Federal and allied cyber agencies this week published CI Fortify guidance advising critical-infrastructure operators to be able to disconnect or otherwise isolate vital operational-technology (OT) systems and the “enabling systems” that support them to limit the spread of a compromise and keep essential services running.
What the guidance tells operators
CI Fortify frames isolation as both a planning objective and an emergency tool. Operators are urged to map and prioritize ‘vital’ OT and enabling systems, build physical separation or hardened boundaries, and rehearse graduated isolation steps so they can execute disconnections safely if an incident demands it.
The materials instruct operators to identify the minimum set of systems needed to deliver each critical service, map all connections to those systems, and create “graduated” isolation plans that include step-by-step triggers for restriction or full separation. The guidance stresses that physical isolation — where feasible — is the strongest mitigation, though it will likely force manual operations and interrupt automated communications.
Where complete physical air-gapping is impractical, the advisory recommends hardening boundaries through segmentation, strict management-plane controls and encryption across carrier links, and it points operators to high-assurance technologies such as data diodes or cross-domain solutions. It also flags operational risks from prolonged isolation — patching gaps, reduced external visibility and reliance on removable media — and tells organizations to incorporate those trade-offs into planning and testing.
CI Fortify is presented as an allied initiative developed with international partners. Australia’s new CI Fortify advisory, published July 28, points readers to the U.S. CI Fortify resources and lays out technical checklists for identifying isolation points, using data diodes or cross-domain solutions, and testing isolation plans.
Emphasis on testing and recovery
A central theme is rehearsal: CI Fortify calls on organizations to build, exercise and validate isolation and recovery playbooks in peacetime so they can operate for an extended period in isolation if necessary. Recommended actions include documenting architecture and contact information, securing management interfaces, performing reachability tests and practicing full rebuilds from trusted artifacts.
CISA has previously framed CI Fortify as part of a broader push to ensure essential services can endure in a geopolitical crisis where third-party connections — telecoms, vendors, cloud services — may be unreliable. The agency has publicly urged operators to assume adversaries may already have footholds and to prioritize isolation, continuity and rapid recovery.
Context and divergent reporting
News coverage of this week’s allied advisory has been mostly technical and prescriptive, summarizing CI Fortify’s checklist-style recommendations and the allied release. At the same time, some online outlets have amplified more urgent or specific incident claims — for example, alleging active intrusions or large, coordinated disruptions to utilities.
Those incident and attribution claims do not appear in the CI Fortify guidance itself and have not been confirmed by the allied advisory documents. Security reporting and trade outlets have framed CI Fortify as raising expectations for operators — not as binding regulation — while warning that the guidance could create challenging operational and governance questions for utilities and other sectors if implemented without careful safety and continuity planning.
What to watch next
Look for the U.S. agency’s canonical CI Fortify page or PDF and any joint press statements naming participating agencies and the formal authorship list; those primary records will clarify whether the July 28 allied document is co-signed and whether additional technical annexes were released.
Also watch for sector responses — state agencies, utilities trade groups and water, power and transportation operators often publish implementation guidance or after-action summaries after an advisory. Their tabletop and exercise results will show whether operators can safely reconcile isolation with public-safety, regulatory and continuity obligations.
Sources reviewed
- Reuters: Critical Infrastructure Cybersecurity
- hstoday.us: CISA Releases Joint Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure
- Tech Times: China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans
- cyberpress.org: CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
- CyberSecurityNews: CISA Releases Checklist for Critical Infrastructure Organizations to Isolate Vital Systems
- BleepingComputer: CISA shares advice on isolating vital systems during cyberattacks
- gbhackers.com: CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
- varindia.com: Five Eyes cyber agencies urge critical infrastructure operators to prepare for emergency OT isolation
- Rescana: Coordinated Cyberattack Disrupts Operational Technology in 30+ Minnesota Water Utilities – Incident Analysis and Response Recommendations
- Cyber Daily: ASD, CISA and partners release critical infrastructure security advice
- Australian Cyber Security Centre / Cyber.gov.au: CI Fortify — Advice for isolating vital systems (PDF)
- CISA (govdelivery bulletin): CISA and U.S. Government Partners Unveil Guide to Accelerate Zero Trust Adoption in Operational Technology
- SecurityWeek: CISA Launches ‘CI Fortify’ to Prepare Critical Infrastructure for Geopolitical Cyber Conflict
- Cybersecurity Dive: CISA urges critical infrastructure firms to ‘fortify’ before it’s too late