The CISA and the FBI, alongside cybersecurity agencies from Australia, Canada, New Zealand and the UK, have released new guidance for communicating during major IT and OT outages, warning that poor communication can compound the operational damage caused by an incident.
The agencies specifically advise organizations to avoid PR and marketing language, clearly state what is known and unknown, and provide customers with technical and actionable information rather than vague descriptions such as “service degradation.”
The guidance recommends that organizations establish outage communication plans before an incident, including predefined thresholds for when notifications are required, designated spokespeople, backup communication channels and procedures for reaching customers, regulators and critical infrastructure operators.
During an outage, providers should explain which systems are affected, the scope and operational impact, and the known cause without speculating when an investigation is still underway. The agencies also call for continuous, time-stamped updates throughout an outage, including recovery milestones and actions being taken.
Joshua Marpet, Senior Product Security Consultant, Finite State:
“Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great. Companies will use whatever language their crisis communications firm advocates for, because that is how they avoid liability. Firms with the backbone to be open, honest, and transparent are not exactly the majority out there. Unless you have communication strategies mandated, you have an perfect example of Marpet’s law “Unless it’s mandated, or someone is paying for it, ain’t gonna happen”
“The EU CRA is a great example of mandating that type of communication. 24 hours, 72 hours, and 14 days, after an incident, there are specific types of communications with defined pieces of data you MUST give to the public and stakeholders. This is what we need, not best wishes and prayers.”
Denis Calderone, CTO, Suzu Labs:
“Let’s be honest, at a high level, none of this is new. Cross-functional incident teams, designated spokespeople, escalation paths, time-stamped updates, practice transparency. All of that has been in every incident response framework going back to NIST 800-61. Where this guidance actually adds value is in the operational specifics and the timing. It explicitly tells organizations to assume that their own telecommunications and primary communication channels may be disrupted or unreliable during a crisis. That means establishing and testing backup methods like radios, SMS phone trees, and out-of-band channels before you need them. When I run tabletop exercises for clients, one of the first things I do is take their communications down. Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for.
“The timing also matters. This drops alongside CISA’s CI Fortify initiative, which tells critical infrastructure operators to prepare to deliberately disconnect OT systems from third-party networks during a geopolitical crisis. If you’re a water utility or a power plant making a real-time decision about whether to isolate, you need your service providers telling you exactly what is happening and what is not happening. The guidance specifically calls for articulating “what it is and what it is not” to prevent misattribution. After the year we’ve had with attacks against water utilities, ports, power generation, and PLC suppliers, CISA clearly does not want the next big CI outage to trigger days of “was this a nation-state attack?” speculation while downstream operators are making blind isolation decisions.
“What gives this more weight than a typical government advisory is who helped write it. Microsoft, Sophos, Cloudflare, and American Water all contributed. Cloudflare’s November 2025 outage is explicitly cited as an informing event, and for good reason. Their status page went down during the incident, their own response team initially misidentified the root cause partly because of the communication breakdown, and the whole thing spiraled. The organizations that have been through it are helping write the playbook, and that gives the operational details real credibility.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I think everything in this plan is great. There’s just one area I wish they would address more directly. When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls.
“During a breach of this nature, one of the biggest communication problems is often figuring out who’s on first and who’s on second. Who can actually make the call? Who has the authority to shut down access?
“What often happens is that the decision gets escalated again and again and again until it eventually reaches a director, CEO, commissioner, or some other senior official who has enough authority to make the call. Meanwhile, valuable time is being lost.
“Incident response plans need to go deeper than motherhood and apple pie statements about communicating with customers, coordinating between organizations, and keeping everyone informed. That’s all important, but the plan needs to explicitly identify who has the authority to make the really hard decisions during an incident.
“Just as importantly, there needs to be political cover for the people who make those decisions.
“Hindsight is always 20/20. After an incident, everyone gets to sit around and analyze whether shutting something down was absolutely necessary. The person making that decision in the middle of an active breach doesn’t have that luxury.”
Notifications should never be like Apple release notes of “bug fixes and performance improvements”. They should have clear communication in them 100% of the time. Organizations need to work on that now.
UK considers new powers to shut down dangerous AI and block risky tech suppliers
Posted in Commentary with tags UK on September 3, 2026 by itnerdUK lawmakers are considering giving the government emergency powers to deactivate powerful AI systems and shut down data centers if the technology poses a national security threat.
The proposed “kill switch,” introduced as an amendment to the Cyber Security and Resilience Bill, is intended as a last-resort mechanism to stop a runaway AI system before it can compromise critical national infrastructure.
At the same time, the UK government has introduced separate amendments to the same cybersecurity bill that would allow ministers to prevent critical infrastructure organizations from using technology suppliers deemed high risk. The new authority is aimed at supply-chain threats, where attackers can compromise a smaller technology provider and use its access to reach more sensitive organizations.
The move follows a recent cyberattack that forced a small UK power generation facility offline for four days.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A government-mandated remote shutdown capability for data centers is a pre-installed denial-of-service mechanism waiting for the wrong hands. The amendment to the UK’s Cyber Security and Resilience Bill would require operators to build and maintain the exact infrastructure an attacker would need to cause the disruption the legislation claims to prevent. Compromise the authorization channel, and the government has handed the attacker a shutdown switch labeled “safety.”
“Responsibility for containing an AI system sits with the operator running it. If you’re deploying AI on critical infrastructure and cannot kill your own workload when it goes sideways, a minister reaching for a centralized override just confirms nobody expected operators to manage their own systems.
“Cybersecurity minister Baroness Lloyd rejected the proposal, arguing that directing an organization to stop using a specific AI model is more proportionate than shutting down shared infrastructure thousands of services depend on. She’s right.
“The supply-chain provisions in the same bill, letting ministers block critical infrastructure operators from using high-risk technology suppliers, respond to something real. An Iran-linked cyberattack forced a small UK energy generator offline for four days in July. Controlling which vendors touch critical networks addresses the entry point. A kill switch addresses the blast radius after the breach has already happened, and it does so by adding a new attack surface to defend.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I feel like conversations like this in legislatures around the world are incredibly important, and I think many of the provisions being discussed absolutely should be put in place.
“However, I also think the way the conversation is arcing fundamentally misses the point of what AI actually is.
“AI is not something that can be controlled simply by regulating powerful companies like Anthropic, Google, and OpenAI. The technology is already dispersed. With roughly $5,000 worth of hardware, someone can run a highly functional model locally that may be slower than the most powerful commercial models, but can potentially be every bit as destructive.
“If our entire strategy for AI safety is built around restricting what large companies can do with potentially dangerous models, we’re addressing only one part of the problem. Those restrictions may be valuable, but they don’t address what happens when capable models are downloaded, modified, fine-tuned, and operated completely outside those environments.
“There needs to be a much larger conversation about mitigating controls. We need to be thinking about how organizations detect and respond to AI-enabled attacks, how infrastructure is protected when the attacker has access to these capabilities, and what defensive technologies need to change when powerful AI is available to practically anyone willing to invest a few thousand dollars in hardware.
“Regulating the largest AI companies may be part of the answer.
“It cannot be the entire answer.”
I seriously doubt that this is the answer. Thus I hope this gets the time and consideration that this does deserve.
Leave a comment »