What happened
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages.
Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors.
What is verified
The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.
CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis.
For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and…
Why it matters
Cybercrime prosecutions can reveal the scale, methods, and downstream impact of criminal campaigns, but a guilty plea or charge is not the same thing as a new breach notification. The security lesson is in the access methods, affected services, and types of information criminals were able to obtain.
What you should do
Organizations should use the case as a reason to review account protections, access logging, privileged access, and multifactor authentication on cloud and administrative systems. Consumers should pay attention to breach notifications from affected companies and take action based on the data those companies confirm was exposed.