The Cybersecurity and Infrastructure Security Agency (CISA), the FBI and cyber agencies in Australia, Canada, New Zealand and the U.K. are advising service providers to treat outage communications as part of incident response alongside technical remediation.
Their guidance, “Communicating Under Pressure: Best Practices for Service Providers,” calls for communications plans with predefined incident thresholds, approval paths and target audiences.
It also recommends naming an incident lead, communications lead and spokesperson before an outage and testing backup channels for when normal systems are unavailable.
The preparations include “parallel, synchronized workstreams,” with technical teams diagnosing and fixing the problem as communications teams handle public messaging and leadership manages strategy and regulatory outreach.
Backup methods can include SMS and phone trees, radios, alternative email or messaging systems, out-of-band communications and conference bridges.
Rules for effective public messaging
The agencies also spell out what those outage messages should contain.
They recommend tailoring updates to technical, executive and public audiences and leading with a concise summary of affected systems, user impact, scope and any known cause.
Service providers should avoid vague language, generalities and marketing messaging and tell customers what action to take, or make clear when no action is required.
Lessons from the Cloudflare outage
The agencies refer to the Nov. 18, 2025, outage at Cloudflare, an internet infrastructure company, as one of the real-world events that informed the recommendations.
Cloudflare, Microsoft, Sophos and American Water are also credited as industry contributors.
Cloudflare said its network began experiencing significant failures at 11:20 UTC after a database permissions change caused a file used by its Bot Management system to double in size.
The file exceeded a software limit and caused systems handling network traffic to fail. Core traffic was largely restored by 14:30 UTC, with all systems functioning normally by 17:06.
The incident also illustrates one problem the new guidance addresses: uncertainty while engineers are still determining the cause.
Cloudflare said it initially suspected a large distributed denial-of-service attack before identifying the internal configuration problem.
The agencies recommend telling users what is known, what remains unknown and what is still under investigation without drawing premature conclusions about the root cause.
Applying the standards to small businesses
CISA’s resource page tags small and medium businesses among the intended audiences, but the document’s own audience table lists government and critical infrastructure organizations.
Its audience list includes cybersecurity executives, legal advisers, technical staff, incident responders and public relations specialists.
For smaller providers, the nine-page document does not set out a separate staffing model.
Its operational recommendations, however, are specific: define when the communications plan activates, establish approval paths, prepare message templates, test backup communications and rehearse the process through exercises.
The agencies also recommend maintaining a single source for public updates and timestamping updates even when there is no new information.
Coordinating with legal and compliance teams
The advisory further suggests aligning messaging with legal counsel and compliance teams and coordinating with government or law enforcement partners before making public attribution statements.