cisatrade-pressNewsThe Broadside2 min read

CISA to publish CI Fortify lessons learned from Five Eyes assessments

The agency is collecting field data on whether operators can actually isolate and recover OT systems under duress, and plans to turn that into practical guidance, not just another framework document.


TL;DR

CISA is conducting assessments of critical infrastructure operators' ability to isolate and recover OT systems during a cyber incident, and will publish the resulting lessons learned alongside isolation and recovery guidance co-developed with Five Eyes partners. The initiative, CI Fortify, launched in May 2025 and has already produced joint guidance on OT isolation led by the Australian Signals Directorate in July. ICS lead Matt Rogers told a Sept. 21 webinar that operators need to test their plans: "If you haven't tested it, you don't really know if it's going to work."

CISA's CI Fortify initiative is moving from framework-level advice to something closer to field-tested practice. At a Sept. 21 webinar, JCDC acting deputy associate director Matthew Springer said the agency is currently assessing how well critical infrastructure partners can isolate and recover OT systems, and will distill the feedback into "common-sense best practices and lessons learned."

The output will cover two operational problems (how to isolate and how to recover) and will be published jointly with Five Eyes partners Australia, Canada, New Zealand, and the United Kingdom. That's in addition to the July 28 isolation guidance already released under the initiative, which was led by the Australian Signals Directorate and signed onto by CISA, the UK's NCSC, and Canada's CCCS.

ICS lead Matt Rogers pointed to a tension familiar to anyone who's written an IR plan: "The idea of an assumed breach, the idea of somebody in your critical infrastructure, it is really difficult to actually draw down on paper and write up an incident response plan and a business continuity plan." His bottom line: if you haven't tested it, you don't know if it works. CISA runs a technical exchange group where operators discuss what breaks under realistic conditions before they test in their own environments.

Springer framed the international collaboration as a practical necessity. "The U.S. government and international partners need to burden share on this," he said. "It is just too big of an effort within our own internal U.S. critical infrastructure, [because there are] just too many entities."

Rogers also noted that the threat landscape has shifted. Attacks on civilian critical infrastructure, he said, were historically "restricted to nation-state actors" and constrained by deterrence, but "we've seen threat actors do some pretty wild stuff over the last year." The CI Fortify guidance lands in a moment where the old norms around targeting civilian OT no longer hold.


Published ·Deep Fathom