CI Fortify – Advice for isolating vital systems
CISA, the Australian Signals Directorate's ACSC, the FBI, and international partners released joint guidance advising critical infrastructure operators on how to isolate vital operational technology systems from other networks during cyber incidents or geopolitical crises.
Intelligence analysis by Llama
CISA and partners published practical steps for critical infrastructure organizations to identify, map, and disconnect essential operational technology systems so they can keep running in isolation for an extended period if normal connectivity is lost.
Imagine the computers that run a city's power plant are like the brain of a giant machine. CISA just told power-plant bosses: figure out which parts of that brain are super important, unplug them from the wider internet, and practice running the plant by itself for a long time, just in case bad guys or a big crisis try to break in from outside.
Analysis
A Coordinated International Playbook
The release of CI Fortify is the latest in a string of joint advisories that CISA has issued alongside the FBI and foreign cyber agencies, this time with the Australian Signals Directorate's Australian Cyber Security Centre taking a leading role. According to the publication, additional international partners contributed to the document, signaling that hardening critical infrastructure is now being treated as a shared Allied responsibility rather than a domestic compliance exercise. The multi-agency authorship matters because isolation decisions for things like power grids, water systems, and transportation networks often cross borders through supply chains, telemetry, and remote-vendor access, and a guidance that is consistent across jurisdictions is more usable for multinational operators.
What 'Isolation' Actually Means in Practice
The advisory focuses on operational technology and the IT systems that enable it, the hardware and software that run physical processes rather than office work. It calls on organizations to identify which systems are truly vital, map every connection those systems have to corporate, vendor, and internet-facing networks, and then put separation points in place so those connections can be cut cleanly. The end state is the ability to operate in isolation for an extended period, meaning the plant keeps running on its own, without remote support, cloud analytics, or external patching channels, for as long as a crisis lasts. That is a meaningfully higher bar than simply installing a firewall; it implies pre-positioned spare parts, local-only monitoring, paper or air-gapped backups, and rehearsed manual procedures.
Geopolitical Crisis as the Trigger
The language of the guidance frames isolation as a response to both cyber incidents and geopolitical crises, a pairing that reflects how threat actors and nation-state pressure increasingly target critical infrastructure as a lever of statecraft. Recent CISA publications listed alongside this one, including advisories on Russian intelligence services targeting commercial messaging apps and on hardening automatic tank gauge systems, show a consistent posture of preparing operators for adversary actions that fall short of full war but still threaten continuity of service. By publishing this advice, the U.S. and its partners are effectively pre-approving the concept of a 'graceful disconnect' for operators who might otherwise hesitate to sever network links during a fast-moving incident. The trade-off is real: isolation reduces attack surface but also cuts operators off from threat intelligence, vendor patches, and remote diagnostics, so the guidance implicitly asks executives to plan for that loss before they are forced into it.
Key points
- CISA, ASD's ACSC, the FBI, and international partners jointly authored the CI Fortify guidance.
- The document targets critical infrastructure operators and their operational technology environments.
- It outlines steps to identify vital systems, map their connections, and implement separation points.
- The goal is the ability to operate essential systems in isolation for an extended period during cyber or geopolitical crises.
- The guidance is part of a broader CISA push on critical infrastructure resilience, alongside recent advisories on Russian messaging-app targeting and tank-gauge hardening.


