Security
Cybersecurity agencies from the United States, Australia, the United Kingdom and Canada have jointly urged operators of critical infrastructure to prepare for the emergency isolation of operational technology (OT) systems to ensure essential services remain operational during major cyberattacks or geopolitical crises.
The guidance, titled "CI Fortify – Advice for Isolating Vital Systems," has been jointly released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate (ASD), the UK's National Cyber Security Centre (NCSC) and the Canadian Centre for Cyber Security (CCCS).
The advisory comes amid growing concerns over state-sponsored cyber campaigns targeting critical infrastructure sectors, including energy, telecommunications, water, transportation and other essential services.
According to the agencies, operators should be prepared to isolate critical OT environments as an emergency response measure to prevent attackers from disrupting industrial operations, contain ongoing cyber incidents and accelerate system recovery.
"America's critical infrastructure is frequently targeted by malicious state-sponsored cyber threat actors whose aim is persistent access to vital systems and disrupt essential services," said Chris Butera, Acting Executive Assistant Director for Cybersecurity at CISA.
He said organisations should maintain robust isolation and recovery plans that enable essential services to continue operating even under degraded conditions, including through manual operations or alternative Supervisory Control and Data Acquisition (SCADA) pathways where possible.
The guidance outlines a framework for improving operational resilience by identifying critical assets, mapping dependencies between IT and OT environments, establishing predefined separation points and developing graduated isolation procedures that can be activated during a cyber crisis.
The agencies also recommend regularly testing isolation plans and recovery procedures to ensure organisations can sustain operations independently during prolonged cyber incidents or large-scale supply chain disruptions.
The publication forms part of CISA's broader CI Fortify initiative, which focuses on strengthening the cyber resilience of critical infrastructure against increasingly sophisticated state-sponsored threats.
The advisory reflects growing concern among Western governments that cyberattacks on critical infrastructure could accompany geopolitical tensions or armed conflicts. In recent years, security agencies have repeatedly warned that advanced threat groups linked to nation states are attempting to establish persistent access to industrial control systems and other operational technology environments that underpin essential public services.
For operators of critical infrastructure, the guidance signals a shift from traditional incident response toward operational resilience, encouraging organisations to plan not only for preventing cyber intrusions but also for maintaining essential services when critical systems must be deliberately disconnected from wider networks during an attack.
The guidance, titled "CI Fortify – Advice for Isolating Vital Systems," has been jointly released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate (ASD), the UK's National Cyber Security Centre (NCSC) and the Canadian Centre for Cyber Security (CCCS).
The advisory comes amid growing concerns over state-sponsored cyber campaigns targeting critical infrastructure sectors, including energy, telecommunications, water, transportation and other essential services.
According to the agencies, operators should be prepared to isolate critical OT environments as an emergency response measure to prevent attackers from disrupting industrial operations, contain ongoing cyber incidents and accelerate system recovery.
"America's critical infrastructure is frequently targeted by malicious state-sponsored cyber threat actors whose aim is persistent access to vital systems and disrupt essential services," said Chris Butera, Acting Executive Assistant Director for Cybersecurity at CISA.
He said organisations should maintain robust isolation and recovery plans that enable essential services to continue operating even under degraded conditions, including through manual operations or alternative Supervisory Control and Data Acquisition (SCADA) pathways where possible.
The guidance outlines a framework for improving operational resilience by identifying critical assets, mapping dependencies between IT and OT environments, establishing predefined separation points and developing graduated isolation procedures that can be activated during a cyber crisis.
The agencies also recommend regularly testing isolation plans and recovery procedures to ensure organisations can sustain operations independently during prolonged cyber incidents or large-scale supply chain disruptions.
The publication forms part of CISA's broader CI Fortify initiative, which focuses on strengthening the cyber resilience of critical infrastructure against increasingly sophisticated state-sponsored threats.
The advisory reflects growing concern among Western governments that cyberattacks on critical infrastructure could accompany geopolitical tensions or armed conflicts. In recent years, security agencies have repeatedly warned that advanced threat groups linked to nation states are attempting to establish persistent access to industrial control systems and other operational technology environments that underpin essential public services.
For operators of critical infrastructure, the guidance signals a shift from traditional incident response toward operational resilience, encouraging organisations to plan not only for preventing cyber intrusions but also for maintaining essential services when critical systems must be deliberately disconnected from wider networks during an attack.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




