GuidanceUS

CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure

Published by US Cybersecurity and Infrastructure Security Agency on 2026-07-28

Issued by
US Cybersecurity and Infrastructure Security Agency
Jurisdiction
US
Takes effect
Not stated
Comments close
Not applicable

In the issuer’s words

WASHINGTON - The Cybersecurity and Infrastructure Security Agency, Australian Signals Directorate (ASD), United Kingdom’s National Cyber Security Centre (NCSC-UK), and Canadian Centre for Cyber Security (CCCS) published CI Fortify – Advice for Isolating Vital Systems. This joint guidance, led by ASD, helps critical infrastructure operators protect essential services from escalating cyber threats and ensure continuity of operations during cyber incidents or geopolitical crises. 

State-sponsored cyber actors target critical infrastructure for several nefarious reasons such as espionage or service disruption, often linked to broader geopolitical conflicts. During crises or conflicts, operators of critical infrastructure and network defenders may isolate essential operational technology (OT) systems as an emergency measure to prevent adversaries from executing cyberattacks, to contain ongoing threats, and to facilitate the restoration of compromised systems. 

“America’s critical infrastructure is frequently targeted by malicious state-sponsored cyber threat actors whose aim is persistent access to vital systems and disrupt essential services such as telecommunications, water, energy, and transportation. As part of our CI Fortify Initiative, CISA, with our partners, provides this timely, collaborative resource that helps critical infrastructure ensure resilience during a crisis,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA urges OT owners and operators to maintain robust isolation and recovery plans so that essential services can continue under degraded conditions, enabled through either manual or alternative SCADA paths. Through proactive planning and practice, we can strengthen critical infrastructure defenses against state-sponsored threat actors.” 

In the event of a significant nationwide cyber incident disrupting supply chains or critical infrastructure, organizations need to be ready to sustain their operations independently for long periods. Essential steps in isolating important systems involve identifying assets, mapping their connections, and establishing separation points to ensure continued functioning during such incidents. The guidance covers: 

  • Identifying and mapping vital systems and connections
  • Building effective separation points
  • Graduated isolation planning and regular testing
  • Real-world examples of resilience during ransomware attacks

For more information, visit CISA’s CI Fortify webpage at cisa.gov/ci-fortify.

###

About CISA

As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day. 

Published by the US Cybersecurity and Infrastructure Security Agency. A work of the US federal government, in the public domain.

Read it at CISA news
Every entry here is reproduced from the body that issued it, under the licence named above it, and links to the original. Whether an obligation applies to your organisation is a question for your counsel, not for a tracker.