Skip to content
← All articles
Top Cybersecurity News·September 2, 2026·Cybersecurity PSA

Communicating Under Pressure: Best Practices for Service Providers

Voice options

Voice names come from your browser and device.

CISA Cybersecurity Advisories & Alerts ↗
TL;DR
The fast version

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment…

Detailed briefing

What happened

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages.

Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors.

What is verified

The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.

CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis.

For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and…

Why it matters

Cybercrime prosecutions can reveal the scale, methods, and downstream impact of criminal campaigns, but a guilty plea or charge is not the same thing as a new breach notification. The security lesson is in the access methods, affected services, and types of information criminals were able to obtain.

What you should do

Organizations should use the case as a reason to review account protections, access logging, privileged access, and multifactor authentication on cloud and administrative systems. Consumers should pay attention to breach notifications from affected companies and take action based on the data those companies confirm was exposed.