We use cookies. By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechGeer Black Text Logo Light Header TechGeer Main Logo
  • News
    • AI News
    • Cybersecurity News
    • Streaming News
    • Tech News
  • Statistics
    • Entertainment
    • Gadgets and Hardware
    • Internet Security
    • Lifestyle
    • Marketing and Finance
    • Science
    • Web and Software
    • Workplace and Business
  • Streaming
  • Security
    • VPN
    • Spy
    • Antivirus
    • Torrenting
  • AI
  • About Us
    • Why Trust Us
    • Editorial Policy
    • Our Writers and Editors
    • Terms of Use
    • How We Make Money
    • Get in Touch
Reading: US and Allies Issue New Outage Guidance Urging Firms to Drop PR Spin
TechGeerTechGeer
Search
  • News
    • AI News
    • Cybersecurity News
    • Streaming News
    • Tech News
  • Statistics
    • Entertainment
    • Gadgets and Hardware
    • Internet Security
    • Lifestyle
    • Marketing and Finance
    • Science
    • Web and Software
    • Workplace and Business
  • Streaming
  • Security
    • VPN
    • Spy
    • Antivirus
    • Torrenting
  • AI
  • About Us
    • Why Trust Us
    • Editorial Policy
    • Our Writers and Editors
    • Terms of Use
    • How We Make Money
    • Get in Touch
Have an existing account? Sign In
Follow US
  • Terms of Use
  • Privacy Policy
© 2024 TechGeer.com. All Rights Reserved.
Home » News » Cybersecurity » US and Allies Issue New Outage Guidance Urging Firms to Drop PR Spin

US and Allies Issue New Outage Guidance Urging Firms to Drop PR Spin

Daniel Hayes
Last updated: September 3, 2026 5:42 pm
By Daniel Hayes
8 Min Read
Share
We conduct in-depth independent evaluations before making a recommendation. If you buy through links on our site, we may earn a fee that supports our mission.
  • On September 2, 2026, CISA and the FBI, alongside four international partners, released new outage communication guidance.
  • The guide instructs service providers to provide immediate information, acknowledge unknowns and offer clear guidance to customers.
  • It includes disruptions resulting from cyber incidents, human errors, hardware malfunctions and natural disasters.
US and Allies Issue New Outage Guidance Urging Firms to Drop PR Spin

The FBI and the Cybersecurity and Infrastructure Security Agency (CISA), together with four international partners, issued new joint guidance for companies facing major IT and operational technology outages.

The nine-page guide, “Communicating Under Pressure: Best Practices for Service Providers,” came out on September 2. It helps technology providers and critical infrastructure organizations communicate during serious service disruptions.

In This Article
Lead Outage Communications with Facts, not PRDifferent Messages for Different AudiencesPrepare Before the Next CrisisKeep Customers UpdatedCloudflare Outage Shows Why Early Assumptions MatterTransparency should Continue After Recovery

CISA put this together with input from the FBI and cybersecurity centers in Australia, Canada, New Zealand, and the UK. They stated that communicating clearly when things go wrong goes a long way to help mitigate damage. A disruption at one company can also affect other connected systems.

This guide looks at all kinds of disruptions, cyberattacks, plain old mistakes, broken equipment, and natural disasters.

Lead Outage Communications with Facts, not PR

The guide’s message is direct: tell people what is happening without trying to protect the company’s image. The agencies urge service providers to avoid public relations and marketing language. They also warn against vague terms such as “service degradation.”

Instead, companies should explain which systems have problems, what users are experiencing, the scope of the outage, and its known cause. If the cause remains unclear, companies should say so.

The guide tells providers to separate confirmed facts from information still under review. Honest statements about uncertainty can help more than silence or speculation.

That does not mean companies should reveal every technical detail. During an active cyber incident, too much information could expose systems or interfere with an investigation.

Providers, therefore, must carefully balance between openness and security. Should an attack be the cause of an outage, coordination with law enforcement will be necessary.

Different Messages for Different Audiences

The guide stated that firms should not treat every audience the same. A technical team may need system details. Executives may need information about business impact. Customers may just need to know which services aren’t working and what steps they need to take.

There are other groups you might have to think about too, like your own staff, regulators, government officials, critical infrastructure operators, journalists, and pretty much the general public.

The guide suggests you should figure out how you’ll talk to all these people ahead of time, before anything actually goes wrong. It also tells providers to focus on operational impact, not just technical symptoms. Customers need to know how an outage affects their work.

For example, saying a system has failed tells customers little. Explaining which services they cannot use gives them information they can act on.

Prepare Before the Next Crisis

The guidance places strong emphasis on preparation. Service providers should create an outage communication plan. That plan should define when an incident requires wider communication. It should identify who is responsible for what aspects of the response.

The agencies suggest a cross-functional team consisting of engineering, operations, communications, legal, risk and compliance, customer service, and sales. They may need to include government relations personnel as well, in cases where government services suffer an outage.

Companies should assign clear roles as well. An incident lead should manage the response. A communications lead should coordinate information. A spokesperson should handle public statements.

The guide also calls for backup communication methods. These can include backup email, text messages, phone trees, radios, and other channels that do not rely on affected systems.

Companies should test those methods before an emergency. The agencies also recommend regular training and simulated exercises.

Keep Customers Updated

The guide urges companies to keep communicating throughout an outage. Providers should maintain one main source for public information, such as a status page or company blog. Updates should include timestamps and major recovery milestones.

The agencies also recommend posting updates when there is no major change. That can reduce speculation and show customers that teams continue to work on the problem.

Companies should also make customer actions clear. If users need to take a step, the provider should explain it. If no action is needed, the provider should say that too.

The guide also warns that outage messages can trigger legal duties. Some industries have specific reporting rules. Contracts may also include service-level requirements.

Cloudflare Outage Shows Why Early Assumptions Matter

One of the events that led to the formation of these guidelines is the 2025 November 18 incident that occurred with Cloudflare. Cloudflare first believed that there was a huge DDoS attack that caused the failure. But they realized another thing caused the problem.

The investigation into Delta Air Lines’ 2024 travel meltdown highlights the importance of clear communication during outages. The DOT closed its probe without penalties in June 2026, determining that Delta’s passengers received prompt refunds and adequate assistance after the CrowdStrike outage forced approximately 7,000 cancellations over five days.

It resulted from changing database permissions, causing the Bot Management system to produce a significantly larger feature file. That file spread across Cloudflare’s network and caused software failures. Cloudflare said it was not caused by a cyberattack or any malicious activity.

The outage affected core traffic and several Cloudflare services. Cloudflare later restored its core traffic at around 14:30 UTC. Then by 17:06 UTC, everything was fully up and running.

The example above is one of many reasons why businesses should be very careful during crisis times. Early symptoms can point investigators in the wrong direction.

Transparency should Continue After Recovery

The agencies say companies should keep communicating after services return. Incident updates must cover what occurred, the company’s response, and planned changes. Also, service providers need to address security measures, vulnerability management, and patching when applicable.

The guide concludes its guidelines on effective outage communication in five key tenets: prompt, technical, transparent, accountable and iterative.

That entails that companies should address the issue promptly, provide relevant information, and be upfront about things they don’t know. Also, they need to continue to update customers as more facts emerge.

It does not mean that the company should present itself positively in the case. The objective is to enable people to understand what took place and what should be done next.

As for technology companies and providers of critical infrastructure, what the agencies require of them is simple: resolve the problem, but communicate while doing so.

Share This Article
Facebook LinkedIn Reddit Copy Link
ByDaniel Hayes
Daniel Hayes is a cybersecurity analyst and tech editor with a strong background in information security and digital risk. He writes about malware, hacking campaigns, cloud security, data protection, and emerging cyber trends. Daniel combines technical expertise with clear, engaging writing to help businesses and individuals better understand today's rapidly changing cybersecurity landscape.
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related Articles

Microsoft to Enable Memory Integrity on More Windows 11 PCs from October
Cybersecurity

Microsoft to Enable Memory Integrity on More Windows 11 PCs from October

September 3, 2026
Anthropic Revokes Claude Sessions After Malware Steals User Login Tokens
Cybersecurity

Anthropic Revokes Claude Sessions After Malware Steals User Login Tokens

August 31, 2026
Microsoft Pushes Bing with New Windows 11 App that Changes Browser Search Settings
Cybersecurity

Microsoft Pushes Bing with New Windows 11 App that Changes Browser Search Settings

August 24, 2026
SafePal Data Breach Exposes Personal Information of Nearly 40,000 Customers
Cybersecurity

SafePal Data Breach Exposes Personal Information of Nearly 40,000 Customers

August 17, 2026
TechGeer Black Text Logo Light Header TechGeer Main Logo

Discover the latest in tech at TechGeer.com: AI, software, VPNs, privacy, monitoring, gaming, streaming, and alternatives. Your go-to source for cutting-edge news and guides in the digital world.

Navigation

  • News
  • Statistics
  • Security and Privacy Guides
  • Monitoring
  • VPN
  • Torrenting
  • Streaming & Geoblocking
  • Software and Apps
  • Artificial Intelligence

Company

  • About Us
  • Why Trust Us
  • Editorial Policy
  • Disclaimer
  • How We Evaluate
  • Career
  • Contact

Follow Us

TechGeer Ltd
Office 1214 727 51
High Streat, East
London E72JA
United Kingdom

© 2024 TechGeer.com. All Rights Reserved.
  • Terms of Use
  • Privacy Policy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up