What happened
On July 29, 2026, CISA and the Australian Signals Directorate’s Australian Cyber Security Centre released CI Fortify advice for isolating vital systems. The guidance tells critical-infrastructure operators to identify vital OT and enabling systems, classify networks by criticality and trust, map all connections, build separation points, create a graduated isolation plan and test it. Connections requiring documentation include corporate systems, vendor remote access, internet access, cloud environments, carrier networks and peer operators.
The target state is the ability to continue critical services while vital systems are isolated for an extended period. The guidance distinguishes physical separation from operational isolation and says vital OT should not share active switches, routers, compute or other infrastructure with non-OT networks where physical separation is required. Where complete isolation is infeasible, operators should harden boundaries, use dedicated communications where possible and apply strong encryption over untrusted links.
The guidance also calls for routing-table inspection, network-flow monitoring, reachability tests, protected management planes and offline hard copies of isolation plans. No campaign indicators, affected product versions, CVEs or actor infrastructure were published because this is resilience architecture guidance, not an incident notification. Attribution posture: The CI Fortify guidance attributes no incident or malicious activity to a named actor.
Why this matters now
Many OT response plans assume that defenders can disconnect a site or disable remote access, but shared identity, DNS, virtualisation, storage, backup, time synchronisation and carrier services may make that action operationally unsafe. CI Fortify moves the leadership question from whether an isolation procedure exists to whether essential service has been proven to function during isolation.
The guidance also exposes third-party concentration risk. Vendors, integrators, fuel or chemical suppliers, carriers and incident responders may be simultaneously constrained during a widespread crisis. Isolation planning must therefore include staffing, manual operations, emergency communications and recovery resources, not merely firewall rules.
The decision for security leaders
Commission a joint operational and technical assessment led by the COO and CISO. It should identify the smallest set of systems required to maintain each critical service, every external dependency and the physical or administrative control capable of breaking each connection.
Require a graduated exercise that progresses from disabling remote access to separating corporate and OT networks and, ultimately, completely isolating vital systems. Safety, environmental and service-quality criteria must be agreed before testing, with explicit abort conditions and restoration procedures.
Evidence of closure
- Approved diagrams identify all vital systems, dependencies and isolation points.
- Test results prove critical services continue during complete isolation.
- Routing and flow evidence confirms no unauthorised interconnection during exercises.
- Manual procedures document staffing, communications and external-support limitations.
The Security.io assessment
This guidance does not establish that a particular operator has been compromised, nor does it mandate a universal architecture. Its significance is the authoritative expectation that critical services should survive deliberate disconnection from lower-trust systems and remain observable during that state.
Organisations relying entirely on VLANs, access lists or remotely administered controls should examine whether an attacker with management-plane access could defeat isolation. Physical separation, out-of-band administration and independent support services provide stronger assurance, but each must be tested against operational and safety consequences.
Questions for the morning meeting
- Which essential services can operate without corporate or internet connectivity?
- Who has authority to progress through each isolation stage?
- Which shared services would fail first during complete isolation?
- When was the last full-scope isolation exercise completed?