Security.io Intelligence DeskFriday, 7 August 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Operational Technology and Resilience · Executive briefing

New CI Fortify guidance makes OT isolation a testable resilience requirement

International agencies now ask critical-infrastructure operators to identify vital systems, build physical isolation points and prove services can continue while disconnected.

ResilienceOperational TechnologyThird-Party Risk
Why it is in today’s brief

This brief is included because newly issued government guidance changes the assurance question from whether OT is segmented to whether vital services can operate in a verified state of isolation. It warrants executive attention over routine advisory releases because implementation crosses engineering, operations, safety, vendor contracts and recovery investment, exposing dependencies that conventional cyber testing often misses.

Read first

The guidance moves OT isolation from an emergency network action to a designed operating mode. Owners must map dependencies, pre-authorise graduated isolation and test complete service operation without corporate or external connectivity.

Act now

Identify the minimum systems required for each critical service.

Accountable owner

Chief operating officer with the CISO, OT engineering leader and business-continuity executive

Decision horizon

Assign design review this week; schedule a complete isolation exercise within the next planning cycle

AssessmentHigh confidence
Emerging riskSector-specific regulatory adoption, mandatory exercise expectations and evidence that operators cannot isolate without interrupting critical services.

What happened

On July 28, 2026, the Australian Cyber Security Centre published CI Fortify — Advice for isolating vital systems, developed with CISA, the FBI and international partners. The guide defines a six-step path: identify vital systems, identify critical customers, classify trust and criticality, map connections, build separation points, and create and test an isolation plan. Its stated objective is continuity of critical services while vital OT and enabling systems are disconnected from other networks.

The guide says physical isolation requires no shared active infrastructure between vital and non-vital systems. It identifies dependencies that can defeat isolation, including shared virtualisation, storage, backup, Active Directory, DNS, DHCP, public-key infrastructure and time synchronisation. No incident-specific indicators, affected products or threat-actor attribution were published. No specific incident or threat actor attribution underpins this guidance.

Why this matters now

Many organisations have segmentation diagrams but have not demonstrated that production, safety, communications and recovery functions remain viable after disconnection. CI Fortify asks operators to design isolation points in advance and account for the manual processes, lost communications and third-party dependencies that isolation creates. This is an operational resilience test, not a firewall review.

The guidance also makes shared enterprise services a leadership issue. An OT network may appear segmented while remaining dependent on corporate identity, virtualisation, storage, backups, name resolution, certificate services or network management. If those services are unavailable or compromised, isolation can stop the critical service it is intended to protect. Remediation may therefore require capital investment and revised operating procedures.

The decision for security leaders

Commission a joint operations, engineering and security review that identifies the minimum technology and personnel required to sustain each critical service. Document every connection to corporate IT, cloud platforms, remote vendors, carriers, peers and internet services, including the owner, protocol, business purpose, recovery objective and approved isolation method.

Define graduated stages that first remove lower-trust access and can progress to physical isolation. Each stage needs named authority, activation criteria, safe operating limits, communication methods and reconnection conditions. Test the complete service rather than individual devices, and retain an offline or printed plan that remains accessible during enterprise-wide disruption.

Evidence of closure

  • A signed inventory identifies each vital system and owner.
  • Architecture records show tested isolation points for every connection.
  • Exercise results prove service delivery meets approved targets while isolated.
  • Offline plans include current contacts, authority and reconnection criteria.

The Security.io assessment

The guidance is strategically important because it treats isolation as an enduring operating state rather than a brief containment manoeuvre. Physical separation is described as most effective, but the agencies acknowledge that distributed or internet-dependent services may require dedicated communications, strong encryption and hardened boundaries instead. Boards should expect documented exceptions where full isolation is infeasible.

No new campaign or imminent attack is asserted, and this should not be presented as an incident warning. The decision value comes from authoritative convergence on a measurable resilience capability. Our assessment changes if exercises show that shared infrastructure, remote support or manual-process limitations prevent essential services from meeting approved delivery targets while isolated.

Questions for the morning meeting

  • Which critical services can operate without corporate connectivity?
  • Who has authority to initiate each isolation stage?
  • Which shared services would fail first during isolation?
  • When was the full isolation plan last exercised?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network

Security.io Executive Roundtable: The 2027 CISO Agenda

CISO Roundtables & Executive events

View roundtables →
Invitation only
Sponsor's Notice · NoBrowser

Security.io CISO Dinner: The Secure Browser Decision

Virtual PC's & Secure Browsers in the Cloud

Request an invitation →
Black Hat week
Paid Placement · HackerFX

Security.io at Black Hat: Daily Intelligence Briefing

Catch the Daily News Where it Happens First

Follow the Black Hat desk →