CI Fortify: who wrote the guidance and what it aims to do
The document, titled "CI Fortify – Advice for isolating vital systems," was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners. It lays out practical recommendations for critical infrastructure organizations to plan for — and execute — the disconnection of operational technology (OT) and supporting systems from corporate, Internet‑facing, and other less‑trusted networks while continuing to provide essential services over an extended period.
What counts as operational technology and which connections to map
The advisory defines operational technology as the hardware and software used to monitor or control processes, citing examples such as water treatment equipment, electrical systems, manufacturing machinery, transportation systems, and telecommunications infrastructure. Agencies instruct operators to identify the "vital systems" — the minimum OT and support systems needed to deliver a critical service — and to document every connection between those systems and corporate networks, remote‑access services, cloud environments, Internet‑facing infrastructure, vendors and contractors, and other critical infrastructure operators.
Isolation techniques and key terms the guidance prescribes
The guidance spells out a menu of isolation approaches and terms organizations should adopt in planning: an "isolation point" where connectivity between critical and non‑critical networks can be cut; "physical isolation," described as completely disconnecting vital systems from shared network or computing infrastructure and noted as the most effective protection; and "graduated isolation," which progressively restricts access as the threat escalates. The advisory also highlights administrative network controls — VLAN, access‑control lists, and routing changes — as temporary mitigations, and recommends hardware controls such as data diodes to permit one‑way data flows. After isolation, the agencies advise continued monitoring of routing tables, network traffic, and intrusion detection, and securing the network management zones used to administer routers and firewalls.
State‑sponsored actors, cybercriminals, and recent incidents cited as context
The advisory frames the guidance against a steady stream of intrusive activity. It says state‑sponsored threat actors routinely target critical infrastructure for espionage and to establish access for potential disruptive or destructive attacks. In February 2024, CISA, the FBI, NSA and other Five Eyes agencies warned that the Chinese Volt Typhoon group had breached organizations across communications, energy, transportation, and water sectors and had remained undetected in at least one critical infrastructure network for five years. The advisory also points to Chinese state‑sponsored actors tracked as Salt Typhoon, which it says have breached government, telecommunications, transportation, lodging, and military networks since at least 2021 — including compromises of major U.S. telecommunications providers AT&T, Verizon, and Lumen, and access to sensitive communications and U.S. law enforcement wiretap systems. The agencies additionally recount cybercriminal extortion and ransomware motives and recent disruptions to water infrastructure: American Water deactivated some systems after a cyberattack in October 2024, and a Kansas water treatment facility switched to manual operations after compromise. The advisory also notes that pro‑Russian hacktivists have sought unsecured OT systems at water and other CI operators with disruptive intent.
Operational trade‑offs: testing, maintenance, and the risks isolation introduces
The agencies acknowledge important trade‑offs. Physical isolation may be impractical for organizations that depend on Internet‑facing services, carrier networks, cloud services, or geographically distributed facilities. For those environments the guidance recommends strengthening OT network boundaries, using dedicated or encrypted communications links, removing unnecessary dependencies on corporate systems, and maintaining the ability to rapidly rebuild systems. Plans should define who can authorize each step, the conditions that trigger isolation, which systems must remain available, and how operations will continue without normal network connectivity. The advisory stresses testing the complete isolation of vital systems regularly — not just isolated subsystems — because partial tests can miss shared infrastructure and hidden dependencies. It also warns that isolation can cause systems to fall behind on security updates, reduce monitoring, and increase reliance on removable media, so operators must prepare to operate, monitor, and update systems manually until reconnection is possible.
What this means for technologists, policymakers, and water utilities
- Technologists and security teams: identify and document vital systems and every connection to them; establish isolation points; test full isolation scenarios regularly; and keep a secure offline or printed copy of isolation plans so they remain available if corporate networks are disrupted.
- Policymakers and regulators: the guidance provides a concrete playbook tied to cited intrusions (Volt Typhoon, Salt Typhoon) and recent water‑sector incidents, giving regulators a set of practical controls and testing expectations to weigh when assessing resilience requirements for critical infrastructure.
- Water utilities and other affected enterprises: the advisory underscores prior incidents — such as American Water's October 2024 response and the Kansas facility's move to manual operations — reinforcing the need to prepare for manual operation, secure offline plans, and the ability to rebuild and monitor isolated systems.
The agencies' message is unambiguous: prepare to isolate before an incident, not while one unfolds. But the guidance also exposes a central tension — physical isolation is the strongest defense the advisory offers, yet it may be operationally unrealistic for many modern, cloud‑dependent or geographically spread systems. How operators reconcile that tension — maintaining essential services while denying adversaries lateral access — is the practical test the guidance sets for critical infrastructure defenders.




