CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate

blocks spelling trust/truth
Source: AKart Design via Getty Images

A user tries to start their workday, but their laptop is stuck in a "blue screen of death" loop. Halfway across the world, someone tries to post on X, but nothing loads. These are the real-world ripple effects of a global outage where users know there's a problem but details are limited.

Despite more breaches and incidents triggering mandatory disclosures, users are often left in the dark because companies prioritize liability protection over helping people understand what really happened. The problem compounds when those incidents — whether they stem from threat actors or internal errors — lead to widespread and highly disruptive outages.

Issues with effective communication during IT and operational technology (OT) service outages prompted the Cybersecurity and Infrastructure Security Agency (CISA), along with the FBI and international partners, to publish the "Communicating Under Pressure: Best Practices for Service Providers" advisory this month. The authors define effective crisis communication as transparent, skips the PR spin, and analyzes the root causes to help users minimize operational impact.

"Service outages alone have the potential to cause enough damage, disruption, and societal panic without speculation and uncertainty from end users and the public as added factors," the advisory states.

Key takeaways urge providers to communicate immediately, provide actionable guidance, be transparent about what they do and do not know, and be accountable and iterative with continuous updates, while maintaining compliance and reporting requirements. All 50 US states have laws mandating reporting of data breaches, and many federal agencies, from CISA to the Securities and Exchange Commission to the US Department of Health, require prompt reporting.

Technical vs. Practical

Attack transparency is an ongoing issue across the industry, even as the industry consensus has shifted from "if you'll be breached" to "when you'll be breached." Companies worry about how disclosures will affect their reputations, customer relations, and finances.

The advisory represents a deliberate effort to reframe breach communications where candid disclosure becomes a more expected standard. But CISA is responding to an even broader problem: trust, explains Chris Novak, partner and co-founder of Quadrum Advisors.

Novak found it interesting how CISA worded the advisory. The agency didn't tell companies to simply communicate more but rather called for clarity, accountability, and transparency. The advisory also encourages organizations to focus on actionable information, rather than reputation management, and to avoid leading with generic reassurances or marketing language, he adds.

"That language suggests to me that policymakers have seen incidents where technically accurate corporate communications were nevertheless not particularly useful," Novak tells Dark Reading.

Traditionally, organizations treat incident communications as something to be managed primarily through legal, communications, and public-relations processes. This naturally creates incentives to minimize statements, avoid attribution, reduce liability, and say as little as possible until all the facts are established, he explains.

Novak has observed this trend more times than he can count while helping clients navigate data breaches over the past two decades, he says. The objectives may be legitimate, but they conflict with what customers, boards, regulators, investors, employees, and the public actually need during a major disruption, he notes.

'Communication Gaps Amplify Panic'

The timing of the advisory aligns with how outages have become more visible, more interconnected, and more disruptive across both IT and OT environments, explains Meredith Schnur, US and Canada cyber practice leader for Marsh Specialty.

Recent incidents have highlighted how technical issues are only part of the problem when critical services go down, she says. Communication gaps are the other, and they can amplify confusion, panic, and operational impact — the same concerns CISA outlines in the advisory.

Schnur believes it is likely that CISA published the advisory at this time due to a recurring communication pattern: inconsistent updates, vague statements, delayed disclosure, and mismatched messaging among technical teams, leadership, legal, and public affairs.

"We feel that it reflects a need to improve communications, but it is better read as 'best practices and readiness are uneven' rather than 'everyone is doing it badly,'" Schnur tells Dark Reading.

While CISA's guidance is beneficial for organizations across sizes and sectors, it is directed toward service providers. CISA says the guidance was informed by "real-world events such as the Nov. 18, 2025, Cloudflare outage" that disrupted services for almost six hours.

Attacks on service providers and suppliers can be particularly damaging because of the supply chain scope. The situation is worsened by threat actors leveraging artificial intelligence to propagate their access downstream drastically faster than they could before, warns Jake Reynolds, head of security engineering at Coalition.

For Cloudflare, good incident communication starts with timeliness, clarity, and transparency. In the November outage, the company quickly acknowledged the incident and apologized to users.

"During incidents, we always aim to provide ongoing updates and publish a detailed post-mortem within about 12 hours, outlining what went wrong and how we responded," Grant Bourzikas, chief security officer at Cloudflare, tells Dark Reading. "It’s also important to lay out the safeguards that are being put in place moving forward and the ways you intend to hold yourself accountable to customers moving forward. Outages and bugs happen, but being transparent about them and sharing lessons learned is critical to maintaining customer trust."

Cloudflare adds that it is dedicated to transparency and accountability to its customers and is excited to see this reinforced by the CISA advisory "as it's an approach we hope to see adopted across the industry."

In a statement to Dark Reading on the timing of the advisory, Chris Butera, acting CISA executive assistant director, said that changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to minimize operational impact, limit speculations, and preserve trust.

Butera reiterated that the guidance was informed by real-world events, like the Cloudflare outage, and supports the CI Fortify initiative, which "provides information and resources that help critical infrastructure organizations prepare to isolate and recover their vital OT systems during a major cyber incident or crisis."

Experts Weigh in on Key Recommendations

Quadrum's Novak, Marsh's Schnur, and Coalition's Reynolds agree that effective communication needs to start before organizations suffer an attack. Organizations need to decide who will be in charge and include preparations during tabletop exercises.

It's essential that decisions are made prior to an attack, and that's why the advisory emphasizes cross-functional teams; predefined authority; synchronized technical, legal, and communications workstreams; and prewritten playbooks, Novak says.

"Even before the advisory was released, we had been seeing a slow but steadily increasing demand from customers looking for help in these areas," Novak reveals. "I expect we will see the pace continue to accelerate. It will be interesting to reassess in six months or a year."

Empathy without spin is another key ingredient frequently missing from communications, he adds, pointing back to the broader trust problem. If a customer's manufacturing line stops, hospital operations are impaired or employees can't work, telling them that the company is "committed to delivering world-class service" isn't particularly helpful.

Instead, acknowledge the impact, explain next steps, tell them what they should do, and when they will receive updates, he recommends.

"Trust isn't preserved by pretending the incident isn't serious," he says. "It's often preserved by demonstrating that you understand how serious it is."

Balance is also key. Don't share too much too soon, Schnur warns. Key facts can change as an incident unfolds, and it may look worse to correct earlier statements. CISA's advisory focuses on external communications, but internal communications matter just as much, she adds.

'More Important Than Most People Realize'

Now that the message is out there — communications must evolve to be effective — will it do anything to boost breach transparency? Experts are leaning toward "yes." But meaningful change will depend on leadership culture, regulatory pressure, and incident response maturity, Schnur says.

Now that CISA and the FBI have established best practices for effective communication, it will change the standard against which companies are judged. Expectations moving forward may shift from "disclose what companies are legally required to disclose" toward "communicate what company stakeholders reasonably need to manage their own risk," and that's a considerably higher bar, Novak says.

"That's more important than most people realize," he says. "For perspective, one of the most common questions our team hears in the boardroom is, 'What are other organizations similar to us doing?'"

While the advisory can raise expectations, it is not a substitute for accountability, says Reynolds, expressing concern that the true target audience may not engage with the guidance without stronger incentives.

The advisory alone probably won't materially change organizational behavior, he says. Broader change will likely require a combination of regulatory enforcement, board oversight, contractual and insurance requirements, litigation exposure, and customer pressure.

"This may be the advisory's most important limitation," he says. "It tells organizations what good communication should look like, but it does not by itself make that behavior a priority for organizations that have little perceived downside for doing the minimum."

source: DarkReading