whether your critical infrastructure OT systems have documented isolation and recovery procedures that align with the CI Fortify initiative.
- Consider identifying and testing backup communication methods in case primary telecommunications services are disrupted.
User Protection
- Consider training service desk and communications staff on the core principles of clarity, accountability, and transparency during service outages.
Security Awareness
- Consider rolling crisis communication expectations into existing security awareness programs so staff understand their roles during IT or OT outages.