Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
Cloud

CISA’s Strategic Blueprint for Isolating Critical Infrastructure from Cyber Threats

CISA and global partners have released a structured six-step guide to help organizations effectively isolate their critical infrastructure during cyberattacks.

Jul 30, 2026 | 3 min read
Sign in to save

Many IT professionals recognize the importance of isolating critical infrastructure in times of crisis, yet implementing such measures without sacrificing security can pose significant challenges. A new practical guide, named CI Fortify, has been released by the United States Cybersecurity and Infrastructure Security Agency (CISA) in collaboration with the Five Eyes intelligence alliance, which includes agencies from the UK, Australia, Canada, and New Zealand. The guide aims to help entities effectively isolate and protect their essential systems from cyber threats while ensuring operational continuity.

"The goal is to enable the continued operation of critical services while in a state of isolation," the guide emphasizes, addressing the imperatives of maintaining functionality amidst increasing cyber threats.

Six Steps to Secure Isolation

With specific focus on operational technology (OT) systems as prime targets for state-sponsored cyber activities, the likelihood of attacks disrupting vital services—ranging from utilities to emergency services—has heightened considerably. Recent incidents, like the temporary suspension of online banking services by CAF Bank due to third-party issues and the coordinated cyberattack on Minnesota Water Utilities, illustrate these risks for organizations.

The newly provided action plan delineates a "critical path to isolation" through six methodical steps:

  • Identify vital systems and networks
  • Recognize critical customers
  • Assess common levels of criticality and trust across networks and hosts
  • Determine potential isolation points and map connectivity
  • Create effective separation and isolation infrastructures
  • Develop and regularly test an isolation response plan

The initial steps are largely tactical: Clearly delineating the systems essential for delivering critical services and establishing service benchmarks based on primary customer requirements, such as service volume. Segmentation into varying categories of criticality will also be necessary, enabling better risk management and threat mitigation.

Once systems are classified, ongoing mapping and updating of connection points between vital networks and others must occur. Important considerations include connections with vendors requiring remote access, relationships with cloud services, and ties to less secure peer networks. Documentation should detail all interconnections, including technical specifications like firewall settings, infrastructure layouts, and emergency contacts, as outlined by the guide. This detailed data is vital for constructing effective isolation measures.

Creating Separation and Isolation

The assumption that zero-trust architectures minimize the necessity for isolation has been challenged by this guide, which asserts that establishing clear isolation points between networks is crucial for containing cyber incidents. The guide underscores that, "Organizations must build physical isolation points into their vital systems to operate effectively in isolation."

Such isolation mandates strict separation from non-OT networks, excluding shared infrastructure through devices like routers, switches, and multiplexers. Aspects critical to maintaining operations, such as power supply and physical security measures, should not connect with less secure networks.

Organizations are advised to strengthen OT boundaries, ensuring that management and administrative systems are entirely segregated. Control mechanisms such as VLANs, route blocking, and blackhole routing can be employed to preemptively mitigate attack vectors.

Yet CISA recognizes that for certain extensive infrastructures, achieving complete physical separation may not be practical. In those scenarios, robust encryption must secure OT boundaries, combined with dedicated communication channels to restrict unwanted data exchanges.

Network communications must undergo encryption as well, particularly concerning external remote access, which should be strictly limited or completely restricted. Enforcing these rigorous security protocols helps counteract reliance on potentially vulnerable OT device encryption.

Ultimately, any service provided by an external carrier should be treated with apprehension, as it may introduce additional vulnerabilities.

Understanding Risks and Phased Isolation

To effectively isolate systems, operators must comprehend interdependencies between OT and non-OT environments. Dependencies could manifest through shared services for routing, storage, and authentication processes, necessitating careful oversight to avoid unintended degradation of service during isolation efforts.

Furthermore, organizations must consider operational sustainability during extended isolation periods, as they may provoke compliance issues, operational risks, or lack of external communications. With these challenges in mind, the guide recommends a phased approach to isolation, encouraging organizations to progressively limit access to assist in maintaining business continuity.

To fortify defenses, companies should adopt these strategic steps:

  • Disable remote access for employees to OT systems via corporate systems.
  • Insulate on-premises access to OT systems from non-critical environments.
  • Completely separate non-OT networks from OT environments.
  • Purge additional lower-priority connections between decentralized OT systems.
  • Achieve total isolation for OT environments and critical systems.

"Gradually restricting connectivity to OT systems as cyber threats escalate can effectively hinder attacks on vital operational technology," the guide concludes. Implementing this structured approach may provide organizations with a means to navigate the intricacies of safeguarding their essential infrastructure against an ever-evolving cyber threat landscape.

Source: Richard Rodriguez · www.csoonline.com
Sign in to join the discussion.