US, Australia publish OT isolation guidance

CISA and Australia’s Cyber Security Centre released CI Fortify guidance advising how to isolate operational technology so critical services can continue during cyber incidents.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Australia’s Cyber Security Centre (ACSC) published joint guidance that explains how operators of critical infrastructure can isolate operational technology (OT) and supporting systems to keep services running during cyber incidents.
Titled CI Fortify – Advice for isolating vital systems, the document outlines technical and operational steps for OT owners, operators and cybersecurity teams to prepare for, respond to and recover from disruptions. It describes how systems can be segmented and run disconnected from other networks for extended periods while preserving core functions.
The guidance directs organizations to begin by identifying all systems and networks that support critical services and the people or communities that depend on them. Operators should classify systems by levels of criticality and trust, then group related assets into segments and zones to apply controls and reduce risk. The document also instructs operators to record and regularly update every connection between critical systems and other networks, including corporate IT, vendor remote access, untrusted networks, cloud environments and peer critical networks.
The guidance warns that operating systems in isolation will halt automated system-to-system communication and require manual processes. That change can affect upstream dependencies and peers such as other utilities or dispatch operators. The document advises organizations to identify and coordinate with impacted partners as part of their isolation planning.
To limit attacker movement and support containment and remediation, the guidance recommends creating clear separation and isolation points between critical and non-critical services and networks. The agencies write: “Planned physical separation of vital systems from all other networks and systems is a pre-requisite for physical isolation.” The document emphasises that physical separation is the foundation for running systems in an isolated state.
CI Fortify also sets out how to build and exercise a graduated isolation plan so operators can progressively cut pathways to sensitive systems while preserving continuity of key functions. It urges continuous monitoring of isolation controls during an event to check for unintended connections and to confirm manual processes work as intended.
The guidance lists operational and security trade-offs when systems operate in isolation, including reduced ability to apply patches, lower external visibility into system health and a higher risk of malware introduced via removable media. Organizations are advised to plan mitigations for these risks before entering an isolated state.
CISA and the ACSC point operators to CISA’s CI Fortify resources for further technical material and implementation advice. The document frames isolation as a capability to contain active incidents and rebuild compromised systems while maintaining critical services.







