The bottom line: CISA and Five Eyes partners release a six-step procedure for controlled isolation of critical infrastructure that enables continued supply during attacks.
The US CISA and partner agencies from the Five Eyes alliance have published a structured procedure for isolating critical infrastructure during and after cyberattacks. The procedure “CI Fortify” is designed to help organizations disconnect their systems in a way that limits attackers and enables safe reconstruction.
CISA, the UK National Cyber Security Centre, Australia’s Australian Signals Directorate, Canada’s Communications Security Establishment, and New Zealand’s Government Communications Security Bureau have jointly developed the “CI Fortify” guidelines. The document addresses a known gap: while most IT managers know that critical infrastructure should be isolated in a crisis, many lack practical implementation guidance.
The procedure consists of six steps: (1) identification of vital systems and networks, (2) identification of critical customers or services, (3) classification by criticality levels and trust levels, (4) mapping of isolation points and connections to critical systems, (5) establishment of effective separations and isolation points, (6) creation and testing of an isolation plan. The goal is to continue operating critical services in an isolated state – not their complete shutdown.
Classification by criticality should divide networks, hosts, and systems into zones based on their function and threat landscape. This initially requires an inventory of connections to external systems: remote access from consultants and managed service providers, cloud environments, carrier networks, WiFi, satellite, radio, and mobile networks. Each connection must be checked for security mechanisms (such as encryption) and documented – including gateway information, architectures, firewall, and VPN configurations.
The background for the guidelines stems from repeated critical infrastructure outages: this week Minnesota Water Utilities had to shut down its operational technology systems following a coordinated attack; CAF Bank locked down its online services due to a third-party vulnerability. The guidelines emphasize that zero-trust network approaches can reduce the isolation problem, but isolation between networks and services remains necessary – particularly for OT (Operational Technology) systems, which are increasingly targeted by state actors.
Source: www.csoonline.com · Published 30 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.