CISA and FBI Release Guidance on Crisis Communications for Service Providers During IT and OT Outages
New advisory emphasizes clarity, accountability, and transparency to prevent societal panic and preserve trust during service disruptions
Key Takeaways
- CISA, FBI, and international partners published guidance on crisis communications for service providers during IT and OT outages.
- Outages caused by cyber threat actors, human error, equipment failure, or natural hazards can cascade across interconnected systems, increasing uncertainty and alarm.
- Core principles of effective crisis messaging are clarity, accountability, and transparency.
- The guidance helps organizations inform stakeholders and the public while aligning with legal requirements and law enforcement efforts.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



