CISA and partners publish CI Fortify guidance for isolating critical infrastructure OT

CISA and partners publish CI Fortify guidance for isolating critical infrastructure OT

CISA and allied agencies issued CI Fortify guidance for isolating vital OT systems during cyber incidents and crises.

Format News Brief
Read Time 2 min
Category Cyber Security
Updated Jul 29, 2026

CISA and allied cyber agencies have published new CI Fortify guidance aimed at a hard problem for critical infrastructure operators: keeping essential operational technology running when internet, vendor, cloud or enterprise-network connections can no longer be trusted.

The July 28 guidance, led by the Australian Signals Directorate and released with CISA, the U.K. National Cyber Security Centre and the Canadian Centre for Cyber Security, focuses on isolating vital OT and enabling systems during a cyber incident, crisis or broader service disruption. The agencies frame isolation as a resilience measure, not just a security control: operators may need to disconnect parts of an environment while still delivering water, energy, transport, telecommunications or other essential services.

What the guidance asks operators to prepare

The document emphasizes preparation before a crisis. It tells critical infrastructure organizations to identify vital systems, map dependencies and connections, choose separation points, and test graduated isolation plans. That matters because OT environments often depend on business networks, external service providers, licensing servers, remote maintenance links and telecommunications paths that may be unreliable or unsafe during a major incident.

CISA said state-sponsored cyber actors frequently target critical infrastructure to gain persistent access or disrupt services. In that threat model, emergency isolation can help stop an adversary from moving through connected networks, contain an intrusion already in progress, and create cleaner conditions for restoring compromised systems.

  • Operators are urged to understand which systems are essential for minimum service delivery.
  • Network defenders should pre-plan how to separate OT from IT, vendors and third-party dependencies.
  • Exercises should test degraded operations, including manual procedures or alternative SCADA paths where appropriate.
  • Recovery planning should include the ability to rebuild or restore systems while isolated.

Why it matters now

The guidance lands as governments continue to warn that critical infrastructure is exposed to both criminal ransomware crews and state-backed actors. Many industrial networks were designed for uptime and safety rather than modern remote-access risk, and simply taking systems offline can carry public-safety or service-continuity consequences.

CI Fortify therefore pushes a practical middle ground: know what must keep running, know what it depends on, and rehearse how to disconnect risky connections without losing the core service. For operators, the takeaway is that isolation plans should be engineered, documented and practiced before an incident forces improvised decisions under pressure.

Sources

Cover photo by Sergey Sergeev on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...