Communicating Under Pressure: Best Practices for Service Providers
September 2, 2026
U.S. Cybersecurity and Infrastructure Security Agency
U.S. Federal Bureau of Investigation
Australian Cyber Security Centre
Canadian Centre for Cyber Security
New Zealand National Cyber Security Centre
U.K. National Cyber Security Centre
This document is distributed as TLP:CLEAR. Disclosure is not limited. Sources may use TLP:CLEAR when information
carries minimal or no foreseeable risk of misuse, in accordance with applicable rules and procedures for public release.
Subject to standard copyright rules, TLP:CLEAR information may be distributed without restriction. For more information on the Traffic Light Protocol, see Traffic Light Protocol (TLP) Definitions and Usage.
Executive Summary
Service outages impacting IT and operational technology (OT) systems can be
damaging and disruptive for customers, network defenders, critical infrastructure
owners and operators, and the general public. During incidents that reach or
exceed established thresholds, whether caused by malicious activity or a non-
malicious event, service providers must communicate effectively so end users can
minimize operational impact. This guide outlines how to prepare for effective
outage communications and key elements of clear, actionable messaging.
Effective communication begins with a factual summary tailored to predefined
audiences, avoids PR spin, and adheres to regulatory requirements. Service
providers should be transparent by sharing what is known, unknown, and under
investigation, while providing frequent, iterative updates as new information
emerges or circumstances change.
Key Actions:
Develop a communications plan with defined incident thresholds and target
audiences for communications.
Practice transparency and avoid PR/marketing language.
Provide technical information and a root cause analysis for end users.
Align all messaging with legal and regulatory requirements.
Intended Audience
Organizations: Government; Federal Civilian Executive Branch (FCEB); State,
Local, Tribal, and Territorial (SLTT); Critical Infrastructure.
Sectors: Critical Manufacturing, Information Technology, Energy, Water and
Wastewater, Transportation, Communications.
This publication was prepared by the CISA with contributions from the FBI, NCSC-UK, Cyber Centre, NCSC-NZ,
and ASD’s ACSC. It reflects best practice within the United States, not Australia. This document was not
prepared in consideration of Australian law and does not reflect the reporting obligations placed on Australian
companies.
For more information on Australian cyber incident reporting requirements, consider guidance on Australian
incident reporting obligations. For example:
Report | Cyber.gov.au
SOCI Act regulatory obligations
https://www.cisc.gov.au/resources-s...er-security-obligations-corporate-leaders.pdf
Information provided to the Australian Signal Directorate’s Australian Cyber Security Centre regarding a cyber
incident may be protected by the Limited Use regime, which protects how the information is used within the
Australian Government.
Roles: Defensive Cybersecurity Analysts, Executive Cybersecurity Leadership, Cybersecurity Legal Advisors, Technical Support Staff, Incident Responders, Public Relations Specialists.
Introduction...
Why It Matters...
Preparing Your Organization to Communicate Effectively...
Key Elements of Effective Messaging...
Key Takeaways...
Resources...
Disclaimer...
Continued:
https://www.ic3.gov/CSA/2026/260902.pdf