CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate

A Global Outage Crisis: Why Transparency Matters in Cybersecurity

As you try to start your workday, only to be met with a “blue screen of death” loop on your laptop, or attempt to post on social media but face an endless loading screen, it’s clear that something is amiss. The culprit behind these frustrating outages often lies in the shadows, hidden behind layers of corporate spin and liability protection. But a new joint government advisory from CISA, the FBI, and international partners seeks to shift this paradigm, calling for more transparency and less obfuscation in the wake of cyber incidents.

The “Communicating Under Pressure: Best Practices for Service Providers” advisory is a timely response to the growing problem of effective communication during IT and operational technology (OT) service outages. When an outage occurs, users are often left in the dark, forced to navigate uncertainty and speculation without clear guidance from providers. This not only exacerbates the disruption but also erodes trust between companies and their customers.

The advisory’s key takeaways urge service providers to communicate immediately, provide actionable guidance, be transparent about what they do and don’t know, and maintain accountability throughout the incident response process. This shift towards transparency is a deliberate effort to reframe breach communications, where candid disclosure becomes an expected standard. By doing so, CISA aims to address not just the technical aspects of outages but also the broader issue of trust.

Chris Novak, partner and co-founder of Quadrum Advisors, notes that the advisory’s language signals a significant shift in policy-making. “CISA is calling for clarity, accountability, and transparency,” he explains. “They’re warning organizations to focus on actionable information rather than reputation management, and to avoid leading with generic reassurances or marketing language.” This emphasis on transparency is a response to incidents where technically accurate corporate communications failed to provide users with the information they needed during a crisis.

Traditionally, incident communications have been managed through legal, communications, and public-relations processes, creating incentives to minimize statements and reduce liability. However, this approach conflicts with what customers, boards, regulators, investors, employees, and the public need during a major disruption: accurate and timely information. As Meredith Schnur, US and Canada cyber practice leader for Marsh Specialty, points out, “The timing of the advisory aligns with how outages have become more visible, more interconnected, and more disruptive across both IT and OT environments.”

In practical terms, this means that service providers must prioritize transparency over liability protection when communicating during an outage. This may involve sharing more detailed information about the cause of the outage, providing clear guidance on what users can do to mitigate the impact, and maintaining open channels for communication throughout the incident response process.

Ultimately, the success of this advisory will depend on the willingness of service providers to adopt a more transparent approach to incident communications. By doing so, they can rebuild trust with their customers and stakeholders, and work towards minimizing the disruption caused by outages. As you navigate the increasingly complex world of cybersecurity, remember that transparency is not just a moral imperative but also a practical necessity in building resilience against cyber threats.


Source: Dark Reading — 2026-09-11