CISA shares advice on isolating vital systems during cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
Intelligence analysis by Llama

CISA and the Australian Cyber Security Centre have released guidance on isolating vital systems during cyberattacks. The guidance aims to help organizations prepare before an incident occurs, rather than attempting to determine how vital systems can be disconnected while an attack is already underway.
Imagine you have a water treatment plant that needs to keep running even if there's a cyberattack. The government is telling these plants to prepare by disconnecting from the internet and other systems that could be hacked. This way, even if the plant is attacked, it can still keep running and providing clean water.
Analysis
A Growing Threat to Critical Infrastructure
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions. This guidance, titled 'CI Fortify – Advice for isolating vital systems,' was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners.
The agencies say state-sponsored threat actors routinely target critical infrastructure for espionage and to establish access that could later be used for disruptive or destructive attacks during a crisis or military conflict. 'Cybercriminals continue to opportunistically target CI operators,' reads the advisory. 'The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes.'
In February 2024, CISA, the FBI, NSA, and other Five Eyes agencies warned that the Chinese Volt Typhoon hacking group had breached organizations in the communications, energy, transportation, and water sectors. The hackers remained undetected in at least one critical infrastructure network for five years, with U.S. officials warning that they were positioning themselves for potentially disruptive attacks during a future crisis or conflict.
Isolating Vital Systems
The agencies recommend critical infrastructure entities first identify the minimum systems and networks required to continue delivering a critical service. Organizations should then document every connection between those systems and corporate networks, remote-access services, cloud environments, Internet-facing infrastructure, vendors and contractors, and other critical infrastructure operators.
They should also determine where those connections can be disabled or physically disconnected and account for the manual processes, communication failures, and loss of external resources or dependencies that isolation may trigger.
Key Concepts
The guidance describes several key concepts that organizations should become familiar with, including vital systems, isolation points, physical isolation, graduated isolation, administrative network controls, and data diodes.
Vital systems refer to the minimum OT and supporting systems needed to provide a critical service, such as controlling water distribution, delivering electricity, or operating a telecommunications network.
Isolation points are predetermined locations where connectivity between critical and non-critical networks or systems can be disconnected to contain an attack and prevent lateral movement into other vital systems.
Physical isolation completely disconnects vital systems so they do not share network or computing infrastructure with non-critical systems.
Graduated isolation involves gradually restricting access as the threat increases, such as first blocking remote workers and vendors, then disconnecting corporate networks, connected systems, and eventually all external connections.
Administrative network controls include various administrative controls to modify or manage VLANs, access-control lists, and routing.
Data diodes are specialized equipment that allow data to flow in only one direction, reducing the risk that data or malicious traffic can travel in the opposite direction.
Conclusion
While physical isolation provides the best protection, the cybersecurity agencies say that it may not be practical for organizations to implement. Instead, they recommend using graduated isolation and administrative network controls to temporarily protect vital systems.
Organizations should also secure the network management zones used to administer routers, firewalls, and other network infrastructure so they are isolated from attackers.
By following these guidelines, organizations can better prepare for and respond to cyberattacks on their vital systems.
Key points
- CISA and the Australian Cyber Security Centre have released guidance on isolating vital systems during cyberattacks.
- The guidance aims to help organizations prepare before an incident occurs, rather than attempting to determine how vital systems can be disconnected while an attack is already underway.
- State-sponsored threat actors routinely target critical infrastructure for espionage and to establish access that could later be used for disruptive or destructive attacks during a crisis or military conflict.
- Organizations should identify the minimum systems and networks required to continue delivering a critical service and document every connection between those systems and corporate networks.
- Physical isolation provides the best protection, but it may not be practical for organizations to implement.
If organizations follow the guidance and prepare to isolate their vital systems, they can reduce the risk of a cyberattack causing significant disruptions. This can lead to increased confidence in the resilience of critical infrastructure and improved public trust.
If organizations fail to prepare and isolate their vital systems, they may be left vulnerable to cyberattacks, which could have significant consequences, including disruptions to critical services and potential harm to the public.



