Key Takeaways
- The U.S. CISA, Australian ACSC, FBI and international partners issued “CI Fortify – Advice for isolating vital systems” to help critical‑infrastructure (CI) operators prepare to disconnect essential operational‑technology (OT) assets during cyberattacks or major disruptions.
- State‑sponsored groups such as Chinese Volt Typhoon and Salt Typhoon, as well as pro‑Russian hacktivists, routinely target CI for espionage, persistence, and potential disruptive or destructive actions in crises.
- The guidance defines vital systems as the minimum OT and supporting assets needed to keep a critical service running, and recommends identifying all connections to corporate, Internet‑facing, cloud, vendor and partner networks.
- Isolation can be achieved through physical isolation (complete disconnection), graduated isolation (stepwise restriction), or administrative controls; physical isolation is deemed the most effective protection.
- Technical aids like data diodes, VLAN adjustments, access‑control lists, and encrypted links can support isolation when full physical separation is impractical.
- Organizations must document isolation points, assign authority for each step, define trigger conditions, and maintain an offline copy of the plan to ensure availability if corporate networks are compromised.
- Regular full‑system isolation testing—not just component testing—is essential to uncover hidden dependencies and verify that the plan works under real‑world conditions.
- While isolation improves security, it introduces operational risks such as delayed patching, reduced monitoring, and increased reliance on removable media; mitigations include manual update procedures, continued traffic monitoring, and secure network‑management zones.
Introduction and Purpose of the CI Fortify Guidance
The Cybersecurity and Infrastructure Security Agency (CISA) of the United States, together with Australia’s Signals Directorate Australian Cyber Security Centre (ACSC), the FBI, and several international partners, have released a joint advisory titled “CI Fortify – Advice for isolating vital systems.” The document is directed at owners and operators of critical infrastructure—including water treatment, electricity generation, manufacturing, transportation, and telecommunications—and aims to equip them with concrete steps to pre‑emptively isolate essential operational‑technology (OT) assets when faced with a cyberattack, natural disaster, or other major disruption. Rather than reacting in the heat of an incident, the guidance encourages organizations to develop, test, and maintain isolation capabilities now, thereby reducing the window of opportunity for adversaries to cause widespread damage.
Threat Landscape Targeting Critical Infrastructure
State‑sponsored actors continue to view CI as a high‑value target for espionage and for establishing footholds that could later be leveraged in disruptive or destructive campaigns during geopolitical tensions. The advisory notes that cybercriminals also opportunistically pursue CI operators, attracted by the sensitivity of the data they hold and the potential to extort victims through ransomware or data‑exfiltration schemes. Recent alerts highlight two Chinese advanced persistent threat (APT) groups—Volt Typhoon and Salt Typhoon—as having infiltrated sectors such as communications, energy, transportation, and water, sometimes remaining undetected for years. In parallel, pro‑Russian hacktivist collectives have been observed probing for unsecured OT devices at water facilities and other CI sites with the intent to disrupt service. These trends underscore the necessity for defenders to assume that a breach may already be present and to plan for rapid containment.
Historical Incidents Illustrating the Need for Isolation
The guidance cites several real‑world examples that demonstrate why isolation planning is vital. In February 2024, a coalition of U.S. and Five‑Eyes agencies warned that the Volt Typhoon group had compromised organizations across multiple CI sectors, persisting in at least one network for five years while positioning itself for future disruptive actions. Salt Typhoon, active since at least 2021, has breached government, telecommunications, transportation, lodging, and military networks worldwide, gaining access to sensitive communications and even U.S. law‑enforcement wiretap systems. The water sector has suffered repeated blows: American Water, serving over 14 million customers, deactivated portions of its systems after a cyberattack in October 2024, and a Kansas treatment facility reverted to manual operations when its OT was compromised. These cases show that attackers can linger undetected, manipulate trusted connections, and exploit edge‑device vulnerabilities to pivot laterally—precisely the scenarios the CI Fortify guidance seeks to thwart.
Defining Vital Systems and Isolation Points
A core step in the CI Fortify methodology is identifying the minimum set of OT and supporting systems required to sustain a critical service—labelled vital systems. Examples include the controllers that regulate water distribution, the relays that maintain electricity flow, or the switches that keep a telecommunications network operational. Once these systems are delineated, organizations must map every connection they have to less‑trusted environments: corporate LANs, remote‑access portals, cloud services, Internet‑facing assets, third‑party vendors, and links to other CI operators. Each of these linkages represents a potential isolation point—a predetermined location where connectivity can be severed to contain an attack and prevent lateral movement into other vital assets. Documenting these points creates a clear blueprint for rapid, controlled disconnection when needed.
Forms of Isolation: Physical, Graduated, and Administrative Controls
The advisory distinguishes three primary isolation strategies. Physical isolation entails completely disconnecting vital systems from all non‑critical networks, ensuring they share no computing or network infrastructure. This approach is described as the most effective because it eliminates the pathways attackers use to move laterally. When full physical separation is impractical—due to reliance on Internet‑facing services, carrier links, cloud platforms, or geographically dispersed facilities—the guidance recommends graduated isolation. This method involves progressively tightening restrictions as threat levels rise: first blocking remote workers and vendors, then severing corporate network links, followed by disconnecting connected systems, and finally cutting all external connections. Complementary administrative network controls—such as adjusting VLANs, access‑control lists (ACLs), and routing policies—can serve as temporary measures, but the ultimate goal remains achieving physical isolation where feasible. The document also highlights specialized tools like data diodes, which permit data to flow in only one direction, thereby reducing the risk of malicious traffic infiltrating the isolated environment.
Technical and Operational Considerations for Implementation
For organizations that cannot adopt outright physical isolation, the guidance offers several hardening practices. Strengthening OT network boundaries, employing dedicated or encrypted communication links, and eliminating unnecessary dependencies on corporate systems can raise the bar for attackers. Maintaining the capacity to rapidly rebuild systems from known‑good backups is also essential. Crucially, isolation plans must specify who has the authority to authorize each disconnection step, what conditions trigger the plan (e.g., detection of malicious activity, loss of integrity alerts, or geopolitical escalation), which systems must remain operational throughout the process, and how essential services will continue without normal network connectivity. Keeping a secure offline or printed copy of the plan ensures that it remains accessible even if corporate servers or storage are compromised during an incident.
Testing, Validation, and Ongoing Maintenance
The advisory stresses that testing should involve the complete isolation of vital systems, not merely individual components. Partial tests may miss shared infrastructure or hidden dependencies that only manifest when the full isolation sequence is executed, leading to unexpected failures during a real event. Regular, full‑scale exercises help validate that isolation points function as intended, that communication fallback mechanisms (e.g., radio, satellite) work, and that personnel understand their roles. After isolation is achieved, continuous monitoring of routing tables, network traffic, and intrusion‑detection systems is required to confirm that no unauthorized connections have been inadvertently restored. Additionally, the network‑management zones used to configure routers, firewalls, and other infrastructure must themselves be isolated from potential attackers to prevent tampering with the isolation controls.
Risks Introduced by Isolation and Mitigation Strategies
While isolation dramatically reduces the attack surface, it also introduces operational trade‑offs. Systems isolated from external networks may fall behind on security patches, experience degraded monitoring capabilities, and necessitate greater use of removable media (e.g., USB drives) to transfer updates or data—each of which can become a new vector if not managed carefully. To mitigate these risks, organizations should establish manual patch‑management procedures, maintain air‑gapped update repositories, and enforce strict controls on removable media (such as whitelisting, encryption, and scanning). Continued traffic monitoring within the isolated enclave helps detect insider threats or malware that may have been introduced prior to isolation. Finally, securing the administrative interfaces that manage firewalls and routers ensures that attackers cannot simply re‑enable connections from within the isolated zone.
Conclusion: Building Resilience Through Preparedness
The CI Fortify guidance underscores a proactive mindset: rather than scrambling to disconnect vital systems amid an active breach, critical‑infrastructure owners should anticipate the need for isolation, design robust plans, and validate them through regular testing. By clearly identifying vital systems, mapping all connections, selecting appropriate isolation techniques, defining authority and triggers, and addressing the inherent risks of disconnection, organizations can significantly improve their ability to sustain essential services even when faced with sophisticated, persistent adversaries. In an era where state‑sponsored and criminal threats increasingly target the backbone of modern society, the principles outlined in CI Fortify offer a practical roadmap for resilience, continuity, and ultimately, the protection of public safety and national security.

