What CISA's New Outage Communication Guidance Means for Enterprise Resilience
In short
On September 2, 2026, CISA, the FBI and the cyber agencies of Australia, Canada, New Zealand and the UK published joint guidance on communicating during IT and OT outages, informed by the November 2025 Cloudflare outage. It calls for a prepared incident team, audience-segmented messaging, continuous timestamped updates and tested backup communication methods. The gap most organizations still have: their backup plan often depends on the same personal phones, email and consumer apps that a real incident can take down or compromise alongside the primary system.
A joint advisory born from a real outage
When Cloudflare went down on November 18, 2025, the disruption rippled across thousands of dependent services, a reminder that a single provider's outage can cascade well beyond its own customer base. In response, CISA worked with the FBI and the national cyber agencies of Australia, Canada, New Zealand and the UK to publish joint guidance for service providers: Communicating Under Pressure: Best Practices for Service Providers, released September 2, 2026 and marked TLP:CLEAR for unrestricted distribution.
The guidance is aimed primarily at service providers in Critical Manufacturing, Information Technology, Energy, Water and Wastewater, Transportation and Communications, and at the people who handle incidents inside those organizations: defensive cybersecurity analysts, executive leadership, legal advisors, technical support staff, incident responders and PR specialists.
What the guidance actually recommends
The core argument is simple. During an outage, whether caused by malicious activity or a non-malicious failure, how an organization communicates matters almost as much as how fast it fixes the problem.
Build the structure before you need it
The guidance recommends organizations put a service outage communications plan in place in advance, with defined triggers, escalation paths and templates for status pages, customer and partner notices and regulatory communications. That plan should include a cross-functional incident team spanning engineering, communications, legal, risk and compliance and customer support, with clearly designated roles: an incident lead, a communications lead and a single spokesperson.
- Backup communication methods, including out-of-band channels, SMS and phone trees, for moments when primary systems are degraded or compromised
- Pre-planned playbooks that are reviewed and tested regularly, including simulated tabletop exercises
- Message consistency between internal staff communications and external public statements
Lead with facts, not reassurance
The guidance warns against front-loading communications with reassurances, generalities or marketing language, and says transparency should be the default for non-malicious outages, while active cyber incidents require more care to avoid compromising investigation or containment efforts.
Segment the audience, update continuously
Not every audience needs the same message. The guidance recommends segmenting communications across enterprise IT teams and security operations centers, affected employees and customers, government partners and regulators, critical infrastructure owners and operators, and media and the general public, each with information relevant to the decisions they need to make. It also calls for continuous, timestamped updates, even when there is nothing new to report, maintained through a single source of truth such as a status page.
Stay aligned with legal and regulatory obligations
Outage communications can trigger real legal obligations: incident reporting disclosure rules, sector-specific mandates in industries like financial services, healthcare and transportation, and contractual SLAs. The guidance recommends aligning all messaging with legal counsel and compliance teams, and coordinating with government or law enforcement partners before making any public attribution statements.
The gap this exposes
Here is where the guidance quietly surfaces a harder problem. It calls for tested backup and out-of-band communication methods for when primary systems are degraded or compromised, and for a cross-functional team that includes legal, compliance and, where relevant, a government relations lead coordinating with regulators or law enforcement.
In practice, many organizations' fallback plan is informal: personal phones, consumer messaging apps, personal email. That is precisely the shadow IT problem showing up in a new context. If a cyber incident has compromised parts of the network, falling back to ungoverned, unencrypted consumer channels to coordinate the response is not a backup plan, it is a second exposure. And when that coordination needs to extend to a regulator, a law enforcement partner or an affected customer organization, an ungoverned channel has no way to prove who saw what, or when.
What this means in practice
An effective response to this guidance needs infrastructure that holds up to three specific requirements the guidance lays out:
- A genuinely out-of-band channel, independent of the primary systems that might be degraded or compromised, available for the incident team to coordinate on
- Governed, auditable communication for the incident team itself, so legal, compliance and leadership have a clear record of who said what and when, matching the guidance's call for message consistency and alignment with legal counsel
- A way to extend that same governed coordination to outside parties, regulators, law enforcement, affected partner organizations, without merging directories or losing control of who has access, when government relations or cross-organization coordination becomes part of the response
Key takeaways from the guidance
The authoring agencies summarize effective outage communication in five words: immediate, technical, transparent, accountable and iterative. Acknowledge quickly, provide actionable guidance, share what you know and do not know, own the outcome, and keep updating as the picture changes.
Where NetSfere fits
NetSfere is built to meet exactly the three gaps this guidance exposes. It operates as a genuinely out-of-band channel, independent of the email and collaboration tools that may be degraded or compromised during an incident, so the response team always has a working line of communication. NetSfere's industry-leading Out-of-Band Communication capability is a resilient IT-controlled safeguard that guarantees business continuity, compliance, and reliable communications even when primary systems like email, PBX, or cloud platforms are offline, degraded, or compromised.
Built on NetSfere's Omnichannel platform and backed by global Mobile Network Operator (MNO) infrastructure, this next-generation capability delivers carrier-grade reliability and global reach, ensuring enterprises stay connected when it matters most. For enterprises in regulated industries already held to standards like HIPAA, GDPR, and FedRAMP Ready extends naturally to incident communication, rather than requiring a separate, ungoverned fallback plan.
Frequently Asked Questions
What is the CISA guidance on communicating under pressure?
It is a joint advisory published September 2, 2026 by CISA, the FBI and the cyber agencies of Australia, Canada, New Zealand and the UK, giving service providers best practices for communicating during IT and OT outages, informed by the November 2025 Cloudflare outage.
Who is this guidance intended for?
It is aimed at service providers in Critical Manufacturing, Information Technology, Energy, Water and Wastewater, Transportation and Communications, and at incident responders, executive leadership, legal advisors, technical support staff and PR specialists within those organizations.
What does the guidance say about backup communication methods?
It recommends organizations establish and regularly test backup communication methods, including out-of-band communications, SMS, phone trees and conference bridges, for use when primary systems are degraded or compromised.
Why do personal apps and email fall short as a backup communication plan?
They are ungoverned and typically unencrypted by default for business use, offer no audit trail of who saw what and when, and can introduce a second point of exposure if used to coordinate response to a cyber incident that has already compromised parts of the network.
How does NetSfere address the backup communication gap described in the guidance?
NetSfere operates as an out-of-band channel independent of an organization's primary email and collaboration tools, so the incident team retains a working, encrypted line of communication even if primary systems are degraded or compromised.
What encryption and compliance standards does NetSfere support?
NetSfere supports enterprise requirements including HIPAA, GDPR, FINRA and FedRAMP Ready, depending on deployment.