CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages
CISA and FBI issued guidance urging service providers to deliver timely, transparent communications during major IT and OT outages.
CISA, with the FBI and international partners, released 'Communicating Under Pressure: Best Practices for Service Providers', urging providers to prepare crisis-communication procedures, provide timely status updates during IT/OT outages, and maintain out-of-band communication channels. The guidance warns that disruptions to telecom, cloud, energy, and water services can cascade across critical infrastructure. It aligns with CISA's CI Fortify initiative supporting IT/OT isolation and recovery.
- Pre-establish crisis communication procedures and channels before outages
- Maintain alternative channels like satellite comms and out-of-band messaging
- Avoid speculative attribution claims in initial notifications
- Guidance supports CISA's CI Fortify isolation-and-recovery initiative
Full article608 words · extracted from gbhackers.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance urging service providers to deliver timely, accurate, and transparent communications during major information technology (IT) and operational technology (OT) outages.
The document, titled ‘Communicating Under Pressure: Best Practices for Service Providers’, was developed with the Federal Bureau of Investigation (FBI) and international partners.
It explains how organizations should communicate during disruptions caused by cyberattacks, equipment failures, human error, natural hazards, or defensive isolation measures that interrupt critical services.
Service Providers to Provide Transparent Updates
CISA has warned that outages affecting telecommunications, cloud platforms, managed service providers, industrial systems, transportation networks, energy operations, and water utilities can quickly extend beyond the initially impacted organization.
A disruption in one service can lead to broader failures across interconnected suppliers, customers, government entities, and critical infrastructure operators. In such situations, incomplete messaging or prolonged periods without updates can fuel speculation, misinformation, operational confusion, and public anxiety.
The guidance emphasizes that organizations should not wait for an outage to decide who will communicate, which channels will be used, or how technical details will be verified.
Instead, providers should establish crisis communication procedures in advance and include communications personnel in incident-response planning, tabletop exercises, recovery operations, and executive decision-making.
CISA states that effective outage communications must balance transparency with legal obligations, law enforcement coordination, operational security, and containment efforts.
Service providers may not be able to disclose every technical detail during an active incident, especially if adversaries remain in the environment or if disclosure could reveal defensive measures.
However, organizations should still provide stakeholders with clear information about what is known, what remains under investigation, which services are affected, and what actions users should take.
Initial notifications should avoid unsupported attribution claims or speculative root-cause assessments. Instead, providers should acknowledge the disruption, identify affected service categories or geographic regions (if possible), describe immediate mitigation activities, and provide an expected timeframe for the next update.
For instance, a provider could state that a service interruption is affecting customer authentication or remote monitoring capabilities, confirm that investigation and restoration teams are engaged, advise customers on available workarounds, and commit to another update within a specific timeframe.
The advisory also notes that conventional communication systems may be unavailable during a major cyber incident. Organizations should assume that email, collaboration platforms, customer portals, voice services, and internet connectivity could be degraded or inaccessible.
Therefore, critical infrastructure owners and operators should maintain alternative communication mechanisms, including emergency phone trees, satellite communications, secure out-of-band messaging platforms, pre-established public status pages, radio systems, and contact lists maintained outside the production environment.
These communication channels should be tested regularly and integrated into business continuity and incident-response exercises. Providers should also ensure that communications teams can access approved messaging templates, legal contacts, executive escalation procedures, and technical status data without relying on compromised systems.
The guidance aligns with CISA’s CI Fortify initiative, which helps critical infrastructure organizations prepare to isolate and recover vital operational technology during major cyber incidents.
Isolation may be necessary to prevent attackers from moving between IT and OT environments. However, it can also impact visibility, remote access, automation, and customer-facing services.
CISA emphasizes that transparent, ongoing communications can help end users minimize operational disruption, reduce uncertainty, and preserve trust. For service providers supporting critical infrastructure, outage messaging should be treated as a core resilience capability, rather than merely a public-relations function.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/cisa-urges-service-providers-to-provide-transparent-updates/