Security2 distinct publishers2 min readPublished
CISA, the FBI and partner agencies in four countries now tell service providers to fix incident thresholds, escalation paths and status page wording before anything breaks, which hands customers something they can test after the fact.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The lever here is pre-commitment rather than advice. A threshold defined before an incident is a number somebody can check afterwards, and so are an escalation path, a named spokesperson and a status page designated as the single source of truth [4][6][9]. The guidance also tells providers to align external messaging with legal, contractual and sector-specific reporting obligations [10]. Contractual is the operative word: a customer can lift thresholds and update cadence into a renewal, then test them after the next outage.
Count what a provider needs on the shelf before anything breaks. According to The Cyber Express's summary of the document, the plan has to define incident thresholds, escalation paths and target audiences, then set procedures for three channels: status pages, customer and partner notices, and regulatory communications [4]. Three definitions plus three channel procedures is six artifacts, and none of them can be drafted while the phones are lit [16].
The hard instruction is the operational security one. Where malicious activity is suspected or confirmed, external communication must not compromise the investigation or containment, and the agencies warn against premature conclusions on root cause while it is still under investigation [7]. That judgement cannot sit with a communications lead alone, which is why legal, risk and compliance are placed on the same incident team as engineering, operations and customer support [5]. The useful content of the plan, in practice, is a pre-agreed list of what can be published while an intrusion is still live.
CISA's own resource page pushes from the buyer's side. Critical infrastructure owners and operators are told to assume telecommunications may be disrupted or unreliable, to keep crisis communications plans that integrate backup methods, and to understand the type of communication they should expect from their service providers [13]. The same page points that audience at CI Fortify material on isolating and recovering vital OT systems during a major incident [14]. Because an outage at one organization can cascade across interconnected systems [12], a downstream operator can now put specific questions to a vendor: which threshold triggers your notice, who speaks, and where is the single page.
Nothing in either publication is binding. Neither carries a deadline nor an enforcement mechanism [15]. Providers already posting time-stamped updates with scope, impact and a stated customer action will read the five principles and change nothing [11]. The delta shows up in renewal terms, where a customer now has a document signed off by agencies in five countries to quote instead of an opinion about what good looks like [17].
Ranked by verification strength, evidence, and original report placement.
CISA and the FBI, along with cybersecurity agencies from Australia, Canada, New Zealand and the UK, released new guidance on outage communications for service providers dealing with major IT and OT outages.
The guidance is titled "Communicating Under Pressure: Best Practices for Service Providers" and was developed by CISA, the FBI and international partners.
The guidance covers outages whether caused by cyber threat actors, human error, equipment failure or natural hazards.
The agencies recommend establishing an outage communications plan before an incident; the plan should define incident thresholds, escalation paths, target audiences and procedures for status pages, customer and partner notices, and regulatory communications.
If malicious activity is suspected or confirmed, external communications should not compromise investigations, containment or other response activities, and organizations are advised against premature conclusions while root cause remains under investigation.
The agencies frame effective outage communications around five principles: immediate acknowledgement, technical and actionable information, transparency, accountability, and continuous updates.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
The UK plant that went dark for four days was too small to have to tell anyone1 distinct publisher
security
CISA finally counts the water intrusions: 100-plus exposed systems behind cellular modems2 distinct publishers
security
CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary document, one second reader
Everything here traces to a page CISA published itself, which is the strongest kind of sourcing for what a document says and the weakest for whether it matters. The Cyber Express is the only outlet that read the guidance closely enough to reproduce its mechanics, and no reporter has checked those mechanics against a provider's actual runbook.
Publication is not uptake
We can see the guidance went out on 2 September and that at least one trade outlet worked through it. We cannot see one provider that has set an incident threshold, named a spokesperson, or rewritten a status page because of it — and there is no telemetry, survey or disclosure in this reporting that would show us.
Framing runs a step ahead of the text
Neither publisher oversells: CISA is dry, and The Cyber Express sticks to "recommends" and "advised" throughout. The stretch is ours — calling this a pre-built control implies customers will hold providers to it, which is an inference about buyer behaviour rather than anything the agencies asked for or can compel.
Mission publishing with a house ad
There is no commercial pressure on the agencies here, though CISA uses the same page to route readers toward its CI Fortify programme — the one piece of self-interest in the document. The Cyber Express earns its traffic by restating advisories, which explains why its account is thorough rather than skeptical: no provider, customer or regulator is quoted at all, so nobody with money at stake gets a say.
Firm on what was said, blank on what follows
The what — who signed, what they recommend, in what words — is nailed down by the issuer plus a detailed second reading, and the two accounts agree everywhere they overlap. The unknown is consequence: with no compliance hook and no visible uptake, our read on whether this changes provider behaviour is a judgement call, not a measurement.