DarkReading

CI Fortify Guide Urges Isolation Of Critical Systems


Malicious cyber actors routinely target critical infrastructure to conduct espionage, extort victims, or establish access for disruptive and destructive attacks. The new CI Fortify Guide advises owners and operators to strengthen their ability to isolate vital systems from other networks, helping contain incidents and maintain critical services during a crisis or service disruption.

The CI Fortify Guide, titled CI Fortify: Advice for isolating vital systems, details steps for isolating operational technology (OT) and enabling systems from other networks. The guidance states that this capability can help OT owners, operators, and cyber defenders maintain continuity of critical services during incidents.

CI Fortify Guide Focuses on Isolating Vital Systems

State-sponsored actors routinely target critical infrastructure for espionage or to pre-position access for disruptive or destructive effects during a crisis or conflict. Cybercriminals also target critical infrastructure operators because of the sensitivity of their data and the importance of the services they provide. These attacks can include data exfiltration and ransomware campaigns intended to cause disruption or destruction.

The CI Fortify Guide says isolating vital OT and enabling systems can limit the ability of malicious actors to achieve their objectives, contain active incidents, and support the safe rebuilding of compromised systems.

Identifying Vital Systems Is Key to Network Isolation

The guidance outlines a six-step path toward effective network isolation. Operators are advised to first identify the minimum systems and networks required to deliver a critical service. They should also identify critical customers, determine common levels of criticality and trust across networks and hosts, map connections to vital systems, build separation and isolation points, and create and test an isolation plan.

Operators are also advised to document connections between critical networks and non-critical corporate systems, vendor remote access, untrusted networks, cloud environments, and peer critical networks. The guidance recommends recording technical and business information about these connections, including system owners, third-party providers, information flows, and recovery objectives.

Physical Separation Can Limit Cyber Attacks

The CI Fortify Guide describes isolation points as an effective way to limit an attacker’s ability to move into vital systems. Such points can help contain cyber attacks, limit operational impact, and reduce the time needed to remove a malicious actor and restore services.

Physical isolation requires no connectivity or shared infrastructure between vital and non-vital systems. The guidance describes physical isolation of vital OT and enabling systems as the most effective form of protection, while warning that it may trigger manual processes and interrupt system-to-system communication.

Where complete physical isolation is not operationally feasible, particularly for internet-facing services or geographically dispersed sites, operators are advised to strengthen and secure OT boundaries that must remain connected.

Isolation Plan Should Be Graduated and Tested

The guidance recommends a graduated approach that progressively removes pathways into vital OT as the cyber threat environment worsens. The example provided moves from disabling remote worker access to OT, through isolating non-OT and OT connections, before ultimately reaching complete isolation of the OT environment and vital systems.

However, the CI Fortify Guide emphasizes that a graduated approach must still have complete isolation of the most vital systems as its target state. Trigger criteria for each step should be defined in advance and linked to the organisation’s incident response plan.

Operators should regularly review and test their isolation plan to identify unforeseen consequences. The guidance recommends periodically testing the isolation of all vital systems rather than testing only individual systems or subsets, as limited testing may fail to reveal dependencies. Secure offline copies of isolation plans should also be maintained.

Following isolation, organisations should monitor whether controls remain effective and ensure that unauthorised or accidental connections do not reappear between critical and non-critical networks. Routing tables, network traffic flows, and intrusion detection systems can be used to identify potential weaknesses in isolation measures.

The guidance also warns that isolation can introduce risks, including systems falling out of patch cycles, reduced external visibility, and greater exposure to infected removable media. Where physical separation cannot be achieved, operators are advised to maintain the capability to rapidly rebuild vital OT and enabling systems, harden OT boundaries, and consider cross-domain solutions for transferring information across security domains.



Source link