CISA Releases Joint Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure

Helps OT Owners and Operators Protect Vital Systems and Provide Continuity of Critical Services During a Cybersecurity Incident, Crisis or Service Disruption

The Cybersecurity and Infrastructure Security Agency, Australian Signals Directorate (ASD), United Kingdom’s National Cyber Security Centre (NCSC-UK), and Canadian Centre for Cyber Security (CCCS) have published CI Fortify – Advice for Isolating Vital Systems. This joint guidance, led by ASD, helps critical infrastructure operators protect essential services from escalating cyber threats and ensure continuity of operations during cyber incidents or geopolitical crises.

State-sponsored cyber actors target critical infrastructure for several nefarious reasons such as espionage or service disruption, often linked to broader geopolitical conflicts. During crises or conflicts, operators of critical infrastructure and network defenders may isolate essential operational technology (OT) systems as an emergency measure to prevent adversaries from executing cyberattacks, to contain ongoing threats, and to facilitate the restoration of compromised systems.

“America’s critical infrastructure is frequently targeted by malicious state-sponsored cyber threat actors whose aim is persistent access to vital systems and disrupt essential services such as telecommunications, water, energy, and transportation. As part of our CI Fortify Initiative, CISA, with our partners, provides this timely, collaborative resource that helps critical infrastructure ensure resilience during a crisis,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA urges OT owners and operators to maintain robust isolation and recovery plans so that essential services can continue under degraded conditions, enabled through either manual or alternative SCADA paths. Through proactive planning and practice, we can strengthen critical infrastructure defenses against state-sponsored threat actors.”

In the event of a significant nationwide cyber incident disrupting supply chains or critical infrastructure, organizations need to be ready to sustain their operations independently for long periods. Essential steps in isolating important systems involve identifying assets, mapping their connections, and establishing separation points to ensure continued functioning during such incidents. The guidance covers:

  • Identifying and mapping vital systems and connections
  • Building effective separation points
  • Graduated isolation planning and regular testing
  • Real-world examples of resilience during ransomware attacks

The original announcement can be found here.

The Government Technology & Services Coalition's Homeland Security Today (HSToday) is the premier news and information resource for the homeland security community, dedicated to elevating the discussions and insights that can support a safe and secure nation. A non-profit magazine and media platform, HSToday provides readers with the whole story, placing facts and comments in context to inform debate and drive realistic solutions to some of the nation’s most vexing security challenges.

Related Articles

Latest Articles