Joint Guidance

Communicating under pressure: best practices for service providers

This guidance is to help provide effective communication during IT and operational technology (OT) outages to minimise harm and operational disruption.

PUBLISHED DATE: 3 September 2026

Preparing your organisation to communicate effectively

Effective communication during a service outage begins long before an incident occurs. Service providers should establish and regularly exercise the structures, processes, and relationships required to respond quickly and confidently in a crisis. This includes maintaining a cross-functional incident response team, strong government and stakeholder engagement channels, clearly defined roles and decision-making authority, and synchronised workstreams that enable technical, operational, legal, and communications teams to work in parallel. Organisations should also ensure backup communication methods are available, supported by pre-defined playbooks, procedures, and messaging frameworks that promote consistency across all channels.

Key elements of effective messaging

During an incident, timely and transparent communication is essential for maintaining trust and reducing uncertainty. Effective messaging starts with a clear understanding of the issue and the needs of different audiences. Communications should lead with concise, actionable summaries, demonstrate transparency and accountability, and provide regular, time-stamped updates as new information becomes available. Service providers must also ensure compliance with regulatory and reporting obligations while communicating how security enhancements and product improvements will help prevent similar incidents in the future. By delivering clear, consistent, and audience-focused updates, organisations can strengthen stakeholder confidence throughout the incident response lifecycle.

 


This guidance was co-authored by:
  • U.S. Cybersecurity and Infrastructure Security Agency
  • U.S. Federal Bureau of Investigation
  • Australian Cyber Security Centre
  • Canadian Centre for Cyber Security
  • U.K. National Cyber Security Centre