The CISA, in coordination with international partners, has released new CI Fortify guidance to help critical infrastructure organizations isolate vital operational technology (OT) and supporting systems during cyberattacks or periods of heightened cyber threat.
The guidance is intended to help operators maintain essential services while containing cyber incidents and recovering compromised systems.
The guidance recommends identifying critical operational systems and customers, establishing predefined network isolation points, preparing to operate disconnected from third-party networks for weeks to months, and regularly testing recovery plans.
The CISA said organizations should assume internet; telecommunications, vendors and other external dependencies may become unavailable during a major cyber incident or geopolitical crisis.
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“This guidance is more than a checklist. The Five Eyes are telling critical infrastructure operators to prepare for the possibility that they may have to intentionally isolate from the Internet, vendor connectivity, telecommunications providers, and other external dependencies in order to continue delivering essential services during a major cyber incident or geopolitical crisis.
“Some FVEY partners are recommending planning for up to three months of isolated operations. That’s less a prediction of duration than a recognition that operators must be prepared to sustain essential services for as long as necessary.
“Perhaps the most significant shift is the planning assumption. For years, cyber defense has focused primarily on protecting the internet edges. This guidance recognizes that the operational edge is much broader. Critical infrastructure operators should increasingly view the communications fabric connecting remote sites, substations, treatment facilities, vendors, and control centers, including private telecommunications and point-to-point links, not simply as infrastructure they depend upon, but as part of the attack surface itself.
“Resilience should be engineered before a crisis. Organizations need to identify their critical systems, understand hidden dependencies, establish and exercise isolation procedures, and ensure they can continue operating safely when connectivity becomes a liability instead of an asset.”
Seemant Sehgal, Founder & CEO, BreachLock:
“What stood out to me is the instruction to treat carrier-provided services as untrusted and potentially hostile. Most OT operators have longstanding relationships with their telecoms vendors and have built operational trust into those relationships over years. That trust does not translate to technical assurance, and in a geopolitical crisis or major incident, the carrier network itself may be the vector, the casualty, or both.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This really feeds into something I’ve been talking about for quite a while. We’re entering the age of agentic attacks and agentic AI, where vulnerabilities are being discovered and weaponized faster than organizations can respond. In many cases, there won’t be a patch immediately. Sometimes there won’t be a patch at all, especially when we’re talking about operational technology that’s decades old and can’t realistically be upgraded.
“That leaves every CISO with one unavoidable question. What are your compensating controls?
“That’s why it’s encouraging to see CISA putting more emphasis on isolation and compensating controls. It shows a shift in thinking that’s been needed for years. We have to move beyond the idea that every security problem can be solved with EDR, firewalls, and patch management alone. Organizations need layered defenses that assume vulnerabilities will exist, patches will be delayed, and some systems simply cannot be fixed. The future of cybersecurity isn’t just about preventing compromise. It’s about building resilient environments that continue to protect critical systems even when traditional approaches no longer work.”
Dahvid Schloss, Chief Operating Officer, Suzu Labs:
“Most everything stated in the guidance has been common language and advice from security professionals for years, if not decades. That being said, it is quite refreshing that government agencies are finally stating the obvious and, in some places, going above and beyond in ways that most would loosely recommend but not push for enforcement. There are two pieces within the guidance that I appreciated more than others. The first was explicitly calling out MPLS(Multiprotocol Label Switching) as not a security boundary. This is a common argument between IT and Security folks when talking Layer 2/3 security, but in the same way VLANs aren’t treated as a security boundary, neither can MPLS, so kudos to the ASD and others for calling that out in writing.
“The other great piece here is the recommendation to separate encryption from the OT devices themselves, and instead recommend prioritizing and implementing a dedicated crypto device to handle traffic. This is very much needed, especially with how quickly technology is advancing and how it may accelerate the rate at which modern encryption mechanisms become obsolete. OT devices average a 20-year lifecycle; the ability to upgrade and protect the network without a full tech refresh, which comes with its own set of availability risks, is key to future-proofing the security of the network. They also state that crypto should terminate on the OT-side router and not somewhere more convenient, which is a common trend I’ve seen when testing.
“Every time I’ve brought this up as a finding in the past, it was always a “yeah, we know, but it’s easier to manage this way”. If anything, changing the way CI implements crypto within the network would improve security 10-fold in my opinion. Overall, this release is old guidance many security professionals have been screaming from the rafters for decades, but hey, hopefully this will create the change we have been asking for.”
Matt Wyckhouse. Founder & CEO, Finite State:
“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.
“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”
Organizations need to take what the CISA has done and not only build their own playbooks from it, but practise it and use it if required. That way it will reduce the level of pwnage if it comes to that.
FCC blocks new foreign-made robots over security risks
Posted in Commentary with tags FCC on July 29, 2026 by itnerdThe FCC has added foreign-produced advanced robotic devices to its Covered List, preventing new models from receiving the equipment authorization required for importation, marketing and sale in the U.S. The action follows national security determinations that the products pose unacceptable supply chain and cybersecurity risks.
According to the FCC, network-connected robots could be exploited to manipulate physical operations, collect sensitive data, conduct surveillance or be remotely commandeered, while connected power inverters could create vulnerabilities affecting critical infrastructure.
The restrictions apply only to new device models and do not affect previously authorized products already in the U.S. market.
Matt Wyckhouse. Founder & CEO, Finite State:
“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.
“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“Taken together with recent guidance from the Five Eyes and other federal agencies, this decision reflects a growing emphasis on the cybersecurity of cyber-physical systems and the resilience of the critical infrastructure that depends on them. We should pay close attention to these signals. They are likely indicative of how governments assess the evolving threat environment and where they see strategic risk increasing.
“Industrial robots are increasingly more than just machines, they are connected computers capable of sensing, deciding, and acting in the physical world. Many of today’s advanced robots have significant operational dependencies on cloud connectivity, AI services, remote management, identity systems, and vendor-operated infrastructure. The security question is not simply whether someone can hack the robot; it’s also what happens if the cloud, the vendor, or the communications path the robot depends on is compromised or unavailable.”
Seemant Sehgal, Founder & CEO, BreachLock:
“The FCC drew a line at the import stage, which is the wrong place to draw it if the goal is reducing risk. There are already authorized devices operating in U.S. networks that carry the same trust relationships, the same firmware update dependencies, and the same remote access capabilities as anything on the new restricted list. Blocking future imports without a plan for what is already inside the perimeter is a procurement policy dressed up as a security measure.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I think these technology-specific bans feel very arbitrary. The security concerns people raise about robotics are the same concerns we’ve had with automobiles, drones, industrial control systems, smartphones, and just about every other connected technology. If it has software, it will have vulnerabilities. That’s simply the reality of modern computing.
“If the standard is that a technology could someday be exploited by a foreign adversary, then almost every technology would qualify. That’s why these policies can feel less like a coherent cybersecurity strategy and more like market protectionism wrapped in the language of national security. The focus should be on building resilient systems, validating software and hardware, and reducing risk regardless of who manufactures the technology, instead of singling out one category while ignoring the fact that the same security challenges exist across the entire technology ecosystem.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“Nation-state attackers have spent a decade moving up the supply chain. Software exploits get patched. Firmware backdoors get caught in audits. Hardware is where verification breaks down, because you cannot audit a fabrication line you do not control.
“That is the security argument behind the FCC adding foreign-produced robots and power inverters to its Covered List this week. Network-connected humanoid robots carry cameras, LiDAR, and persistent connectivity. Inverters sit between solar panels, batteries, data center equipment, and the grid. Both create attack surface that defenders can monitor but cannot fully inspect when the hardware ships from a geopolitical competitor.
“I’ve done enough embedded-device assessments to know that firmware review catches what you can reach, and on hardware imported from an adversary nation, there are layers you simply cannot reach. Software backdoors exist in every copy, find one and you’ve found them all. Hardware is different.
“One unit gets pulled off the line or intercepted in shipping, altered with a modified chip, and put back. Intelligence agencies, including ours, have been doing this for years. You can tear down a sample unit, certify it clean, and have no way of knowing the next unit off the same line hasn’t been touched.
“The FCC has banned three product categories in seven months using the same Secure Networks Act written in 2019 for Huawei and ZTE. Drones in December, routers in March, now robots and power inverters. A White House interagency body issues a National Security Determination, the FCC updates its list, and the ban takes effect without new legislation.
“Watch the Conditional Approval list over the next 90 days. Fifteen non-Chinese UAS vendors cleared approval within months of the drones ban. Netgear and eero passed the router review within a month. Zero Chinese manufacturers have received approval in either category, and that ratio will hold for robots and inverters.”
For the record, China has reacted negatively to this and it sounds like they’re going to retaliate. Therefore it is unlikely that this is over.
Leave a comment »