Canadian Cyber Security Journal
SOCIAL:
Filed under: Legislation

CISA, FBI, and Canadian Centre for Cyber Security Set New Rules for Outage Communication

What Happened

CISA, the FBI, and cyber agencies from Canada, Australia, New Zealand, and the United Kingdom published joint guidance titled “Communicating Under Pressure: Best Practices for Service Providers” on September 2. The Canadian Centre for Cyber Security joined ASD’s ACSC, NCSC-NZ, and NCSC-UK as a co-author alongside CISA and the FBI. The guidance directs organizations to build outage communications plans around five principles: immediate acknowledgement, technical and actionable information, transparency, accountability, and continuous updates. It calls for predefined incident thresholds, named incident and communications leads chosen before an outage occurs, and tested backup channels such as SMS, phone trees, radios, and out-of-band messaging for when normal systems are unavailable. The advisory applies to outages from cyberattacks, human error, equipment failure, or natural hazards, not cyber incidents alone. Full guidance is available from CISA.

Why This Matters for Canadian Organizations

Direct participation by the Canadian Centre for Cyber Security places this guidance on equal footing with domestic advisories, and Canadian critical infrastructure operators, telecommunications providers, and managed service vendors should expect the CCCS to reference these practices in future incident-response evaluations. The advisory follows a stretch of multi-day outages across major platforms in 2026, including the Microsoft 365 and Exchange Online disruption affecting Canadian government, healthcare, and enterprise tenants at the end of August, where the pace and clarity of vendor communication shaped customer response as much as the outage itself. Bill C-26 continues to move toward mandatory incident reporting obligations for federally regulated critical infrastructure, and organizations building compliance programs around it gain a concrete communications framework to pair with technical reporting requirements once the bill takes effect.

What to Do

Service providers should draft or update an outage communications plan now, naming an incident lead, a communications lead, and a spokesperson in advance rather than assigning those roles after an incident begins. Define incident severity thresholds triggering customer notification and set expectations for update frequency during a prolonged outage. Test backup communication channels, including SMS and out-of-band messaging systems, on a schedule separate from technical disaster recovery drills, since a channel working fine during normal operations frequently fails under the same conditions causing the outage itself. Organizations preparing for Bill C-26 compliance should map this framework against upcoming reporting timelines to avoid building two separate response processes. The full advisory is available from CISA.

Enjoy this article? Don’t forget to share.