What happened
On July 28, 2026, the Australian Cyber Security Centre published CI Fortify — Advice for isolating vital systems, developed with CISA, the FBI and international partners. The guide defines a six-step path: identify vital systems, identify critical customers, classify trust and criticality, map connections, build separation points, and create and test an isolation plan. Its stated objective is continuity of critical services while vital OT and enabling systems are disconnected from other networks.
The guide says physical isolation requires no shared active infrastructure between vital and non-vital systems. It identifies dependencies that can defeat isolation, including shared virtualisation, storage, backup, Active Directory, DNS, DHCP, public-key infrastructure and time synchronisation. No incident-specific indicators, affected products or threat-actor attribution were published. No specific incident or threat actor attribution underpins this guidance.
Why this matters now
Many organisations have segmentation diagrams but have not demonstrated that production, safety, communications and recovery functions remain viable after disconnection. CI Fortify asks operators to design isolation points in advance and account for the manual processes, lost communications and third-party dependencies that isolation creates. This is an operational resilience test, not a firewall review.
The guidance also makes shared enterprise services a leadership issue. An OT network may appear segmented while remaining dependent on corporate identity, virtualisation, storage, backups, name resolution, certificate services or network management. If those services are unavailable or compromised, isolation can stop the critical service it is intended to protect. Remediation may therefore require capital investment and revised operating procedures.
The decision for security leaders
Commission a joint operations, engineering and security review that identifies the minimum technology and personnel required to sustain each critical service. Document every connection to corporate IT, cloud platforms, remote vendors, carriers, peers and internet services, including the owner, protocol, business purpose, recovery objective and approved isolation method.
Define graduated stages that first remove lower-trust access and can progress to physical isolation. Each stage needs named authority, activation criteria, safe operating limits, communication methods and reconnection conditions. Test the complete service rather than individual devices, and retain an offline or printed plan that remains accessible during enterprise-wide disruption.
Evidence of closure
- A signed inventory identifies each vital system and owner.
- Architecture records show tested isolation points for every connection.
- Exercise results prove service delivery meets approved targets while isolated.
- Offline plans include current contacts, authority and reconnection criteria.
The Security.io assessment
The guidance is strategically important because it treats isolation as an enduring operating state rather than a brief containment manoeuvre. Physical separation is described as most effective, but the agencies acknowledge that distributed or internet-dependent services may require dedicated communications, strong encryption and hardened boundaries instead. Boards should expect documented exceptions where full isolation is infeasible.
No new campaign or imminent attack is asserted, and this should not be presented as an incident warning. The decision value comes from authoritative convergence on a measurable resilience capability. Our assessment changes if exercises show that shared infrastructure, remote support or manual-process limitations prevent essential services from meeting approved delivery targets while isolated.
Questions for the morning meeting
- Which critical services can operate without corporate connectivity?
- Who has authority to initiate each isolation stage?
- Which shared services would fail first during isolation?
- When was the full isolation plan last exercised?