A user tries to start their workday, but their laptop is stuck in a “blue screen of death” loop. Halfway across the world, someone tries to post on X—nothing loads. These are the real-world ripple effects of a global outage where users know there's a problem, but details are limited.
Despite more breaches and incidents triggering mandatory disclosures, users are often still left in the dark because companies prioritize liability protection over helping people understand what really happened. The problem compounds when those incidents lead to widespread and highly disruptive outages that can last for days or weeks, whether they stem from threat actors or internal errors.
Issues with "effective communication" during IT and operational technology (OT) service outages led the Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI and international partners, to publish a "Communicating Under Pressure: Best Practices for Service Providers" advisory this month. The authoring agencies defined effective crisis communication as transparent, one that skips the PR spin and explains the root cause analysis to help users minimize operational impact.
Related:Insurers Search for Answers to Rein in Rogue AI
"Service outages alone have the potential to cause enough damage, disruption, and societal panic without speculation and uncertainty from end users and the public as added factors," the advisory stated.
Key takeaways urged providers to communicate immediately, provide actionable guidance, be transparent and share what they do and do not know, and be accountable and iterative with continuous updates; all while maintaining compliance and reporting requirements. All 50 U.S. states have laws mandating reporting of data breaches and many federal agencies, from CISA to the Securities and Exchange Commission to the U.S. Department of Health, require prompt reporting.
Technical vs. Practical
Attack transparency is an ongoing issue across the industry, even as the industry consensus has shifted from "If you'll be breached" to "When you'll be breached." Companies worry about how disclosures will affect their reputations, customer relations, and finances.
The advisory represents a deliberate effort to reframe breach communications where candid disclosure becomes a more expected standard. But CISA is responding to an even broader problem: trust, explains Chris Novak, partner and co-founder of Quadrum Advisors.
Novak found it interesting how CISA worded the advisory. The agency didn't tell companies to simply communicate more, but rather called for clarity, accountability, and transparency. The advisory even warned organizations to focus on actionable information rather than reputation management, and to avoid leading with generic reassurances or marketing language, he adds.
... continue reading