CISA and ACSC Release OT Isolation Guidance for Critical Infrastructure
- CVE ID
- N/A
- Affected Products / Orgs
- Critical Infrastructure Operators, Operational Technology (OT) Systems, Industrial Control Systems (ICS)
In a joint initiative to strengthen industrial environments against destructive cyber attacks and persistent threat actors, the US Cybersecurity and Infrastructure Security Agency (CISA) and Australia’s Cyber Security Centre (ACSC) have released joint OT isolation guidance for critical infrastructure operators. Titled CI Fortify – Advice for isolating vital systems, the guidance details how organizations managing operational technology (OT) and supporting networks can sever external connections and operate in complete isolation for extended periods during a crisis.
Rather than treating network disconnection as an emergency measure of last resort, the joint advice frames “islanding” as a deliberate, pre-engineered operational capability designed to contain active intrusions, disrupt adversary playbooks, and ensure the uninterrupted delivery of essential public services.
Why Pre-Engineered OT Islanding Matters
Modern critical infrastructure relies on increasingly tight convergence between enterprise IT and operational environments. While cloud integration, centralized management, and remote vendor access improve operational efficiency, they also open propagation pathways into industrial control systems (ICS)—including Human-Machine Interfaces (HMIs), Programmable Logic Controllers (PLCs), and Distributed Control Systems (DCS).
Threat actors targeting critical sector entities frequently establish initial access within enterprise IT networks or vendor management jump hosts before attempting lateral movement into process control networks. In many high-profile cyber incidents, operators have shut down plant operations out of an abundance of caution—not because control loops were compromised, but because defenders lacked boundary visibility and had no verified mechanism to isolate OT networks without disrupting physical operations.
Building pre-engineered separation points enables critical infrastructure entities to cut off adversary access paths instantly while keeping underlying physical infrastructure running under local, isolated control.
Core Execution Steps in the Framework
The CI Fortify guidance outlines five key operational planning phases that critical infrastructure security teams and plant operators must establish long before an incident occurs:
- Asset Identification and Criticality Zoning: Organizations must map all systems, networks, and downstream customers that rely on their services. Assets should be categorized by criticality and trust levels, then segmented into defined operational zones (aligning with Purdue Model principles) to limit exposure and streamline access controls.
- Comprehensive Boundary and Connection Mapping: Operators must identify and document every connection bridging vital OT networks to external environments. This includes enterprise corporate IT, vendor remote access channels, peer utility data feeds, cloud management platforms, and scheduler or dispatch interfaces.
- Physical Isolation Points: Logical separation enforced by firewalls or VLAN configurations can be undermined if an attacker gains administrative access to network devices. To guarantee effective containment, CISA and ACSC emphasize that physical separation is a prerequisite. Operators must engineer physical isolation mechanisms—such as hardware cut-off switches or air-gapped patching pathways—that allow networks to operate fully decoupled.
- Graduated Isolation Plans: Disconnecting an entire industrial network at once can introduce severe operational stability risks. The guidance recommends establishing a graduated isolation strategy that allows defenders to progressively sever external pathways in controlled stages, balancing containment against operational dependencies.
- Continuous Boundary Monitoring: Throughout any period of isolated operation, defenders must continuously monitor isolation points to ensure no temporary bypasses, rogue wireless bridges, or unauthorized network links are established.
Managing the Risks of Isolated Operations
Disconnecting OT networks from enterprise networks introduces distinct operational friction and trade-offs that security leaders must account for during response planning:
- Vulnerability and Patch Management Stalls: Sustained isolation blocks automated patch deployment, creating a growing backlog of unaddressed software flaws while systems remain disconnected from central repositories.
- Reduced Threat Visibility: Cutting off centralized security operations center (SOC) telemetry limits real-time event detection and remote monitoring, placing greater reliance on local logging and on-site engineering teams.
- Elevated Removable Media Exposure: When network file transfers are severed, personnel often turn to USB drives and external media to transfer critical operational data, configuration files, and logic updates. This shift significantly increases the risk of introducing malware directly into isolated control zones via portable media.
- Disruption of External Operational Dependencies: Severing system-to-system communications interrupts automated data feeds relied upon by upstream peers, utility dispatchers, and business applications, forcing operators to revert to manual business processes.
Guidance Implementation for Defenders
Critical infrastructure owners and operators should integrate the CI Fortify – Advice for isolating vital systems recommendations directly into their operational business continuity and incident response playbooks. Security teams and SCADA engineers should collaborate immediately to audit cross-boundary connections, document upstream/downstream peer dependencies, and conduct practical exercises testing manual failover processes. Additional technical resources and resilience tools are available through CISA’s dedicated CI Fortify initiative platform.
Related content
CISA and ACSC Issue CI Fortify Guidance for Isolating Critical OT Systems
Security NewsCrafted SVGs in Bing Image Search Allow SYSTEM Command Execution
Security NewsCISA Discloses Internal AWS GovCloud Credential Leak and Lack of Incident Response Plan
Security NewsCISA Adds Four Actively Exploited Vulnerabilities, Including SonicWall and Microsoft…
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call