IT and Cyber Outage Message Templates
Templates for the four things IT actually needs to broadcast: outage started, security concern raised, still working on it, and resolved.
When IT / Cyber Templates Matter
Two very different message families live under "IT notification." The first is the routine service outage - a system is down, a workaround exists, restoration is being worked on. The second is the suspected security incident, where the wording has to serve users without inadvertently confirming an attacker's success or making legal or regulatory obligations worse. The four templates below draw that line explicitly and give the on-call incident commander pre-approved language for the moment when composing a message from scratch would either be too slow or too risky.
Every outage template assumes the message may need to reach people through a channel other than the one that's currently broken. Set your channel defaults accordingly.
Template Variants
a. Initial Outage Notice
Routine outage. Names the affected system, points to the documented workaround, sets an update time.
b. Suspected Security Incident
Cautious language for when a security cause is possible but unconfirmed. Prompts user protective action without labeling.
c. Ongoing Status Update
Honors the cadence you promised. Even "no change" is better than silence.
d. Resolution
Marks the outage closed. Gives a channel for stragglers still seeing issues.
Customization Checklist
- Reference documented downtime and workaround procedures by name in every initial notice - do not invent them inside a message
- Keep routine-outage language distinct from security-incident language; the distinction protects both users and the organization
- Identify who in IT or security has authority to activate each variant and who must approve any message that mentions a security concern
- Set a legal and communications review threshold for security-incident-labeled messages before an event, not during one
- Configure fallback channels that do not depend on the systems most likely to be affected (SMS or voice when email or chat is down)
- Set and honor an update cadence - silence during a long outage generates more inbound tickets and speculation than a "no change" message
Related Guides
- Message Templates Library
- How to Write Emergency Notification Templates
- Channel Selection and Redundancy
- Delivery Verification and Acknowledgement
Frequently Asked Questions
Why use different wording for a routine outage than for a suspected security incident?
Labeling an event a security incident in a broadcast message can tip off an active attacker, invite media attention, and create legal exposure before the situation is understood. The suspected-security-incident variant uses cautious, action-oriented language ("technical issue," "as a precaution") that protects users without prematurely declaring an incident.
Which channel should IT outage messages use?
When the outage affects the primary internal channel (email or chat), a fallback channel matters more than the ideal channel. SMS and voice reach people regardless of which internal system is degraded. Never notify about an email outage only by email.
How often should status updates go out during a long outage?
Set a cadence you can actually meet - commonly 30 to 60 minutes for user-impacting outages - and honor it even when there is no new information. A "no change, next update in 30 minutes" message beats silence and reduces the volume of individual inquiries to the help desk.
Who should authorize a message that mentions a security incident?
Anything labeled as a security or cyber incident should route through a defined approval - typically the security lead, legal, and communications - because those messages can trigger regulatory notification obligations and shape external narrative. Routine outage messages do not need this gate.
Should we tell people what workaround to use in the message?
Yes - reference a documented downtime procedure by name rather than embedding step-by-step instructions in an SMS. This keeps the message short and forces the procedure to actually exist and stay current, instead of being invented under pressure inside a 160-character message.
