Darkreading CISA Urges Transparency Amid Rising Cyber Outages
Article Content
- •CISA released guidance for transparent communication during IT and OT outages.
- •The advisory emphasizes immediate updates and actionable information for users.
- •All U.S. states mandate breach reporting, yet companies often prioritize liability over transparency.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued new guidance urging service providers to communicate transparently during significant IT and operational technology outages. This advisory, developed with the FBI and international partners, emphasizes the importance of timely and accurate updates to minimize user confusion and operational impact. The document, titled 'Communicating Under Pressure: Best Practices for Service Providers', addresses the ongoing issue of ineffective communication during outages, which can lead to societal panic and disruption. CISA's advisory calls for immediate communication, actionable guidance, and accountability from service providers. The shift aims to enhance trust and transparency in breach notifications, as organizations often prioritize liability protection over user awareness. All 50 U.S. states have laws mandating breach reporting, yet many companies still fail to provide adequate information during incidents. The advisory represents a significant regulatory shift towards more candid disclosure practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…