CISA Calls for More Guidance, Less Spin, as Outages Escalate

CISA, FBI, and international partners release new advisory demanding radical transparency from service providers during major outages.

By Central
Highlights
  • CISA demands immediate communication from service providers during outages to reduce public uncertainty.
  • The advisory outlines four core pillars: immediate communication, actionable guidance, transparency, and accountability.
  • Critics argue the guidance lacks enforcement teeth, relying on regulatory and market pressure to drive change.

A blue screen of death. A loading spinner that never resolves. A terse, corporate apology that explains nothing. This is the frustrating, anxiety-inducing reality for millions of users caught in the crosshairs of major IT and operational technology (OT) outages. Despite an era of unprecedented breach disclosure mandates, the people actually affected by these digital blackouts are routinely left in the dark, fed opaque statements crafted more to shield companies from liability than to illuminate the path forward. In a direct and increasingly frustrated response to this pattern, the Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI and international partners, has published a starkly worded advisory. Titled “Communicating Under Pressure: Best Practices for Service Providers,” the document doesn’t just ask for better messaging; it demands a fundamental shift away from legalistic spin toward radical transparency.

The Advisory’s Core Demand: Transparency Over Spin

The explicit target of the new CISA guidance is the communications machinery that kicks into gear when critical services fail. The agencies argue that “service outages alone have the potential to cause enough damage, disruption, and societal panic without speculation and uncertainty from end users and the public as added factors.” The advisory is a direct counterweight to the default corporate posture of minimizing statements, avoiding attribution, and saying as little as possible until every legal fact is nailed down. Instead, CISA is calling for a new standard: immediate communication, actionable guidance that helps users triage their own risk, and a clear separation between what is known and what is still being investigated.

The document goes further by explicitly warning organizations to stop leading with generic reassurances, marketing language, or statements focused primarily on reputation management. The goal, according to the advisory, is to provide stakeholders—be they hospital administrators, critical infrastructure operators, or individual consumers—with the practical information they need to minimize operational impact. This represents a deliberate effort to reframe breach and outage communications from a legal risk mitigation exercise to a customer and public service obligation.

What Are the Key Principles of the CISA Advisory?

For organizations seeking a clear benchmark, the advisory outlines four core pillars of effective crisis communication. Communicate immediately, even if all the details are not yet available. Provide actionable guidance that end users and downstream customers can implement to reduce their own risk. Be transparent about what you know and, crucially, what you do not know. Finally, be accountable and iterative, providing continuous updates as the investigation unfolds and root causes are determined. This framework is designed to replace the long silences and vague statements that have become the painful hallmark of major outages.

Why This Advisory Now? The Escalating Pattern of Failure

The timing of the advisory is no accident. It has been informed by a series of catastrophic, real-world events, most notably the November 18, 2025, Cloudflare outage that disrupted services for nearly six hours, and the far more devastating CrowdStrike incident earlier that year, which caused an estimated $5.4 billion in losses. These events have illustrated a painful truth: as digital infrastructure becomes more interconnected, the blast radius of any single failure expands exponentially. A technical flaw in one provider can ground airlines, halt surgeries, and shut down global payment systems.

Meredith Schnur, US and Canada cyber practice leader for Marsh Specialty, notes that when critical services go down, the technical issue is only half the problem. “Communication gaps amplify panic,” she explains. The advisory is a direct response to a recurring pattern of failure: inconsistent updates, vague statements, delayed disclosures, and severe mismatches in messaging between technical teams, legal departments, and public affairs. CISA, by turning this into official guidance, is signaling that this dysfunction is no longer an acceptable cost of doing business. Chris Butera, acting CISA executive assistant director, confirmed that the guidance was specifically designed to “minimize operational impact, limit speculations, and preserve trust” during chaotic events.

The Supplier Problem and the AI Threat

The new guidance is directed squarely at service providers, and for good reason. Attacks and outages at this level create a supply chain crisis of information. A single failure at a foundational provider cascades down to thousands of downstream customers who are left blind. Jake Reynolds, head of security engineering at Coalition, adds a dangerous accelerant to this fire: artificial intelligence. Threat actors are now leveraging AI to propagate their access through the supply chain at speeds previously impossible. This means the window for effective communication is shrinking even as the complexity of the environment is expanding. The old model of taking days to issue a carefully vetted press release is a relic of a slower, less dangerous era.

The CISA advisory cuts to the heart of a deep organizational conflict that has plagued incident response for two decades. Companies naturally treat incident communications as a process to be managed by legal, communications, and public relations teams. Their primary incentives are legitimate but often problematic: minimize legal liability, avoid attribution of fault, and say as little as possible until all the facts are rigorously established. The problem, as Chris Novak, partner and co-founder of Quadrum Advisors, points out, is that these objectives directly conflict with what customers, boards, regulators, and the public actually need during a major disruption.

“That language suggests to me that policymakers have seen incidents where technically accurate corporate communications were nevertheless not particularly useful,” Novak says. He notes that the advisory is carefully worded. It does not simply tell companies to talk more; it demands clarity, accountability, and a rejection of generic reassurances. The subtle difference is profound. A technically accurate statement that says “We have experienced a service disruption and are investigating” is truthful but effectively useless. It does not tell a hospital administrator whether to cancel surgeries or a factory manager whether to halt production. The advisory is pushing for a shift from technical accuracy to practical usefulness.

Empathy Without Spin: A Missing Ingredient

Novak points to another critical element frequently absent from crisis communications: genuine empathy that is not couched in spin. When a customer’s manufacturing line is stopped, hospital operations are impaired, or employees cannot work, telling them that the company is “committed to delivering world-class service” is insulting rather than reassuring. The advisory implicitly supports a more honest approach: acknowledge the impact, explain the next steps, tell them what they should do, and set a clear timeline for when they will receive updates. “Trust isn’t preserved by pretending the incident isn’t serious,” Novak argues. “It’s often preserved by demonstrating that you understand how serious it is.”

Cloudflare’s Approach: A Positive Model for Crisis Communication

While much of the advisory is a critique of existing practices, the agencies were able to point to a positive example. In the wake of its November outage, Cloudflare acted as a case study in alignment with CISA’s new standards. The company quickly acknowledged the incident and apologized to users. Grant Bourzikas, chief security officer at Cloudflare, explains that their internal standard is to provide ongoing updates during an incident and to publish a detailed post-mortem within approximately 12 hours. This post-mortem outlines exactly what went wrong, how the company responded, and the safeguards being put in place to prevent recurrence.

“Outages and bugs happen,” Bourzikas states, “but being transparent about them and sharing lessons learned is critical to maintaining customer trust.” Cloudflare has explicitly endorsed the CISA advisory, hoping it becomes a standard practice across the industry. This contrast—between opaque legal defensiveness and transparent operational accountability—frames the choice that the advisory is forcing other providers to confront.

Will This Advisory Actually Drive Change?

The most pressing question following the publication of any non-binding guidance is whether it will materially alter organizational behavior. The expert consensus is cautiously optimistic but deeply pragmatic. The advisory may improve transparency at the margins, but meaningful change will depend on hard factors: leadership culture, regulatory pressure, and incident response maturity.

Schnur warns that balance is critical. There is a danger in sharing too much too soon, as key facts can change rapidly as an incident unfolds. Correcting earlier statements can look worse than a brief initial silence. However, she agrees that the CISA advisory sets a new baseline for what is considered acceptable. It raises the standard against which companies will be judged by their boards, their customers, and the courts.

Novak believes that the advisory will have a significant, if slow, impact. Now that CISA and the FBI have established best practices for effective communication, the expectations have shifted. The bar is no longer “disclose what you are legally required to disclose.” It is moving toward “communicate what your stakeholders reasonably need to manage their own risk.” This is a considerably higher bar, and it changes the conversation in the boardroom. “One of the most common questions our team hears is: ‘What are other organizations similar to us doing?'” Novak reveals. The existence of this advisory provides the answer.

Is Guidance Enough Without Enforcement?

The most potent critique of the advisory comes from Reynolds, who warns that its primary limitation is its lack of teeth. The document tells organizations what good communication should look like, but it does not, by itself, make that behavior a priority for organizations that face little perceived downside for doing the minimum. “Broader change will likely require a combination of regulatory enforcement, board oversight, contractual and insurance requirements, litigation exposure, and customer pressure,” Reynolds argues. Until the cost of poor communication becomes higher than the cost of good communication, the advisory risks becoming a well-intentioned but largely ignored document.

This tension between guidance and enforcement is the central strategic challenge. The advisory is a powerful tool for customers, regulators, and boards to hold service providers accountable. It can now be cited in contracts, used as a benchmark in insurance underwriting, and referenced in litigation. Its power lies not in its legal authority but in its ability to define the new standard of care. A provider that ignores these principles in a future crisis will find it much harder to defend its actions.

The “Communicating Under Pressure” advisory does not solve the fundamental conflict between legal liability and operational transparency. It does, however, force that conflict into the open. It challenges the cybersecurity industry to mature past defensiveness and toward a model where honest, timely, and useful communication is considered a core component of operational resilience, not an inconvenient afterthought. The era of hiding behind legal review is ending. The era of radical accountability is only beginning, and this advisory is its opening manifesto.

Share This Article