CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure
CISA and allied agencies released joint guidance to help critical infrastructure operators isolate vital operational technology systems during cyber incidents or geopolitical crises.
The Cybersecurity and Infrastructure Security Agency (CISA), Australian Signals Directorate (ASD), United Kingdom’s National Cyber Security Centre (NCSC-UK), and Canadian Centre for Cyber Security (CCCS) published CI Fortify – Advice for Isolating Vital Systems. The guidance, led by ASD, assists operators of essential services in protecting critical infrastructure from escalating cyber threats and maintaining operations during incidents or crises. State-sponsored actors frequently target these systems for espionage or disruption, often amid geopolitical tensions.
Acting Executive Assistant Director for Cybersecurity Chris Butera emphasized the need for critical infrastructure resilience, stating that malicious actors seek persistent access to vital systems. The guidance is part of the CI Fortify Initiative and urges operators to implement robust isolation and recovery plans to sustain essential services during degraded conditions, whether through manual or alternative SCADA paths.
The guidance outlines essential steps for isolating critical systems, including identifying assets, mapping connections, and establishing separation points to ensure continued functioning during cyber incidents. Organizations must prepare to sustain operations independently for extended periods if supply chains or infrastructure are disrupted by significant nationwide cyber incidents.
The joint guidance provides practical recommendations for critical infrastructure operators to enhance defenses against state-sponsored threats. For additional details, visit CISA’s CI Fortify webpage at cisa.gov/ci-fortify. CISA serves as the nation’s cyber defense agency and national coordinator for critical infrastructure security.