The CISA, in coordination with international partners, has released new CI Fortify guidance to help critical infrastructure organizations isolate vital operational technology (OT) and supporting systems during cyberattacks or periods of heightened cyber threat.
The guidance is intended to help operators maintain essential services while containing cyber incidents and recovering compromised systems.
The guidance recommends identifying critical operational systems and customers, establishing predefined network isolation points, preparing to operate disconnected from third-party networks for weeks to months, and regularly testing recovery plans.
The CISA said organizations should assume internet; telecommunications, vendors and other external dependencies may become unavailable during a major cyber incident or geopolitical crisis.
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“This guidance is more than a checklist. The Five Eyes are telling critical infrastructure operators to prepare for the possibility that they may have to intentionally isolate from the Internet, vendor connectivity, telecommunications providers, and other external dependencies in order to continue delivering essential services during a major cyber incident or geopolitical crisis.
“Some FVEY partners are recommending planning for up to three months of isolated operations. That’s less a prediction of duration than a recognition that operators must be prepared to sustain essential services for as long as necessary.
“Perhaps the most significant shift is the planning assumption. For years, cyber defense has focused primarily on protecting the internet edges. This guidance recognizes that the operational edge is much broader. Critical infrastructure operators should increasingly view the communications fabric connecting remote sites, substations, treatment facilities, vendors, and control centers, including private telecommunications and point-to-point links, not simply as infrastructure they depend upon, but as part of the attack surface itself.
“Resilience should be engineered before a crisis. Organizations need to identify their critical systems, understand hidden dependencies, establish and exercise isolation procedures, and ensure they can continue operating safely when connectivity becomes a liability instead of an asset.”
Seemant Sehgal, Founder & CEO, BreachLock:
“What stood out to me is the instruction to treat carrier-provided services as untrusted and potentially hostile. Most OT operators have longstanding relationships with their telecoms vendors and have built operational trust into those relationships over years. That trust does not translate to technical assurance, and in a geopolitical crisis or major incident, the carrier network itself may be the vector, the casualty, or both.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This really feeds into something I’ve been talking about for quite a while. We’re entering the age of agentic attacks and agentic AI, where vulnerabilities are being discovered and weaponized faster than organizations can respond. In many cases, there won’t be a patch immediately. Sometimes there won’t be a patch at all, especially when we’re talking about operational technology that’s decades old and can’t realistically be upgraded.
“That leaves every CISO with one unavoidable question. What are your compensating controls?
“That’s why it’s encouraging to see CISA putting more emphasis on isolation and compensating controls. It shows a shift in thinking that’s been needed for years. We have to move beyond the idea that every security problem can be solved with EDR, firewalls, and patch management alone. Organizations need layered defenses that assume vulnerabilities will exist, patches will be delayed, and some systems simply cannot be fixed. The future of cybersecurity isn’t just about preventing compromise. It’s about building resilient environments that continue to protect critical systems even when traditional approaches no longer work.”
Dahvid Schloss, Chief Operating Officer, Suzu Labs:
“Most everything stated in the guidance has been common language and advice from security professionals for years, if not decades. That being said, it is quite refreshing that government agencies are finally stating the obvious and, in some places, going above and beyond in ways that most would loosely recommend but not push for enforcement. There are two pieces within the guidance that I appreciated more than others. The first was explicitly calling out MPLS(Multiprotocol Label Switching) as not a security boundary. This is a common argument between IT and Security folks when talking Layer 2/3 security, but in the same way VLANs aren’t treated as a security boundary, neither can MPLS, so kudos to the ASD and others for calling that out in writing.
“The other great piece here is the recommendation to separate encryption from the OT devices themselves, and instead recommend prioritizing and implementing a dedicated crypto device to handle traffic. This is very much needed, especially with how quickly technology is advancing and how it may accelerate the rate at which modern encryption mechanisms become obsolete. OT devices average a 20-year lifecycle; the ability to upgrade and protect the network without a full tech refresh, which comes with its own set of availability risks, is key to future-proofing the security of the network. They also state that crypto should terminate on the OT-side router and not somewhere more convenient, which is a common trend I’ve seen when testing.
“Every time I’ve brought this up as a finding in the past, it was always a “yeah, we know, but it’s easier to manage this way”. If anything, changing the way CI implements crypto within the network would improve security 10-fold in my opinion. Overall, this release is old guidance many security professionals have been screaming from the rafters for decades, but hey, hopefully this will create the change we have been asking for.”
Matt Wyckhouse. Founder & CEO, Finite State:
“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.
“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”
Organizations need to take what the CISA has done and not only build their own playbooks from it, but practise it and use it if required. That way it will reduce the level of pwnage if it comes to that.
Related
This entry was posted on July 29, 2026 at 2:50 pm and is filed under Commentary with tags CISA. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
The CISA issues guidance to isolate critical systems during cyberattacks
The CISA, in coordination with international partners, has released new CI Fortify guidance to help critical infrastructure organizations isolate vital operational technology (OT) and supporting systems during cyberattacks or periods of heightened cyber threat.
The guidance is intended to help operators maintain essential services while containing cyber incidents and recovering compromised systems.
The guidance recommends identifying critical operational systems and customers, establishing predefined network isolation points, preparing to operate disconnected from third-party networks for weeks to months, and regularly testing recovery plans.
The CISA said organizations should assume internet; telecommunications, vendors and other external dependencies may become unavailable during a major cyber incident or geopolitical crisis.
Donald McFarlane, Advisory Board Member, Xcape, Inc.
“This guidance is more than a checklist. The Five Eyes are telling critical infrastructure operators to prepare for the possibility that they may have to intentionally isolate from the Internet, vendor connectivity, telecommunications providers, and other external dependencies in order to continue delivering essential services during a major cyber incident or geopolitical crisis.
“Some FVEY partners are recommending planning for up to three months of isolated operations. That’s less a prediction of duration than a recognition that operators must be prepared to sustain essential services for as long as necessary.
“Perhaps the most significant shift is the planning assumption. For years, cyber defense has focused primarily on protecting the internet edges. This guidance recognizes that the operational edge is much broader. Critical infrastructure operators should increasingly view the communications fabric connecting remote sites, substations, treatment facilities, vendors, and control centers, including private telecommunications and point-to-point links, not simply as infrastructure they depend upon, but as part of the attack surface itself.
“Resilience should be engineered before a crisis. Organizations need to identify their critical systems, understand hidden dependencies, establish and exercise isolation procedures, and ensure they can continue operating safely when connectivity becomes a liability instead of an asset.”
Seemant Sehgal, Founder & CEO, BreachLock:
“What stood out to me is the instruction to treat carrier-provided services as untrusted and potentially hostile. Most OT operators have longstanding relationships with their telecoms vendors and have built operational trust into those relationships over years. That trust does not translate to technical assurance, and in a geopolitical crisis or major incident, the carrier network itself may be the vector, the casualty, or both.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This really feeds into something I’ve been talking about for quite a while. We’re entering the age of agentic attacks and agentic AI, where vulnerabilities are being discovered and weaponized faster than organizations can respond. In many cases, there won’t be a patch immediately. Sometimes there won’t be a patch at all, especially when we’re talking about operational technology that’s decades old and can’t realistically be upgraded.
“That leaves every CISO with one unavoidable question. What are your compensating controls?
“That’s why it’s encouraging to see CISA putting more emphasis on isolation and compensating controls. It shows a shift in thinking that’s been needed for years. We have to move beyond the idea that every security problem can be solved with EDR, firewalls, and patch management alone. Organizations need layered defenses that assume vulnerabilities will exist, patches will be delayed, and some systems simply cannot be fixed. The future of cybersecurity isn’t just about preventing compromise. It’s about building resilient environments that continue to protect critical systems even when traditional approaches no longer work.”
Dahvid Schloss, Chief Operating Officer, Suzu Labs:
“Most everything stated in the guidance has been common language and advice from security professionals for years, if not decades. That being said, it is quite refreshing that government agencies are finally stating the obvious and, in some places, going above and beyond in ways that most would loosely recommend but not push for enforcement. There are two pieces within the guidance that I appreciated more than others. The first was explicitly calling out MPLS(Multiprotocol Label Switching) as not a security boundary. This is a common argument between IT and Security folks when talking Layer 2/3 security, but in the same way VLANs aren’t treated as a security boundary, neither can MPLS, so kudos to the ASD and others for calling that out in writing.
“The other great piece here is the recommendation to separate encryption from the OT devices themselves, and instead recommend prioritizing and implementing a dedicated crypto device to handle traffic. This is very much needed, especially with how quickly technology is advancing and how it may accelerate the rate at which modern encryption mechanisms become obsolete. OT devices average a 20-year lifecycle; the ability to upgrade and protect the network without a full tech refresh, which comes with its own set of availability risks, is key to future-proofing the security of the network. They also state that crypto should terminate on the OT-side router and not somewhere more convenient, which is a common trend I’ve seen when testing.
“Every time I’ve brought this up as a finding in the past, it was always a “yeah, we know, but it’s easier to manage this way”. If anything, changing the way CI implements crypto within the network would improve security 10-fold in my opinion. Overall, this release is old guidance many security professionals have been screaming from the rafters for decades, but hey, hopefully this will create the change we have been asking for.”
Matt Wyckhouse. Founder & CEO, Finite State:
“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.
“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”
Organizations need to take what the CISA has done and not only build their own playbooks from it, but practise it and use it if required. That way it will reduce the level of pwnage if it comes to that.
Share this:
Like this:
Related
This entry was posted on July 29, 2026 at 2:50 pm and is filed under Commentary with tags CISA. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.