CISA Tells Critical Infrastructure Operators to Plan How They'll Talk When the Systems Go Dark
New joint guidance from CISA, the FBI and international partners spells out what utilities, hospitals and transport operators should say to the public during a major IT or industrial outage, and how to say it before rumours fill the gap.

Key points
- CISA, the FBI and international partners released joint guidance on crisis communications during IT and operational technology outages.
- The document tells critical infrastructure operators to plan messaging in advance, not scramble for words mid-incident.
- It sits alongside CISA's CI Fortify initiative, which helps operators isolate and recover industrial control systems during a cyber crisis.
- Operators are told to assume phone and internet services may fail during a major event and to prepare backup ways to reach customers.
- The guidance stresses three principles: clarity, accountability and transparency.
When a hospital's booking system goes down, or a water utility's controls stop responding, the second crisis is usually the silence that follows. Customers do not know what has happened. Staff do not know what to tell them. Rumours move faster than facts.
That gap is what the US Cybersecurity and Infrastructure Security Agency wants critical infrastructure operators to close. In new joint guidance published with the FBI and international partners, CISA lays out how utilities, transport operators, hospitals and other essential services should communicate with the public during a serious outage.
The document, released through CISA Cybersecurity Advisories, covers outages of both IT systems (the ordinary computer networks that handle email, billing and records) and operational technology, meaning the industrial control systems that run pumps, power grids, trains and factory lines.
What is CISA actually telling operators to do?
Plan the words before you need them. The guidance argues that clear, timely, accurate messaging has to be drafted, rehearsed and legally cleared before an incident, because there is no time to write it once alarms are going off.
Three principles sit at the centre of the advice: clarity, accountability and transparency. Operators should say what they know, admit what they do not, and name who is responsible for updates. Messaging must line up with legal duties, law enforcement requests and the security of the ongoing response, so nothing said publicly tips off attackers or damages a criminal investigation.
Why does this matter to ordinary customers?
Because outages ripple. One hospital losing its records system can force ambulances to divert to another. A payment processor failing can shut tills across a supermarket chain. CISA warns that outages at one organisation can cascade across interconnected systems, increasing public alarm even when the original problem is contained.
When a company you rely on goes quiet, you are more likely to phone helplines that cannot cope, share unverified posts on social media, or assume the worst. Good crisis messaging is not corporate spin. It is the difference between a manageable disruption and a panic.
What about industrial systems specifically?
CISA points to its CI Fortify initiative, which helps operators of critical infrastructure prepare to isolate and recover operational technology during a major cyber incident. Isolation here means deliberately cutting parts of a network off from the internet or from other systems to stop an attack spreading.
That kind of defensive move looks, to a customer, exactly like a breakdown. The lights are on but the app does not work. The guidance stresses that whenever service availability changes, whether from an attack or from a defensive shutdown, operators must keep telling users what is happening and why.
The telecoms assumption
One line in the guidance stands out. For emergency planning, operators are told to assume that phone and internet services may themselves be disrupted or unreliable during a major event.
That changes everything about how you communicate. If mobile networks are down, a website update helps no one. Plans need backup channels: radio, physical notices, staff on the ground, printed contact trees, agreements with local broadcasters. Operators are also told to know, in advance, what kind of communication they should expect from their own suppliers when those suppliers are the ones in trouble.
| Element | What the guidance says |
|---|---|
| Core principles | Clarity, accountability, transparency |
| Covered outages | IT and operational technology systems |
| Causes in scope | Cyberattack, human error, equipment failure, natural hazards |
| Key assumption | Telecoms may be unreliable during a crisis |
| Companion programme | CISA CI Fortify for OT isolation and recovery |
The guidance is not a rulebook with penalties attached. It is a template, and a nudge. For the nurse, the commuter, the account holder on the other end of an outage, its success will be measured in one thing: whether the next big incident comes with a straight answer instead of a shrug.



