CISA and the FBI just told critical infrastructure operators how to talk to customers when the lights go out.
The two agencies, working with international partners, published guidance for communicating during IT and operational technology outages, regardless of cause: a cyberattack, equipment failure, human error, or a natural hazard. The document centers on three principles, clarity, accountability, and transparency, and walks through how to build messages that satisfy legal requirements and support law enforcement or containment efforts without leaving customers in the dark. It complements CISA's existing CI Fortify initiative, which helps infrastructure owners prepare to isolate and recover industrial control systems during a major incident.
The real value here is in what the guidance assumes rather than what it states outright. It tells operators to plan for their own telecommunications going down alongside everything else, meaning the standard crisis playbook, call customers, post an update, cannot always be relied upon. It also flags that outages at one organization can cascade through interconnected systems, so silence at one utility or provider can spread confusion well beyond its own customer base.
A federal advisory reminding companies to talk to their customers during a crisis is, in its own quiet way, an admission that plenty of them currently don't.