CyberSecurityNews

CISA Releases Checklist for Critical Infrastructure Organizations to Isolate Vital Systems


The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), the Federal Bureau of Investigation (FBI), and international partners, has released new joint guidance to strengthen the resilience of critical infrastructure (CI) organizations.

The official CI Fortify guidance provides actionable recommendations to help organizations rapidly isolate essential systems during active cyber incidents or geopolitical disruptions.

At its core, the CI Fortify guidance emphasizes maintaining essential services even when primary networks are compromised.

This includes ensuring that vital operational technology (OT) systems, such as those used across the energy, water, transportation, and healthcare sectors, can operate independently of corporate IT networks and external connections.

CISA and Partners Release Checklist to Help CI Systems

These measures align with broader operational technology guide frameworks designed to protect legacy industrial assets.

The document outlines a structured approach for identifying and prioritizing “vital systems,” defined as assets critical to safety, service delivery, or national security.

Organizations are encouraged to assess dependencies, including upstream and downstream systems, to understand how disruptions could cascade across operations.

The joint advisory provides a checklist of technical and operational measures to prepare organizations for emergency isolation:

  • Asset Mapping: Identify critical assets and map system interdependencies across IT and OT environments.
  • Separation Points: Establish clearly defined separation points between vital systems and less critical networks.
  • Isolation Mechanisms: Implement secure isolation mechanisms such as air-gapping, network segmentation, or controlled disconnection procedures.
  • Manual Fallbacks: Develop and test manual fallback procedures to maintain operations without digital dependencies.
  • Personnel Readiness: Ensure personnel are trained to execute isolation protocols during emergencies.

Additionally, the guidance highlights the importance of pre-configured isolation plans that can be activated rapidly, minimizing decision-making delays during active incidents.

Example Use Case: A power grid operator could isolate its supervisory control and data acquisition (SCADA) systems from corporate IT networks during a ransomware attack.

By pre-establishing segmentation controls and manual override capabilities, the operator can continue delivering electricity while incident response teams contain the threat within non-critical systems.

The release comes amid a surge in cyberattacks targeting critical infrastructure globally, including campaign shifts across industrial control systems driven by advanced persistent threat (APT) groups and geopolitical tensions.

These campaigns often exploit weak segmentation between IT and OT environments, enabling lateral movement and widespread disruption. By focusing on isolation as a defensive strategy, CISA and its partners aim to limit attacker access and reduce blast radius during incidents.

The guidance aligns with broader secure-by-design and resilience-focused initiatives being promoted across international cybersecurity agencies.

Defense ParadigmTraditional Preventive SecurityResilience-Driven Isolation Framework
Primary AssumptionAssumes breaches can be fully preventedAssumes compromise will occur; focuses on operating through it
Network ArchitectureHighly interconnected IT and OT systemsPre-defined separation points and air-gapped segments
Incident HandlingReactive containment after initial compromiseRapid activation of pre-configured manual fallbacks
Impact RadiusHigh risk of lateral movement across networksRestricted blast radius isolating non-critical systems

The CI Fortify framework underscores a shift from purely preventive security models to resilience-driven approaches. Rather than assuming breaches can always be prevented, the guidance prepares organizations to operate through compromise.

For cybersecurity leaders, this reinforces the need to integrate isolation planning into incident response strategies, OT security architectures, and business continuity planning.

As regulatory pressure increases across critical sectors, adopting such frameworks may also support compliance with emerging resilience mandates.

Organizations can access the full guidance through CISA and ASD ACSC official resources to begin implementing these isolation strategies.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link