Security.io Intelligence DeskFriday, 7 August 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Operational Technology and Resilience · Executive briefing

New OT guidance makes extended isolation a resilience requirement

US and Australian authorities now ask critical-infrastructure operators to engineer and regularly test the ability to isolate vital OT while continuing essential services.

ResilienceOperational TechnologyThird-Party Risk
Why it is in today’s brief

The July 29 CI Fortify publication is new authoritative guidance rather than a response to a newly disclosed breach. It warrants inclusion because it changes the target architecture and exercise standard for critical-infrastructure resilience: operators should be able to isolate vital OT for an extended period, including from shared corporate, cloud, vendor and carrier dependencies, without causing unacceptable service failure.

Read first

Critical-infrastructure leaders should treat OT isolation as an engineered operating state, not an improvised incident action.

Act now

Identify vital OT and enabling systems supporting critical services.

Accountable owner

COO and CISO with OT engineering, site operations, safety and business-continuity leadership

Decision horizon

Assign capability assessment now; define isolation gaps and exercise plan this quarter

AssessmentHigh confidence
Emerging riskSector-specific regulatory adoption, mandatory exercise expectations, regulator-defined assurance evidence and implementation guidance for safety-critical or geographically distributed operations.

What happened

On July 29, 2026, CISA and the Australian Signals Directorate’s Australian Cyber Security Centre released CI Fortify advice for isolating vital systems. The guidance tells critical-infrastructure operators to identify vital OT and enabling systems, classify networks by criticality and trust, map all connections, build separation points, create a graduated isolation plan and test it. Connections requiring documentation include corporate systems, vendor remote access, internet access, cloud environments, carrier networks and peer operators.

The target state is the ability to continue critical services while vital systems are isolated for an extended period. The guidance distinguishes physical separation from operational isolation and says vital OT should not share active switches, routers, compute or other infrastructure with non-OT networks where physical separation is required. Where complete isolation is infeasible, operators should harden boundaries, use dedicated communications where possible and apply strong encryption over untrusted links.

The guidance also calls for routing-table inspection, network-flow monitoring, reachability tests, protected management planes and offline hard copies of isolation plans. No campaign indicators, affected product versions, CVEs or actor infrastructure were published because this is resilience architecture guidance, not an incident notification. Attribution posture: The CI Fortify guidance attributes no incident or malicious activity to a named actor.

Why this matters now

Many OT response plans assume that defenders can disconnect a site or disable remote access, but shared identity, DNS, virtualisation, storage, backup, time synchronisation and carrier services may make that action operationally unsafe. CI Fortify moves the leadership question from whether an isolation procedure exists to whether essential service has been proven to function during isolation.

The guidance also exposes third-party concentration risk. Vendors, integrators, fuel or chemical suppliers, carriers and incident responders may be simultaneously constrained during a widespread crisis. Isolation planning must therefore include staffing, manual operations, emergency communications and recovery resources, not merely firewall rules.

The decision for security leaders

Commission a joint operational and technical assessment led by the COO and CISO. It should identify the smallest set of systems required to maintain each critical service, every external dependency and the physical or administrative control capable of breaking each connection.

Require a graduated exercise that progresses from disabling remote access to separating corporate and OT networks and, ultimately, completely isolating vital systems. Safety, environmental and service-quality criteria must be agreed before testing, with explicit abort conditions and restoration procedures.

Evidence of closure

  • Approved diagrams identify all vital systems, dependencies and isolation points.
  • Test results prove critical services continue during complete isolation.
  • Routing and flow evidence confirms no unauthorised interconnection during exercises.
  • Manual procedures document staffing, communications and external-support limitations.

The Security.io assessment

This guidance does not establish that a particular operator has been compromised, nor does it mandate a universal architecture. Its significance is the authoritative expectation that critical services should survive deliberate disconnection from lower-trust systems and remain observable during that state.

Organisations relying entirely on VLANs, access lists or remotely administered controls should examine whether an attacker with management-plane access could defeat isolation. Physical separation, out-of-band administration and independent support services provide stronger assurance, but each must be tested against operational and safety consequences.

Questions for the morning meeting

  • Which essential services can operate without corporate or internet connectivity?
  • Who has authority to progress through each isolation stage?
  • Which shared services would fail first during complete isolation?
  • When was the last full-scope isolation exercise completed?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network

Security.io Executive Roundtable: The 2027 CISO Agenda

CISO Roundtables & Executive events

View roundtables →
Invitation only
Sponsor's Notice · NoBrowser

Security.io CISO Dinner: The Secure Browser Decision

Virtual PC's & Secure Browsers in the Cloud

Request an invitation →
Black Hat week
Paid Placement · HackerFX

Security.io at Black Hat: Daily Intelligence Briefing

Catch the Daily News Where it Happens First

Follow the Black Hat desk →