Medium New document us

CISA, ASD, NCSC-UK, and CCCS publish CI Fortify guidance on isolating operational technology systems

Original title: CI Fortify – Advice for Isolating Vital Systems

CISA, Australian Signals Directorate, UK National Cyber Security Centre, and Canadian Centre for Cyber Security published CI Fortify – Advice for Isolating Vital Systems, a joint guidance document to help critical infrastructure operators protect essential services from state-sponsored cyber threats. The guidance enables organizations to maintain continuity of operations during cyber incidents or crises by establishing robust isolation and recovery plans. Critical infrastructure operators should identify and map vital systems, build effective separation points, develop graduated isolation plans with regular testing, and be prepared to sustain operations independently for extended periods under degraded conditions.

What changed

  • CISA and partner agencies (ASD, NCSC-UK, CCCS) released a new joint guidance document titled 'CI Fortify – Advice for Isolating Vital Systems' to provide critical infrastructure operators with frameworks for isolating operational technology (OT) systems during cybersecurity incidents and crises.
  • The guidance emphasizes identifying and mapping vital systems and their connections as a foundational step in establishing effective separation points to prevent adversary access and contain ongoing threats.
  • Organizations are advised to develop graduated isolation planning with regular testing to ensure they can sustain operations independently during significant nationwide cyber incidents that disrupt supply chains or critical infrastructure.
  • The guidance includes real-world examples of how organizations achieved resilience during ransomware attacks, providing practical case studies for critical infrastructure operators.
  • Operators should maintain both manual and alternative SCADA paths to enable essential services to continue functioning under degraded conditions when primary systems are isolated.

Who is affected

Critical infrastructure operators and owners in the United States and internationally, including those in telecommunications, water, energy, and transportation sectors. The guidance applies broadly to all organizations responsible for vital systems that may face state-sponsored cyber threats or geopolitical crises.

Action
Action required
Language
EN

Frameworks

CISA NCSC

Open the original source