cisatrade-pressNewsThe Broadside1 min read

CISA and allied partners publish CI Fortify OT isolation guidance

The guidance operationalizes the isolation half of CISA's May CI Fortify initiative, six steps from asset identification through post-isolation verification, with adversaries assumed to have some OT access from the start.


TL;DR

CISA joined the Australian Signals Directorate, the UK's NCSC, the Canadian Centre for Cyber Security, and New Zealand's NCSC to publish "CI Fortify, Advice for Isolating Vital Systems" on July 28. The joint guidance, led by ASD, gives OT owners and operators a six-step path for isolating critical systems from business and third-party networks during a cyber incident or geopolitical crisis. The planning assumption is blunt: in a conflict scenario, assume threat actors already have some access to the OT network and that telecom, internet, and vendor dependencies will be unreliable.

The guidance is the second major output from CI Fortify, the resilience initiative CISA launched May 5. That first release established isolation and recovery as paired emergency capabilities. Monday's document supplies the practical isolation playbook.

The six-step path runs from asset identification and connection mapping through establishing separation points, then moves into post-isolation verification and monitoring. A graduated isolation plan (progressively severing pathways to vital OT and enabling systems) gets particular attention as the mechanism for balancing security against business continuity.

CISA Acting Executive Assistant Director for Cybersecurity Chris Butera framed the guidance around degraded operations: "CISA urges OT owners and operators to maintain robust isolation and recovery plans so that essential services can continue under degraded conditions, enabled through either manual or alternative SCADA paths."

What's new here

Previous allied OT guidance, like the October 2024 "Principles of Operational Technology Cybersecurity," focused on governance-level decision-making, six principles for how business choices affect OT security posture. This one is operational. It assumes a crisis is either underway or imminent and tells you what to disconnect, in what order, and how to verify it stayed disconnected.

The guidance also reflects a practical escalation in threat modeling. The CI Fortify program's core scenario is a nation-state conflict where third-party connectivity cannot be relied upon and adversaries are prepositioned in OT environments. That's a harder planning assumption than most U.S. critical infrastructure sectors have publicly adopted.

What's missing

CI Fortify's May launch framed isolation and recovery as paired capabilities, but Monday's document is almost entirely isolation. Recovery gets mention in the planning context (testing recovery plans, practicing local and manual operations) but the detailed procedural treatment hasn't arrived yet. For asset owners building a full CI Fortify program, the recovery half remains the May guidance and their own engineering.


Published ·Deep Fathom