CISA shares advice on isolating vital systems during cyberattacks

The US and Australian governments have issued new guidance for critical infrastructure organizations to prepare for isolating vital operational technology (OT) systems in the event of a cyberattack. The advice, developed by the US Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and international partners, aims to help organizations protect themselves against state-sponsored threat actors who target critical infrastructure for espionage and potential disruptive attacks.

Critical infrastructure operators, including those in water treatment, electrical systems, manufacturing, transportation, and telecommunications sectors, are at risk of cyberattacks. State-sponsored hackers have been targeting these organizations for years, with the Chinese Volt Typhoon hacking group breaching US communications, energy, transportation, and water sector networks as far back as 2024. The hackers remained undetected in one network for five years, positioning themselves for potentially disruptive attacks during a future crisis or conflict.

The new guidance, titled “CI Fortify,” recommends that critical infrastructure entities identify the minimum systems and networks required to continue delivering essential services. They should then document every connection between those systems and corporate networks, remote-access services, cloud environments, Internet-facing infrastructure, vendors and contractors, and other critical infrastructure operators. This will help organizations determine where connections can be disabled or physically disconnected and account for the manual processes, communication failures, and loss of external resources or dependencies that isolation may trigger.

The guidance also highlights the importance of understanding vital systems, which include OT hardware and software used to monitor or control processes. Isolating these systems requires a clear plan, including identifying potential isolation points where connectivity between critical and non-critical networks or systems can be disconnected to contain an attack. This process is not trivial, as it involves manually disconnecting systems and accounting for the loss of external resources.

The new guidance is a response to the increasing threat of cyberattacks on critical infrastructure. In recent years, we have seen numerous examples of water treatment facilities being targeted, with some deactivating systems following attacks and others switching to manual operations. Government agencies have also warned that pro-Russian hacktivists were seeking out unsecured OT systems used by water facilities and other critical infrastructure organizations.

The CI Fortify guidance is a proactive measure aimed at helping organizations prepare before a cyberattack occurs, rather than attempting to determine how vital systems can be disconnected while an attack is already underway. It emphasizes the importance of understanding the complex interconnections between OT systems and corporate networks and developing a clear plan for isolating vital systems in the event of a cyberattack.

For critical infrastructure operators, this guidance provides a much-needed framework for preparing against potential cyberattacks. By following the recommendations outlined in CI Fortify, organizations can reduce their risk exposure and improve their ability to respond to and recover from a cyberattack. This is not a one-time task but rather an ongoing process that requires continuous monitoring and maintenance of critical systems.

In practical terms, this means that organizations should regularly review their OT systems and networks to identify potential vulnerabilities and develop plans for isolating vital systems in the event of a cyberattack. This includes identifying isolation points, disabling connections between critical and non-critical networks or systems, and accounting for manual processes, communication failures, and loss of external resources. By taking these steps, organizations can better protect themselves against state-sponsored threat actors and reduce the risk of disruptive attacks on critical infrastructure.


Source: Bleeping Computer — 2026-07-28