Following a major information technology (IT) or operational technology (OT) outage, organizations should not go into “damage control” mode or attempt to put a “spin” on the story. That is contrary to what many PR teams may suggest, but this month, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), joined by international partners, released joint guidance titled “Communicating Under Pressure: Best Practices for Service Providers.”

It directed technology and critical infrastructure organizations to maintain transparency following such events.

“Effective communication begins with a factual summary tailored to predefined audiences, avoids PR spin, and adheres to regulatory requirements. Service providers should be transparent by sharing what is known, unknown, and under investigation, while providing frequent, iterative updates as new information emerges or circumstances change,” the plan stated. At the same time, the guide offered an outline for organizations to prepare for such events.

The Key Actions

The joint report stated there should be several “key actions” taken following an IT or OT outage:

  • Develop a communications plan with defined incident thresholds and target audiences for communications.
  • Practice transparency and avoid PR/marketing language.
  • Provide technical information and a root cause analysis for end users.
  • Align all messaging with legal and regulatory requirements.

The report further recommended that service providers segment communications so that each audience (e.g., technical, executive, public) can effectively act on relevant information. It also called on providers to avoid vague language (e.g., service degradation), and to design messaging for rapid comprehension. That included an overall “bottom line upgrade” that explains the issue to both a public and technical audience.

Entities should state what is known, what is not known, and use a single source of truth. The focus should be on actionable information, not on reputation management.

In addition, “certain legal considerations may need to be taken into account when externally communicating about an outage or incident,” the report stated. It also noted that outage communication could trigger legal obligations, including:

  • Incident reporting disclosure rules.
  • Sector-specific mandates (e.g., Financial Services, Healthcare, Transportation, etc.).
  • Contractual service level agreements (SLAs).

Does the Message Matter

Cybersecurity experts have expressed differing views on how important this communication report is, with warnings that it is still too reactive and may not address several issues.

John Strand, owner of Black Hills Information Security, told ClearanceJobs that while the plan is a good start, there was at least one area that needed to be addressed more directly.

“When the decision is made to shut down network access, there need to be very clear lines defining who is authorized to make that decision and what political protections exist for the people making those calls,” Strand explained. “During a breach of this nature, one of the biggest communication problems is often figuring out who’s on first and who’s on second. Who can actually make the call? Who has the authority to shut down access?”

Instead, there is a situation where the “decision gets escalated again and again and again” until it eventually reaches a director, CEO, commissioner, or some other senior official who has enough authority to make the call.

“Meanwhile, valuable time is being lost,” warned Strand.

He further told ClearanceJobs that incident response plans need to go deeper than “motherhood and apple pie statements” about communicating with customers, coordinating between organizations, and keeping everyone informed.

“That’s all important, but the plan needs to explicitly identify who has the authority to make the really hard decisions during an incident,” Strand continued. “Just as importantly, there needs to be political cover for the people who make those decisions.”

Warning of PR Spin is Spin Itself

Despite the warnings from CISA and the FBI to avoid PR-speak, that may be impossible to avoid, simply because that is what those teams are there to do. In an ideal world, the concern might be over lost customer or client data, and how an outage is impacting clients.

But that’s not often the case.

“Agencies advocating clear communication with timely updates, and avoiding PR style language is great! Useless, but great,” suggested Joshua Marpet, senior product security consultant at cybersecurity provider Finite State.

“Companies will use whatever language their crisis communications firm advocates for, because that is how they avoid liability,” Marpet told ClearanceJobs. “Firms with the backbone to be open, honest, and transparent are not exactly the majority out there. Unless you have communication strategies mandated, you have a perfect example of Marpet’s law: ‘Unless it’s mandated, or someone is paying for it, ain’t gonna happen.’”

Even when it is mandated, there is a reason that there are such things as crisis management firms.

“Let’s be honest, at a high level, none of this is new. Cross-functional incident teams, designated spokespeople, escalation paths, time-stamped updates, practice transparency,” added Denis Calderone, chief technology officer at cybersecurity provider Suzu Labs.

The new report may add some key bullet points that response teams should add to the checklist following an incident.

“Where this guidance actually adds value is in the operational specifics and the timing,” Calderone told ClearanceJobs. “It explicitly tells organizations to assume that their own telecommunications and primary communication channels may be disrupted or unreliable during a crisis.”

That could mean establishing and testing backup methods like radios, SMS phone trees, and out-of-band channels before you need them.

Calderone said in his tabletop exercises for clients, the first thing he tells them is how to react when their communications are down.

“Email is gone, Teams is gone, your status page is offline. Now coordinate your response and communicate with your customers. Most organizations completely fall apart at that point, and that is exactly the scenario this guidance is built for,” Calderone continued.

So Why Now?

The final consideration is why this report was issued now. As the experts suggested, nothing was particularly innovative, but firms at all levels may have needed a reminder.

“The timing also matters,” warned Calderone, who noted that it dropped alongside the CISA’s CI Fortify initiative, which was released to critical infrastructure operators to prepare to deliberately disconnect OT systems from third-party networks during a geopolitical crisis.

“The guidance specifically calls for articulating ‘what it is and what it is not’ to prevent misattribution,” Calderone told ClearanceJobs. “After the year we’ve had with attacks against water utilities, ports, power generation, and PLC suppliers, CISA clearly does not want the next big CI outage to trigger days of ‘was this a nation-state attack?’ speculation while downstream operators are making blind isolation decisions.”

Even if the suggestions are obvious, such reminders could be necessary as the next incident could be just around the corner. Being prepared is what will ensure everyone can get through it.

“Hindsight is always 20/20. After an incident, everyone gets to sit around and analyze whether shutting something down was necessary,” said Strand. “The person making that decision in the middle of an active breach doesn’t have that luxury.”

Related News

Peter Suciu is a freelance writer who covers business technology and cyber security. He currently lives in Michigan and can be reached at petersuciu@gmail.com. You can follow him on Twitter: @PeterSuciu.