Back to Feed
PolicyJul 28, 2026

CISA shares advice on isolating vital systems during cyberattacks

US and Australian governments release guidance on isolating critical OT systems during cyberattacks.

Summary

CISA, ACSC, and the FBI have issued new guidance, 'CI Fortify,' advising critical infrastructure organizations on how to isolate vital operational technology (OT) systems during cyberattacks or major disruptions. The guidance emphasizes identifying essential systems, documenting connections, and planning for manual operations to maintain services while disconnected from less trusted networks. This comes amid increasing threats from nation-state actors and cybercriminals targeting critical infrastructure for espionage, disruption, and ransomware.

Full text

CISA shares advice on isolating vital systems during cyberattacks By Lawrence Abrams July 28, 2026 02:41 PM 0 The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. The guidance, titled "CI Fortify – Advice for isolating vital systems," was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners. It provides recommendations for disconnecting critical operational technology (OT) and associated systems from corporate, Internet-facing, and other less-trusted networks while continuing to provide essential services for an extended period. Operational technology includes the hardware and software used to monitor or control processes, such as water treatment equipment, electrical systems, manufacturing machinery, transportation systems, and telecommunications infrastructure. The agencies say state-sponsored threat actors routinely target critical infrastructure for espionage and to establish access that could later be used for disruptive or destructive attacks during a crisis or military conflict. "Cybercriminals continue to opportunistically target CI operators," reads the advisory. "The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes." In February 2024, CISA, the FBI, NSA, and other Five Eyes agencies warned that the Chinese Volt Typhoon hacking group had breached organizations in the communications, energy, transportation, and water sectors. The hackers remained undetected in at least one critical infrastructure network for five years, with U.S. officials warning that they were positioning themselves for potentially disruptive attacks during a future crisis or conflict. Chinese state-sponsored hackers tracked as Salt Typhoon have also breached government, telecommunications, transportation, lodging, and military networks worldwide since at least 2021. The group compromised major U.S. telecommunications providers, including AT&T, Verizon, and Lumen, gaining access to sensitive communications and U.S. law enforcement wiretap systems. The hackers also exploited known vulnerabilities in edge networking devices and used compromised equipment and trusted connections to pivot into other networks. Water infrastructure has also repeatedly been targeted. In October 2024, American Water, which provides water and wastewater services to more than 14 million people, deactivated some systems following a cyberattack. Around the same time, a Kansas water treatment facility switched to manual operations after its systems were compromised. Government agencies have also warned that pro-Russian hacktivists were seeking out unsecured OT systems used by water facilities and other critical infrastructure organizations to disrupt operations. The new CI Fortify guidance aims to help organizations prepare before such an incident occurs, rather than attempting to determine how vital systems can be disconnected while an attack is already underway. Isolating vital systems The agencies recommend critical infrastructure entities first identify the minimum systems and networks required to continue delivering a critical service. Organizations should then document every connection between those systems and corporate networks, remote-access services, cloud environments, Internet-facing infrastructure, vendors and contractors, and other critical infrastructure operators. They should also determine where those connections can be disabled or physically disconnected and account for the manual processes, communication failures, and loss of external resources or dependencies that isolation may trigger. Some of the terms and processes that the advisory recommends organizations become familiar with include: Vital systems: The minimum OT and supporting systems needed to provide a critical service, such as controlling water distribution, delivering electricity, or operating a telecommunications network. Isolation point: A predetermined location where connectivity between critical and non-critical networks or systems can be disconnected to contain an attack and prevent lateral movement into other vital systems. Physical isolation: Completely disconnecting vital systems so they do not share network or computing infrastructure with non-critical systems. The guidance describes this as the most effective form of protection. Graduated isolation: Gradually restricting access as the threat increases, such as first blocking remote workers and vendors, then disconnecting corporate networks, connected systems, and eventually all external connections. Administrative network controls: Various administrative controls to modify or manage VLANs, access-control lists, and routing. The guidance says these can be useful temporary protections but that physical isolation should be the ultimate goal. Data diode: Specialized equipment that allows data to flow in only one direction, reducing the risk that data or malicious traffic can travel in the opposite direction. Post-isolation: Monitor routing tables, network traffic, and intrusion detection systems to verify that isolation controls remain effective. Administrators should also secure the network management zones used to administer routers, firewalls, and other network infrastructure so they are isolated from attackers. While physical isolation provides the best protection, the cybersecurity agencies say that it may not be practical for organizations that depend on Internet-facing services, carrier networks, cloud services, or geographically distributed facilities. In those environments, operators are advised to strengthen OT network boundaries, use dedicated or encrypted communications links, remove unnecessary dependencies on corporate systems, and maintain the ability to rapidly rebuild systems. Isolation plans should also define who can authorize each step, the conditions that would trigger it, which systems must remain available, and how operations will continue without normal network connectivity. Organizations are urged to test the complete isolation of their vital systems regularly, rather than testing only individual systems, because partial tests may fail to identify shared infrastructure and other hidden dependencies that could cause problems when the isolation plan is initiated. The guidance also recommends keeping a secure offline or printed copy of the isolation plan so that it remains available in the event that access to corporate network or storage servers are disrupted. After systems have been isolated, operators should continue monitoring network traffic, routing information, and management systems to ensure that unauthorized or accidental connections have not restored access between critical and non-critical networks. However, the agencies warn that isolation also introduces risks, including systems falling behind on security updates, reduced monitoring, and increased use of removable media to transfer data between systems Organizations must therefore prepare not only to disconnect vital systems, but also to operate, monitor, update manually until they can eventually reconnect systems again. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: Is Your SSO Protected Against Modern Credential Attacks?Shadow AI agents are multiplying. Here's how to find and secure them.Hermes AI agent used

Indicators of Compromise

  • mitre_attack — T1078
  • mitre_attack — T1562
  • mitre_attack — T1049

Entities

OT (product)CISA (vendor)ACSC (vendor)FBI (vendor)Volt Typhoon (threat_actor)Salt Typhoon (threat_actor)