Government Advisory

New Guidance: How Businesses Should Communicate During IT Outages

CISA · 2 Sept 2026
Key Takeaway Prepare a simple communication plan now—covering who says what, when, and to whom—so your business can respond calmly and clearly if an outage or cyber incident occurs.

Government cybersecurity agencies, led by CISA and the FBI with international partners, have published new guidance on how organisations should communicate during IT and operational technology outages. The advice applies whether an outage is caused by a cyberattack, human error, equipment failure, or a natural event, and highlights that such disruptions can trigger public confusion and panic, especially when interconnected systems cause problems to cascade across multiple organisations.

The guidance stresses three core principles for crisis communication: clarity, accountability, and transparency. It outlines how businesses can craft messages that keep customers, staff, and the public accurately informed while still respecting legal obligations, security needs, and any ongoing law enforcement or containment activities. This balance is important because poorly handled communication during an incident can worsen reputational damage even if the technical response is well managed.

While aimed primarily at critical infrastructure and service providers, the underlying lessons apply broadly: any business that experiences a service disruption benefits from having a clear communication plan ready before a crisis hits, rather than improvising under pressure.

incident response crisis communication CISA business continuity cybersecurity guidance

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.