cisatrade-pressNewsThe Broadside2 min read

CI Fortify pushes OT isolation without the Monday playbook

Four allied agencies now agree critical infrastructure operators must be able to isolate operational technology during a crisis, but nobody's said how to sync data across the boundary in peacetime without breaking the isolation.


TL;DR

CISA, ASD, CCCS, and NCSC released joint guidance July 28 under the CI Fortify banner urging critical infrastructure operators to develop the capability to physically and digitally isolate operational technology from business networks and third-party systems. The guidance frames isolation as emergency planning, something operators should rehearse so essential services can continue during a geopolitical conflict when telecommunications and internet may be unreliable. It does not specify implementation timelines, compliance verification mechanisms, or how operators should manage routine data synchronization across isolated boundaries without creating the kind of workarounds that isolation is meant to prevent.

CI Fortify pushes OT isolation without the Monday playbook
Editorial illustration · drawn by The Broadside

The July 28 release of CI Fortify ("Advice for Isolating Vital Systems") marks the first time four allied cyber agencies have published joint guidance telling critical infrastructure operators the same thing: assume your third-party connections will be compromised or unavailable during a geopolitical conflict, and plan to run without them.

CISA's framing is blunt. "Operators should assume that in a conflict scenario third-party connections (such as telecommunications, internet, vendors, service providers, and upstream dependencies) will be unreliable and that threat actors will have some access to the OT network." The guidance positions isolation not as a technical control for normal operations but as an emergency capability, one operators should rehearse, with the goal of sustaining essential services "in a degraded communications environment."

That emergency-planning frame is both the guidance's strength and its limitation. CI Fortify tells operators what to practice: isolating from third-party networks including managed service providers, integrators, and cellular modems to remote sites, and recovering systems in that isolated state without phone or internet. It doesn't tell them how to manage the gap between the isolated emergency posture and the connected reality of day-to-day operations.

What's missing

CI Fortify is silent on three practical questions any operator will face. First, there's no implementation timeline, no expectation for when isolation capability should be in place. Second, there's no compliance verification mechanism beyond CISA's mention of "targeted assessments" of preparedness at certain organizations, which remain unnamed and are described as a pilot.

Third and most consequentially, the guidance doesn't address data synchronization across the isolation boundary during normal operations. An operator who builds an air-gapped OT environment still needs to move configuration files, maintenance logs, and compliance evidence between environments. Every informal workaround that fills that gap (a USB drive, a personal email account, a contractor's laptop) is itself a vector. The guidance names the risk of third-party connections. It doesn't name the risk of the shadow IT that isolation, rigidly applied, can produce.

Who this lands on

CISA has directed its initial assessments at "defense critical infrastructure", dams, radars, weapon systems, satellite communications, and related facilities. But the guidance's companion document for integrators and engineering firms makes clear the expectation runs broader: integrators are told to design customer OT systems so operators "retain primary control within their own networks" and to rehearse emergency response plans with customers.

For defense industrial base contractors and the assessors who validate their compliance, the signal is worth noting. Four-nation consensus doesn't create a regulatory mandate, but it does create a baseline against which preparedness will be measured, by CISA assessors, by procurement officers, and eventually by the auditors who show up asking for evidence of isolation testing.

The agencies haven't said when they expect answers. They have made clear they'll be asking the question.


Published ·Deep Fathom