Global Cyber Outages Escalate as CISA Calls for Transparent Breach Notifications
A new joint government advisory from the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the FBI and international partners, has sent a clear signal to organizations worldwide: it’s time to prioritize transparency over liability protection when communicating about IT and operational technology (OT) service outages. The “Communicating Under Pressure: Best Practices for Service Providers” advisory comes on the heels of a surge in highly disruptive cyber incidents that have left users frustrated and in the dark.
The problem is all too familiar. Users know something’s amiss, but companies often struggle to provide clear explanations, instead opting for vague statements or even silence. This lack of transparency can have far-reaching consequences, from damaging public trust to exacerbating societal panic. The advisory acknowledges that service outages alone can cause significant disruption and damage, and that speculation and uncertainty from users only add to the problem.
So, what does this mean in practice? For organizations, it means adopting a new approach to breach notification and incident response protocols. CISA is urging providers to communicate immediately, provide actionable guidance, be transparent about what they know (and don’t know), and maintain accountability throughout the process. This shift towards transparency is not just about complying with existing regulations – it’s also about rebuilding trust with customers, stakeholders, and the wider public.
The advisory represents a significant shift in industry thinking. Gone are the days of sweeping incidents under the rug or downplaying their severity. Instead, companies are being encouraged to focus on providing clear, actionable information that helps users mitigate operational impact. This requires organizations to re-evaluate their approach to incident communications, moving away from a primarily legal, public relations-driven process and towards one that prioritizes transparency and accountability.
As Chris Novak, partner and co-founder of Quadrum Advisors, notes, the language used in the advisory is telling. CISA didn’t simply call for more communication – it demanded clarity, accountability, and transparency. This suggests policymakers have seen firsthand how technically accurate corporate communications can be woefully inadequate in times of crisis.
The stakes are high. Global cyber outages have become increasingly common and interconnected, with far-reaching consequences for businesses, governments, and individuals alike. It’s time for organizations to step up their game when it comes to transparency and accountability. By doing so, they can help rebuild trust, minimize panic, and ultimately reduce the damage caused by these incidents.
So, what can you do? As a user, take note of how your organization responds in times of crisis. Are they transparent about what’s happening and why? Do they provide clear guidance on next steps? If not, it may be time to rethink your relationship with that company. And for organizations, the takeaway is clear: transparency is no longer optional – it’s essential. By prioritizing clarity, accountability, and transparency in their communications, companies can help mitigate the impact of cyber outages and rebuild trust with their stakeholders.
Source: Dark Reading — 2026-09-11