>samit_hota
Back to security news
SN-2026-218HighOpen

CISA and ACSC Issue CI Fortify Guidance for Isolating Critical OT Systems

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Critical Infrastructure Operators, Operational Technology (OT) Systems, Industrial Control Systems (ICS)
#news#ransomware#cisa

The Cybersecurity and Infrastructure Security Agency (CISA), alongside the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and Five Eyes international partners, has issued joint guidance titled “CI Fortify - Advice for isolating vital systems.” The joint advisory addresses a systemic vulnerability across global critical infrastructure: the tight coupling of operational technology (OT) environments with corporate networks and internet-facing assets. As state-sponsored actors and cybercriminals target water treatment facilities, power grids, and telecommunications, government agencies are urging critical infrastructure operators to design, document, and test plans for isolating vital operational technology systems before an active intrusion forces an unmanaged emergency shutdown.

Why Interconnected OT Environments Are At Risk

Operational technology encompasses the industrial control systems (ICS), supervisory control and data acquisition (SCADA) networks, and physical hardware responsible for controlling critical processes—ranging from water distribution pumps and electrical switches to manufacturing lines and telecommunications switching gear. Historically air-gapped from external networks, modern OT environments have become increasingly connected to corporate IT networks, cloud infrastructure, and vendor remote-access portals to enable real-time telemetry, predictive maintenance, and centralized administration.

This convergence introduces substantial risk. Threat actors do not necessarily need to develop specialized industrial malware to disrupt operations. Instead, they exploit vulnerabilities in edge networking devices—such as firewalls, VPN concentrators, and routers—or compromise legitimate remote-access credentials to establish an initial foothold. Once inside the corporate IT environment or edge network, attackers execute lateral movement techniques to pivot directly into OT networks. Because legacy OT protocols (such as Modbus, DNP3, and BACnet) often lack native authentication, encryption, or granular access controls, an adversary with access to an internal OT segment can manipulate physical equipment, modify programmable logic controller (PLC) setpoints, or completely halt operations.

Active Threats: Volt Typhoon, Salt Typhoon, and Ransomware

The “CI Fortify” advisory directly addresses persistent activity from advanced persistent threat (APT) groups and cybercriminals targeting critical infrastructure networks:

  • Volt Typhoon: State-sponsored Chinese hackers breached critical infrastructure entities across the communications, energy, transportation, and water sectors. Volt Typhoon relies heavily on Living-off-the-Land (LotL) techniques—using native administrative utilities like WMI, PowerShell, and netsh—to evade detection. In at least one instance, the group maintained undetected access within a critical infrastructure network for five years, positioning itself to execute disruptive or destructive attacks during a geopolitical crisis or military conflict.
  • Salt Typhoon: Active since at least 2021, this Chinese state-sponsored group compromised major U.S. telecommunications providers—including AT&T, Verizon, and Lumen—by exploiting flaws in edge networking devices and abusing trusted connections. Their intrusions allowed them to harvest sensitive communications and access U.S. law enforcement wiretap request systems.
  • Water Sector Targeting: In October 2024, American Water deactivated internal systems following a cyberattack to contain an intrusion, impacting services associated with over 14 million customers. Around the same time, a Kansas water treatment facility was forced to switch to manual operations after unauthorized actors compromised its digital systems. In parallel, pro-Russian hacktivists have systematically sought out unsecured OT human-machine interfaces (HMIs) across water facilities to disrupt operations.

Core Isolation Strategies in the CI Fortify Framework

Executing network isolation during an active breach often results in unexpected outages or partial disconnections that fail to halt lateral movement. The CI Fortify framework advocates for pre-planned isolation capabilities categorized into clear operational concepts:

  • Vital Systems Mapping: Organizations must map their environments down to the absolute minimum subset of OT, SCADA, and supporting infrastructure required to sustain essential services, stripping away non-essential remote monitoring or administrative dependencies.
  • Isolation Points: Security and engineering teams must pre-define exact network locations where connectivity between critical OT and non-critical IT networks can be severed.
  • Physical Isolation: Recognized as the most effective defense, physical isolation involves completely disconnecting network cables or disabling physical interface ports so vital systems share zero computing or network infrastructure with non-critical systems.
  • Graduated Isolation: A phased approach that progressively restricts access as threat levels escalate—such as first blocking remote vendor access, then severing corporate network connections, and eventually cutting all external ingress and egress.
  • Administrative Controls and Data Diodes: While administrative controls like VLAN segmentation, access control lists (ACLs), and firewall rules offer temporary software-defined protection, hardware-enforced data diodes—which physically restrict network traffic to one-way transmission—provide high assurance for outbound telemetry from OT to IT.

Operational Considerations and Execution Safeguards

Disconnecting OT networks introduces secondary security and operational challenges that operators must account for in advance. When an OT network is isolated, automated monitoring, centralized logging, and routine patch management platforms are typically severed. As a result, systems can quickly lag behind on security updates. Furthermore, operational teams often rely on removable media like USB drives to transfer data across isolated boundaries, introducing new malware vectors if strict media-sanitization protocols are not enforced.

To maintain operational resilience, CI Fortify recommends keeping secure, printed offline copies of all isolation playbooks and network topology diagrams, as corporate storage servers and active directory domains may be rendered inaccessible during an incident. Organizations should conduct full-scale isolation drills rather than isolated component testing to uncover hidden network dependencies, dual-homed devices, and shared infrastructure before an attacker forces an emergency disconnection. Post-isolation procedures must also include continuous monitoring of internal routing tables, network traffic, and intrusion detection systems to confirm that unauthorized paths do not re-establish connectivity.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call