CISA shares advice on isolating vital systems during cyberattacks

The US and Australian governments have issued a joint warning to critical infrastructure organizations about the urgent need to prepare for potential cyberattacks. In new guidance, the US Cybersecurity and Infrastructure Security Agency (CISA) and its international partners urge companies to identify and isolate vital operational technology systems in case of an attack.

This advice comes on the heels of repeated warnings from government agencies about state-sponsored hackers targeting critical infrastructure for espionage and potentially destructive attacks during a crisis or military conflict. CISA has specifically highlighted Chinese state-sponsored groups, such as Volt Typhoon and Salt Typhoon, which have breached organizations in the communications, energy, transportation, and water sectors.

These hackers often exploit known vulnerabilities to gain access to sensitive systems, using compromised equipment and trusted connections to pivot into other networks. Water infrastructure has been a particular target, with at least one major provider, American Water, deactivating some systems following a cyberattack in October 2024. Around the same time, a Kansas water treatment facility had to switch to manual operations after its systems were compromised.

The new guidance aims to help organizations prepare for such incidents by identifying and isolating vital operational technology (OT) systems from corporate networks, remote-access services, cloud environments, Internet-facing infrastructure, vendors, and contractors. This involves documenting every connection between critical systems and other networks, determining where those connections can be disabled or physically disconnected, and accounting for the potential consequences of isolation.

To put this into perspective, operational technology includes hardware and software used to monitor or control processes in industries such as manufacturing, transportation, telecommunications, and water treatment. Isolating these systems from corporate networks would allow organizations to continue providing essential services even if an attack occurs on their more vulnerable corporate infrastructure.

The guidance emphasizes that isolating vital systems is a proactive measure that can help prevent the spread of malware and reduce the impact of a potential cyberattack. By preparing for such incidents in advance, critical infrastructure entities can minimize the risk of disruption to their operations and protect sensitive data from unauthorized access.

For those responsible for securing critical infrastructure, this guidance provides valuable advice on how to prepare for the worst-case scenario. It highlights the importance of understanding network connections, identifying vulnerabilities, and having a plan in place to isolate vital systems quickly and efficiently.


Source: Bleeping Computer — 2026-07-28