US and Australia Urge Critical Infrastructure to Embrace 'CI Fortify' Isolation Strategies Against Cyberattacks
Amid escalating cyber threats from state-sponsored actors and cybercriminals, the U.S. and Australian governments have jointly released new guidance, 'CI Fortify β Advice for isolating vital systems.' This advisory urges critical infrastructure organizations to proactively prepare for the isolation of essential operational technology (OT) systems during major cyberattacks or disruptions, ensuring continued service delivery.
The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)**, the **Australian Signals Directorate's Australian Cyber Security Centre (ACSC)**, the **FBI**, and international partners have collaboratively developed new guidance to bolster the resilience of critical infrastructure. Titled "CI Fortify β Advice for isolating vital systems," the advisory provides actionable recommendations for disconnecting vital operational technology (OT) and associated systems from less-trusted networks.
Operational technology encompasses the hardware and software crucial for monitoring and controlling processes across sectors like water treatment, electrical grids, manufacturing, transportation, and telecommunications.
### The Growing Threat Landscape
Government agencies highlight that state-sponsored threat actors routinely target critical infrastructure. Their objectives range from espionage to establishing persistent access for potential disruptive or destructive attacks during crises or military conflicts.
"Cybercriminals continue to opportunistically target CI operators," the advisory states. "The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes."
In February 2024, **CISA**, the **FBI**, **NSA**, and other **Five Eyes** agencies issued a warning about the Chinese hacking group **Volt Typhoon**. This group had breached organizations in the communications, energy, transportation, and water sectors, remaining undetected in at least one critical infrastructure network for five years. Officials cautioned that **Volt Typhoon** was positioning itself for potential disruptive attacks in future conflicts.
Another Chinese state-sponsored group, **Salt Typhoon**, has also been active since at least 2021, compromising government, telecommunications, transportation, lodging, and military networks globally. This group reportedly compromised major U.S. telecommunications providers, including **AT&T**, **Verizon**, and **Lumen**, gaining access to sensitive communications and U.S. law enforcement wiretap systems.
Beyond state-sponsored threats, water infrastructure has also faced repeated attacks. In October 2024, **American Water** deactivated some systems following a cyberattack, while a Kansas water treatment facility switched to manual operations after a compromise. Furthermore, government agencies have warned about pro-Russian hacktivists actively targeting unsecured OT systems in water facilities and other critical infrastructure.
### Proactive Isolation Strategies
The **CI Fortify** guidance emphasizes proactive preparation, aiming to equip organizations *before* an attack unfolds. This prevents the chaotic scramble to disconnect vital systems mid-crisis.
Key recommendations include:
* **Identify Vital Systems:** Determine the absolute minimum systems and networks necessary to maintain critical service delivery.
* **Map Connections:** Document every connection between vital systems and corporate networks, remote access services, cloud environments, Internet-facing infrastructure, vendors, and other critical infrastructure operators.
* **Define Disconnection Points:** Identify where connections can be disabled or physically disconnected, accounting for manual processes, communication failures, and the loss of external dependencies.
### Key Terms and Processes for Isolation
The advisory introduces several crucial concepts for organizations to understand and implement:
* **Vital systems:** The essential OT and supporting systems required for critical service provision (e.g., water distribution, electricity, telecommunications).
* **Isolation point:** A predetermined location to disconnect connectivity between critical and non-critical networks, containing an attack and preventing lateral movement.
* **Physical isolation:** Completely disconnecting vital systems from non-critical networks, described as the most effective protection.
* **Graduated isolation:** A phased approach to restricting access as a threat escalates, moving from blocking remote workers to full external disconnection.
* **Administrative network controls:** Temporary protections like VLANs, ACLs, and routing modifications, with physical isolation as the ultimate goal.
* **Data diode:** Specialized equipment allowing data flow in only one direction, reducing bidirectional malicious traffic risk.
* **Post-isolation:** Continuous monitoring of routing tables, network traffic, and intrusion detection systems to verify isolation effectiveness. Secure network management zones are also critical.

While physical isolation offers the strongest defense, its practicality may vary for organizations reliant on Internet-facing services, carrier networks, cloud services, or geographically distributed facilities. In such scenarios, operators are advised to strengthen OT network boundaries, utilize dedicated or encrypted communication links, reduce corporate system dependencies, and maintain rapid system rebuilding capabilities.
Crucially, isolation plans must define authorization processes, trigger conditions, essential systems that must remain available, and how operations will continue without normal network connectivity. Regular testing of complete system isolation, rather than partial tests, is strongly recommended to uncover hidden dependencies.
The guidance also advises keeping secure offline or printed copies of isolation plans to ensure accessibility during network disruptions. Post-isolation, continuous monitoring is vital to prevent unauthorized re-connections.
However, isolation introduces its own set of challenges, including potential delays in security updates, reduced monitoring capabilities, and increased reliance on removable media for data transfer. Organizations must therefore not only prepare to disconnect but also to operate, monitor, and manually update systems until safe reconnection is possible.