CISA and FBI Release Crisis Comms Guidance for IT/OT Outages
The guidance covers principles like clarity, accountability, and transparency but stops short of mandated timelines, template libraries, or notification protocols, providers still have to build their own playbook.
TL;DR
CISA and the FBI published joint guidance on crisis communications for service providers managing IT and OT outages. The document walks through core messaging principles (clarity, accountability, transparency) and stresses the need to plan for cascading disruptions and unreliable telecoms during incidents. It's advisory, not a mandate. No templates, no specific notification timelines for customers or law enforcement, and no framework for resolving the tension between early disclosure and investigative holds. Providers who already have a crisis comms plan won't find new obligations here; those who don't have a starting point.
The guidance, developed with international partners, addresses a real operational gap: when an OT or IT outage hits, the provider's communications cadence can either contain the damage or amplify it. The document is built around the premise that "service outages can create disruption and societal panic even without speculation," and that cascading failures across interconnected systems make early, accurate messaging essential.
CISA and the FBI recommend that organizations have crisis communications plans in place before an incident, including backup communication methods. The guidance also flags that "telecommunications services may be disrupted or otherwise unreliable" during an emergency, so providers should not assume normal channels will be available.
What the guidance doesn't provide is equally notable. There are no template statements for different incident classes, ransomware vs. equipment failure vs. nation-state intrusion each carry different disclosure obligations and stakeholder sensitivities, but the document treats "outage" as a single category. There is no framework for what "timely" means when law enforcement asks a provider to delay public disclosure during an active investigation. And there are no specific notification protocols for customers, regulators, or law enforcement, just the principle that communication should happen.
For MSPs, C3PAOs, and primes doing OT or critical infrastructure work, the guidance does not introduce new regulatory requirements. It references CISA's CI Fortify initiative, which provides resources for isolating and recovering OT systems during a crisis, but the communications piece itself is a set of best practices, not a compliance framework. Organizations that have already worked through crisis communications as part of their incident response planning will recognize the terrain. Those that haven't now have a documented starting point to point to when building internal buy-in.
Published ·Deep Fathom