The CISA and the FBI, alongside cybersecurity agencies from Australia, Canada, New Zealand and the UK, have released new guidance for communicating during major IT and OT outages, warning that poor communication can compound the operational damage caused by an incident.
The agencies specifically advise organizations to avoid PR and marketing language, clearly state what is known and unknown, and provide customers with technical and actionable information rather than vague descriptions such as “service degradation.”
The guidance recommends that organizations establish outage communication plans before an incident, including predefined thresholds for when notifications are required, designated spokespeople, backup communication channels and procedures for reaching customers, regulators and critical infrastructure operators.
During an outage, providers should explain which systems are affected, the scope and operational impact, and the known cause without speculating when an investigation is still underway. The agencies also call for continuous, time-stamped updates throughout an outage, including recovery milestones and actions being taken.
Joshua Marpet, Senior Product Security Consultant, Finite State:
“Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great. Companies will use whatever language their crisis communications firm advocates for, because that is how they avoid liability. Firms with the backbone to be open, honest, and transparent are not exactly the majority out there. Unless you have communication strategies mandated, you have an perfect example of Marpet’s law “Unless it’s mandated, or someone is paying for it, ain’t gonna happen”
“The EU CRA is a great example of mandating that type of communication. 24 hours, 72 hours, and 14 days, after an incident, there are specific types of communications with defined pieces of data you MUST give to the public and stakeholders. This is what we need, not best wishes and prayers.”
Denis Calderone, CTO, Suzu Labs:
“Let’s be honest, at a high level, none of this is new. Cross-functional incident teams, designated spokespeople, escalation paths, time-stamped updates, practice transparency. All of that has been in every incident response framework going back to NIST 800-61. Where this guidance actually adds value is in the operational specifics and the timing. It explicitly tells organizations to assume that their own telecommunications and primary communication channels may be disrupted or unreliable during a crisis. That means establishing and testing backup methods like radios, SMS phone trees, and out-of-band channels before you need them. When I run tabletop exercises for clients, one of the first things I do is take their communications down. Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for.
“The timing also matters. This drops alongside CISA’s CI Fortify initiative, which tells critical infrastructure operators to prepare to deliberately disconnect OT systems from third-party networks during a geopolitical crisis. If you’re a water utility or a power plant making a real-time decision about whether to isolate, you need your service providers telling you exactly what is happening and what is not happening. The guidance specifically calls for articulating “what it is and what it is not” to prevent misattribution. After the year we’ve had with attacks against water utilities, ports, power generation, and PLC suppliers, CISA clearly does not want the next big CI outage to trigger days of “was this a nation-state attack?” speculation while downstream operators are making blind isolation decisions.
“What gives this more weight than a typical government advisory is who helped write it. Microsoft, Sophos, Cloudflare, and American Water all contributed. Cloudflare’s November 2025 outage is explicitly cited as an informing event, and for good reason. Their status page went down during the incident, their own response team initially misidentified the root cause partly because of the communication breakdown, and the whole thing spiraled. The organizations that have been through it are helping write the playbook, and that gives the operational details real credibility.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I think everything in this plan is great. There’s just one area I wish they would address more directly. When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls.
“During a breach of this nature, one of the biggest communication problems is often figuring out who’s on first and who’s on second. Who can actually make the call? Who has the authority to shut down access?
“What often happens is that the decision gets escalated again and again and again until it eventually reaches a director, CEO, commissioner, or some other senior official who has enough authority to make the call. Meanwhile, valuable time is being lost.
“Incident response plans need to go deeper than motherhood and apple pie statements about communicating with customers, coordinating between organizations, and keeping everyone informed. That’s all important, but the plan needs to explicitly identify who has the authority to make the really hard decisions during an incident.
“Just as importantly, there needs to be political cover for the people who make those decisions.
“Hindsight is always 20/20. After an incident, everyone gets to sit around and analyze whether shutting something down was absolutely necessary. The person making that decision in the middle of an active breach doesn’t have that luxury.”
Notifications should never be like Apple release notes of “bug fixes and performance improvements”. They should have clear communication in them 100% of the time. Organizations need to work on that now.
The CISA cuts critical infrastructure security services, concerns grow over the shrinking agency
Posted in Commentary with tags CISA on September 5, 2026 by itnerdThe CISA is ending six free cybersecurity assessment programs used by critical infrastructure operators to identify weaknesses in their defenses against ransomware, supply-chain attacks and other cyber threats.
The cuts include Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys.
The assessments provided hands-on assistance from CISA regional advisers to organizations including water utilities, hospitals, local governments and other operators that may not have the resources to pay for comparable private-sector security reviews. CISA says it is retiring the programs to reduce redundancy and will instead direct organizations toward its Cross-Sector Cybersecurity Performance Goals.
The move comes amid broader concerns about CISA’s ability to protect U.S. critical infrastructure following significant reductions in its workforce and budget. The agency has lost roughly one-third of its workforce, while its 2026 budget was cut by approximately $300 million.
Denis Calderone, CTO, Suzu Labs:
“My apologies to those I told to leverage these free resources recently. We’ve been pointing to those how lacked the bigger budgets to the CISA’s assessment programs. All six programs are gone now. The replacement is a self-service questionnaire that the people who built the original tools say doesn’t do the same job.
“The timing here stinks. CISA is weeks away from finalizing CIRCIA, which will require critical infrastructure operators to report cyber incidents within 72 hours and ransomware payments within 24 hours, and this comes just as they take away the testing tools. But, To be fair, we don’t really know how widely adopted these programs were in the first place. The scope is huge with 50,000 small water utilities alone, we doubt that CISA’s regional staff was ever going to reach all of them, and there’s no public data showing how many operators actually used the assessments or what the measurable impact was.
“We’ve been worried about CISA’s capacity all year. The agency lost roughly a third of its workforce over the last 18 months. When DHS announced plans to hire 600 new staff and CISA started extending offers for 329 mission-critical positions, it felt like maybe the rebuilding was starting. But as of late August, it’s unclear how many of those hires have actually come on board, and now we’re watching assessment programs get cut instead. This during a year where critical infrastructure attacks are continuing to increase.
“CSET is open source and older versions on GitHub still include all six retired assessment modules. CSET measures where you actually stand against specific security standards. The CPGs that CISA is pointing everyone toward are a prioritization framework that helps you figure out where to focus. They’re complementary tools, not interchangeable ones. Use CSET to diagnose your current state, then use the CPGs to prioritize what to fix first. What you won’t get anymore is a CISA regional adviser helping you interpret the results, but using both tools together is still better than using either one alone. Several states are also stepping up direct cybersecurity support for local operators. And if you’re a water utility, keep an eye on Project Watershed 250. It just launched in Texas with free vulnerability assessments and red-teaming, and it’s supposed to expand nationally.”
John Strand, Owner, Black Hills Information Security, Inc.:
“Do the people making these decisions have any access to the news?
“Right now, our critical infrastructure is under attack at a level we simply have not seen before. Water systems, energy, telecommunications, municipalities, and other critical infrastructure are actively being targeted. CISA itself warned in July about ongoing Iranian-affiliated attacks against operational technology and PLCs across multiple U.S. critical infrastructure sectors.
“And this is the moment we decide to start cutting the programs designed to help these organizations defend themselves?
“CISA is eliminating six free cybersecurity assessment programs used by critical infrastructure organizations, including ransomware readiness, cyber resilience, incident management, and infrastructure assessments. Many of the organizations relying on these programs are exactly the organizations that do not have the money or personnel to replace them with commercial services.
“This is crazy.
“We should be dramatically increasing the resources available to critical infrastructure organizations right now. We should be expanding free assessments, threat intelligence, training, and technical assistance, especially for small municipalities, rural hospitals, water systems, and utilities that simply cannot afford large cybersecurity programs.
“Instead, we’re pulling resources away from them while the attacks are increasing.”
The White House and the US government are failing US citizens when the CISA is needed the most. And they will likely come to the conclusion after they get pwned by everyone rather than taking proactive measures to stop that from happening.
Leave a comment »