The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), the Federal Bureau of Investigation (FBI), and other international entities, has unveiled a comprehensive guidance document aimed at bolstering the resilience of critical infrastructure organizations. This initiative, known as the CI Fortify guidance, offers actionable strategies to help organizations swiftly isolate essential systems during active cyber incidents or geopolitical disturbances.
Central to the CI Fortify guidance is the emphasis on maintaining uninterrupted essential services, even when primary networks face compromise. This approach ensures that vital operational technology (OT) systems—integral to sectors such as energy, water, transportation, and healthcare—can function independently from corporate IT networks and external connections. Such measures are in line with broader operational technology frameworks designed to safeguard legacy industrial assets.
Key Components of the CI Fortify Guidance
The guidance provides a structured methodology for identifying and prioritizing “vital systems,” defined as assets crucial to safety, service delivery, or national security. Organizations are encouraged to assess dependencies, including upstream and downstream systems, to comprehend how disruptions might cascade across operations.
To prepare organizations for emergency isolation, the joint advisory outlines a checklist of technical and operational measures:
- Asset Mapping: Identify critical assets and map system interdependencies across IT and OT environments.
- Separation Points: Establish clearly defined separation points between vital systems and less critical networks.
- Isolation Mechanisms: Implement secure isolation mechanisms such as air-gapping, network segmentation, or controlled disconnection procedures.
- Manual Fallbacks: Develop and test manual fallback procedures to maintain operations without digital dependencies.
- Personnel Readiness: Ensure personnel are trained to execute isolation protocols during emergencies.
Additionally, the guidance underscores the importance of pre-configured isolation plans that can be activated rapidly, minimizing decision-making delays during active incidents. For instance, a power grid operator could isolate its supervisory control and data acquisition (SCADA) systems from corporate IT networks during a ransomware attack. By pre-establishing segmentation controls and manual override capabilities, the operator can continue delivering electricity while incident response teams contain the threat within non-critical systems.
This release comes amid a surge in cyberattacks targeting critical infrastructure globally, including campaigns against industrial control systems driven by advanced persistent threat (APT) groups and geopolitical tensions. These campaigns often exploit weak segmentation between IT and OT environments, enabling lateral movement and widespread disruption. By focusing on isolation as a defensive strategy, CISA and its partners aim to limit attacker access and reduce the blast radius during incidents.
The guidance aligns with broader secure-by-design and resilience-focused initiatives promoted across international cybersecurity agencies. This shift from purely preventive security models to resilience-driven approaches prepares organizations to operate through compromise, rather than assuming breaches can always be prevented.
For cybersecurity leaders, this underscores the necessity of integrating isolation planning into incident response strategies. By proactively establishing isolation protocols and training personnel accordingly, organizations can enhance their ability to maintain critical operations amidst evolving cyber threats.