Out-of-Band Communications: The Missing Layer in Critical Infrastructure Resilience
Critical infrastructure resilience depends on more than network isolation. Out-of-band communications keep response teams connected when normal systems fail.
Sep 9, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
Critical infrastructure operators are being asked to plan for a harder reality: the network may not be trustworthy during the incident it is supposed to help resolve.
Watch the On-Demand Webinar: What CI Fortify Doesn't Say About Communications
That is the premise behind CI Fortify, the joint guidance from CISA, the Australian Signals Directorate's Australian Cyber Security Centre, the FBI, and international partners including the U.K.’s Cyber Security Centre, the Canadian Centre for Cyber Security, and New Zealand national security centers. The guidance focuses on isolating vital operational technology and the systems that support it, so essential services can continue during a crisis.
The technical objective is sound. But it exposes an operational question that every critical infrastructure organization needs to answer before the next incident: once the network is cut off, how will the people running the response communicate?
Isolation Changes the Communications Problem
During normal operations, communications often ride on enterprise networks, cloud-based collaboration tools, carrier networks, or public internet paths. During a cyber incident, those channels may be unavailable, congested, compromised, or intentionally disconnected.
That means the fallback plan cannot be "use personal phones" or "switch to a consumer messaging app." Those tools may be outside organizational control, weak on auditability, dependent on the same degraded networks, or unable to provide the evidence needed after the incident.
"'Use personal phones' or 'switch to a consumer messaging app' cannot be the fallback plan." — Ramon Pinero, Vice President and General Manager, BlackBerry AtHoc
Out-of-Band Means More than a Separate Path
An out-of-band communications path must be independent of the systems being isolated. It must be trusted, and tested before the incident. It needs to stay functional under degraded conditions, not just in a clean tabletop exercise, and it must carry the functions a response depends on: alerting, acknowledgment, recall, secure coordination, and reporting.
That matters for your organization because response teams are often small. A utility, for instance, may have only a few people who know the plant, understand the control environment, and can make the right operational calls under pressure. If those people cannot be reached and coordinated, technical isolation will not deliver operational resilience.
The Coordination Record Matters
Resilience is now measured after the fact. Regulators, public agencies, boards, and communities may need to know who was notified, who responded, what actions were taken, and when critical updates were shared. A communications platform built only for reach but not for proof will leave a gap when your response record is examined.
Out-of-band communications should be funded and tested as part of every resilience plan. It carries command decisions, personnel accountability, field coordination, and external reporting when normal infrastructure cannot be trusted. That is not a convenience function.
Build It Before the Incident
The practical test is simple: can your team still coordinate internally and with external partners after the network is isolated? If the answer is "not sure," you have found a resilience gap.
Closing that gap means establishing a trusted out-of-band channel, validating response-critical devices, confirming alert delivery and acknowledgment, and rehearsing the process with the same seriousness applied to technical isolation. An isolation plan that cannot carry communications is incomplete. Your organization needs both: systems that can keep running and people who can keep coordinating.
When Operational Technology Goes Offline, Coordination Can't
Recent cyberattacks on U.S. water utilities delivered a stark wake-up call. OT networks at critical infrastructure are prime targets for threat actors, and the risk is no longer theoretical. That's why CISA's July 28 CI Fortify advisory is a clear directive: prepare today to isolate vital OT systems and sustain essential operations.
Learn more: Visit the BlackBerry CI Fortify Resource Center
Out-of-Band Communications: The Missing Layer in Critical Infrastructure Resilience
Critical infrastructure resilience depends on more than network isolation. Out-of-band communications keep response teams connected when normal systems fail.
Sep 9, 2026
·Blog
·Secure Communications
%3Aquality(100)&w=3840&q=75)
Critical infrastructure operators are being asked to plan for a harder reality: the network may not be trustworthy during the incident it is supposed to help resolve.
Watch the On-Demand Webinar: What CI Fortify Doesn't Say About Communications
That is the premise behind CI Fortify, the joint guidance from CISA, the Australian Signals Directorate's Australian Cyber Security Centre, the FBI, and international partners including the U.K.’s Cyber Security Centre, the Canadian Centre for Cyber Security, and New Zealand national security centers. The guidance focuses on isolating vital operational technology and the systems that support it, so essential services can continue during a crisis.
The technical objective is sound. But it exposes an operational question that every critical infrastructure organization needs to answer before the next incident: once the network is cut off, how will the people running the response communicate?
Isolation Changes the Communications Problem
During normal operations, communications often ride on enterprise networks, cloud-based collaboration tools, carrier networks, or public internet paths. During a cyber incident, those channels may be unavailable, congested, compromised, or intentionally disconnected.
That means the fallback plan cannot be "use personal phones" or "switch to a consumer messaging app." Those tools may be outside organizational control, weak on auditability, dependent on the same degraded networks, or unable to provide the evidence needed after the incident.
"'Use personal phones' or 'switch to a consumer messaging app' cannot be the fallback plan." — Ramon Pinero, Vice President and General Manager, BlackBerry AtHoc
Out-of-Band Means More than a Separate Path
An out-of-band communications path must be independent of the systems being isolated. It must be trusted, and tested before the incident. It needs to stay functional under degraded conditions, not just in a clean tabletop exercise, and it must carry the functions a response depends on: alerting, acknowledgment, recall, secure coordination, and reporting.
That matters for your organization because response teams are often small. A utility, for instance, may have only a few people who know the plant, understand the control environment, and can make the right operational calls under pressure. If those people cannot be reached and coordinated, technical isolation will not deliver operational resilience.
The Coordination Record Matters
Resilience is now measured after the fact. Regulators, public agencies, boards, and communities may need to know who was notified, who responded, what actions were taken, and when critical updates were shared. A communications platform built only for reach but not for proof will leave a gap when your response record is examined.
Out-of-band communications should be funded and tested as part of every resilience plan. It carries command decisions, personnel accountability, field coordination, and external reporting when normal infrastructure cannot be trusted. That is not a convenience function.
Build It Before the Incident
The practical test is simple: can your team still coordinate internally and with external partners after the network is isolated? If the answer is "not sure," you have found a resilience gap.
Closing that gap means establishing a trusted out-of-band channel, validating response-critical devices, confirming alert delivery and acknowledgment, and rehearsing the process with the same seriousness applied to technical isolation. An isolation plan that cannot carry communications is incomplete. Your organization needs both: systems that can keep running and people who can keep coordinating.
When Operational Technology Goes Offline, Coordination Can't
Recent cyberattacks on U.S. water utilities delivered a stark wake-up call. OT networks at critical infrastructure are prime targets for threat actors, and the risk is no longer theoretical. That's why CISA's July 28 CI Fortify advisory is a clear directive: prepare today to isolate vital OT systems and sustain essential operations.
%3Aquality(100)&w=3840&q=75)