Skip to main content
CybersecurityIncident Response

CISA Warns Against PR Spin in IT Outages

Government briefing room with podium, chairs, and laptop in foreground.

"Effective communication begins with a factual summary tailored to predefined audiences, avoids PR spin, and adheres to regulatory requirements," the guide states.

CISA and FBI issue plain-language playbook

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) published joint best practices aimed at organizations that must communicate during IT or operational-technology (OT) outages and other disruptive events. The agencies instruct organizations to prioritize transparency, to "avoid PR spin," and to provide frequent, iterative updates that clearly separate what is known, what is unknown, and what remains under investigation.

The guide directs service providers to tailor factual summaries to predefined audiences and to adhere to applicable regulatory requirements while sharing information. It also explicitly recommends articulating “what it is and what it is not” to reduce misattribution during incidents.

Practical specifics: backup channels and timing

Security practitioners quoted in the guidance emphasize operational detail. Denis Calderone, CTO of Suzu Labs, notes the guidance is not new in principle—cross‑functional incident teams, designated spokespeople, escalation paths, and time‑stamped updates are standard incident‑response fare—but he says the value lies in operational specifics and timing. The advisory tells organizations to assume primary communications—telecommunications, email, status pages, and collaboration tools—may be disrupted during a crisis, and to establish and test backup methods such as radios, SMS phone trees, and out‑of‑band channels before an incident.

Calderone describes how he runs tabletop exercises that begin by taking communications down—email, Teams, status pages—forcing teams to coordinate under degraded conditions. The guidance aims to build plans that withstand those real‑world failures rather than idealized scenarios.

Cloudflare, Microsoft, Sophos, American Water: vendors helped write it

The advisory’s operational credibility is bolstered by private‑sector contributors. Microsoft, Sophos, Cloudflare, and American Water all contributed to the guidance, and the document explicitly cites Cloudflare’s November 2025 outage as an informing event. The Cloudflare incident is used as an example where a status page went down, the vendor’s response team initially misidentified a root cause in part because of the communication breakdown, and the incident escalated as a result.

That real‑world involvement, the guidance says, shaped recommendations that go beyond platitudes and toward the concrete steps organizations should take when communications pathways themselves are part of the failure mode.

Authority, decision‑making, and political cover: John Strand’s warning

John Strand, owner of Black Hills Information Security, raises a governance challenge the guidance touches only indirectly: who is authorized to shut down network access and whether the people making those operationally critical calls have political protection afterward. Strand warns that, in practice, decisions about isolating network segments or taking systems offline frequently escalate until a senior official—director, CEO, or commissioner—has the final say, and by then valuable time can be lost.

Strand argues incident response plans must go deeper than general statements about coordination and customer communication; they must explicitly identify decision authorities and ensure decision‑makers are protected from punitive second‑guessing after the fact. Without such delineation and cover, he suggests, organizations risk paralysis in the moments when swift decisions matter most.

Joshua Marpet and the case for mandated communications

Joshua Marpet, senior product security consultant at Finite State, welcomes the emphasis on clear, timely updates and the admonition to avoid marketing language, but he warns the guidance may fall short without mandates. Marpet summarizes his skepticism with his own aphorism—“Unless it’s mandated, or someone is paying for it, ain’t gonna happen”—and points to the EU’s Cyber Resilience Act (CRA) as an example of regulatory language that requires specific communications on defined schedules: 24 hours, 72 hours, and 14 days after an incident, with mandatory data elements each time.

For Marpet, voluntary advice from agencies is useful; true change, he says, follows mandates that impose concrete disclosure duties and timelines.

Where this guidance lands and what it leaves in motion

  • Technologists and security teams: The guide provides actionable practices to test degraded communications—radios, SMS trees, out‑of‑band channels—and to prepare time‑stamped, audience‑specific factual summaries that explicitly state what is and is not known.
  • Critical infrastructure operators: The guidance dovetails with CISA’s CI Fortify initiative by stressing clear messaging during deliberate OT isolation decisions and by aiming to prevent speculation about attribution that could hamper real‑time operational choices.
  • Regulators and procurement leaders: The document’s reliance on vendor contributors and cited examples like Cloudflare’s November 2025 outage and the EU CRA’s mandatory timelines frames a debate about whether voluntary best practices are sufficient or whether mandated incident communications should become standard.

The joint CISA‑FBI guidance aims to replace speculation and public relations sleight‑of‑hand with frequent, factual updates and tested backup communications. Contributors from major vendors and a cited industry outage give the playbook operational heft; critics argue the remedy will be incomplete without clearly codified authorities and mandates to ensure organizations actually follow the prescription. Which of those approaches will govern real incidents—voluntary best practice or binding requirement—remains the practical question the guidance seeks to influence.

Original story