CISA and its international partners are urging critical infrastructure operators to prepare for isolating vital systems during cyberattacks. The new guidance focuses on keeping essential operational technology running after it is disconnected from corporate, internet-facing and other less-trusted networks.
The advice is aimed at organisations in sectors such as water, energy, transport, manufacturing and telecommunications. These operators need plans in place before a serious incident forces them to contain an intrusion.
New guidance focuses on operational technology resilience
The guidance, called CI Fortify – Advice for isolating vital systems, was developed by CISA, the Australian Cyber Security Centre, the FBI and international partners.
It explains how organisations can separate essential operational technology, or OT, from other networks for an extended period. OT includes the hardware and software used to monitor or control real-world processes, from water treatment and electricity distribution to factory equipment and transport systems.
Government agencies warned that critical infrastructure remains a target for both cybercriminals and state-backed threat actors. Attackers may seek sensitive data, deploy ransomware or establish access that could be used to disrupt services during a future crisis.
Critical infrastructure faces persistent cyber threats
Recent incidents have highlighted the danger of attacks against essential services. In 2024, U.S. authorities warned that the China-linked Volt Typhoon group had infiltrated organisations in the communications, energy, transport and water sectors.
Officials said the group had remained inside at least one critical infrastructure network for five years. The campaign was believed to be focused on gaining access that could support disruptive activity during a conflict or major emergency.
Other groups, including Salt Typhoon, have also targeted telecommunications, government and transport networks. Meanwhile, water utilities have repeatedly faced cyber incidents, forcing some operators to deactivate systems or switch to manual processes.
Organisations should identify vital systems first
The agencies advise organisations to identify the minimum systems needed to continue delivering a critical service. These are referred to as vital systems.
For example, a water provider may need systems that control distribution and treatment. An electricity operator may need the systems required to keep power flowing. A telecommunications provider may need core equipment that maintains network availability.
Once identified, operators should map every connection to those systems. This includes links to corporate networks, cloud platforms, remote-access tools, suppliers, contractors, internet-facing services and other infrastructure operators.
Physical isolation offers the strongest protection
The guidance describes physical isolation as the most effective protection. This means fully disconnecting vital systems so they no longer share network or computing infrastructure with non-critical systems.
However, complete separation may not be practical for every operator. Some services rely on cloud systems, carrier networks, remote sites or internet-facing platforms.
In these cases, organisations should strengthen OT network boundaries, remove unnecessary corporate dependencies and use dedicated or encrypted communications links. They should also maintain the ability to rebuild important systems quickly.
Graduated isolation can limit an attack
The guidance recommends preparing isolation points in advance. These are predetermined locations where connections can be disabled or physically disconnected to stop an attacker moving between systems.
Operators may also use graduated isolation. This approach restricts access in stages as a threat becomes more severe.
For instance, an organisation could first block vendor and remote-worker access. It could then disconnect corporate systems, linked environments and, if necessary, all external connections.
Administrative controls, such as changes to VLANs, routing and access-control lists, can offer temporary protection. However, the agencies said physical isolation should remain the end goal where possible.
Isolation plans need regular full-scale testing
Organisations should test the complete isolation of vital systems regularly. Testing only individual systems can overlook shared infrastructure and hidden dependencies that may fail during a real incident.
Each plan should clearly set out who can authorise isolation, what conditions trigger each stage, which services must remain available and how staff will continue operations without normal connectivity.
The agencies also recommend storing the plan in a secure offline or printed format. This ensures teams can access it if corporate systems or file storage become unavailable.
Operators must prepare to work without normal connectivity
Isolation introduces its own challenges. Systems may miss security updates, monitoring can become more difficult and staff may rely more heavily on removable media to transfer data.
After isolating systems, operators should continue checking network traffic, routing tables and intrusion detection tools. This helps confirm that no unauthorised or accidental connection restores access between critical and non-critical networks.
Ultimately, the guidance stresses that isolating vital systems is not simply a technical step. Organisations must be ready to operate, monitor and maintain essential services manually until it is safe to reconnect.


0 responses to “CISA Advises Isolating Vital Systems During Cyberattacks”