Cyber security agencies from Australia, the US, the United Kingdom, and Canada have published new guidance to help critical infrastructure operators isolate vital operational technology (OT) and enabling systems during a major cyber incident or geopolitical crisis.
CI Fortify – Advice for Isolating Vital Systems, led by the Australian Signals Directorate, sets out how operators can protect essential services when wider networks have been compromised or are considered at imminent risk of compromise.
The guidance reflects the growing threat from state-sponsored actors seeking persistent access to infrastructure such as energy, water, telecommunications, and transport systems. Isolation may be needed to prevent an attack from reaching vital systems, contain an intrusion, or support the safe restoration of compromised systems.
Organizations are advised to identify their most vital assets, map the connections and dependencies that support them, and establish effective points at which systems can be separated from other networks. Rather than relying on a single ‘disconnect’ option, the guidance recommends graduated isolation plans that can be activated according to the severity and nature of the threat.
From an operational resilience perspective, the central message is that isolation must preserve essential outcomes, not simply protect technology. Operators should be able to sustain services under degraded conditions for an extended period, potentially using manual processes or alternative SCADA pathways.
The guidance also stresses the importance of regularly testing isolation and recovery arrangements. Separation points that have not been tested may fail when needed or create unforeseen operational consequences. Effective planning therefore requires close cooperation between cyber security, OT, engineering, business continuity, and operational teams.






