New Guidance: How Businesses Should Communicate During IT Outages
Government cybersecurity agencies, led by CISA and the FBI with international partners, have published new guidance on how organisations should communicate during IT and operational technology outages. The advice applies whether an outage is caused by a cyberattack, human error, equipment failure, or a natural event, and highlights that such disruptions can trigger public confusion and panic, especially when interconnected systems cause problems to cascade across multiple organisations.
The guidance stresses three core principles for crisis communication: clarity, accountability, and transparency. It outlines how businesses can craft messages that keep customers, staff, and the public accurately informed while still respecting legal obligations, security needs, and any ongoing law enforcement or containment activities. This balance is important because poorly handled communication during an incident can worsen reputational damage even if the technical response is well managed.
While aimed primarily at critical infrastructure and service providers, the underlying lessons apply broadly: any business that experiences a service disruption benefits from having a clear communication plan ready before a crisis hits, rather than improvising under pressure.