CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks

The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), the Federal Bureau of Investigation, and international partners, has released new joint guidance titled “CI Fortify Advice for Isolating Vital Systems.”

Published on July 28, 2026, the advisory provides critical infrastructure (CI) operators with actionable steps to isolate essential operational technology (OT) and enabling systems during cyberattacks or geopolitical crises.

As nation-state actors and ransomware groups increasingly target OT environments, the ability to rapidly disconnect vital systems from compromised networks has become a cornerstone of operational resilience.

CISA Urges Critical Infrastructure Operators

The guidance addresses a persistent gap in CI cybersecurity planning: many organizations lack pre-established isolation procedures, leaving them vulnerable to prolonged outages when incidents force emergency segmentation decisions under pressure.

The joint advisory emphasizes that isolation is not just a reactive measure but a survivability strategy. Organizations following these recommendations can maintain essential service delivery even while cut off from broader IT networks for extended periods.

CISA notes that a structured approach built around three core pillars. Organizations are advised to identify critical systems by cataloging OT assets essential to maintaining core operational functions, with particular emphasis on those tied to safety and service continuity.

They are also encouraged to map system connections by documenting dependencies between OT, IT, and third-party networks in order to understand potential attack pathways and cascading failure risks.

In addition, the guidance calls for implementing separation points by establishing both physical and logical segmentation boundaries that enable rapid and controlled disconnection without disrupting safe operations.

The advisory further stresses the importance of testing isolation procedures through regular tabletop exercises and live drills. This ensures that operators can execute segmentation plans confidently during real incidents rather than improvising under pressure.

This guidance complements existing frameworks such as the MITRE ATT&CK for ICS matrix and reinforces defense-in-depth principles long advocated by CISA.

It is particularly relevant to sectors within the 16 critical infrastructure categories, including energy, water, transportation, and manufacturing, where compromise of OT systems can have direct physical-world consequences.

The collaborative nature of this release, involving U.S., Australian, and international agencies, highlights a growing recognition that OT resilience requires coordinated and standardized global approaches rather than isolated national efforts.

Organizations should conduct an immediate asset inventory to identify systems that require isolation capabilities, while also reviewing network architecture diagrams to detect undocumented connections between OT and IT environments.

Clear roles and decision-making authority must be established for executing emergency isolation procedures.

Additionally, isolation drills should be incorporated into existing incident response exercises, and plans should be cross-referenced against sector-specific regulatory requirements to ensure compliance.

With geopolitical tensions and ransomware campaigns continuing to target critical infrastructure, this guidance arrives as a timely resource for operators seeking to strengthen resilience strategies.

CISA and ASD’s ACSC have indicated that this publication is part of a broader initiative addressing OT security gaps, suggesting that additional sector-specific guidance may be released in the future.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories