-
CISA, the ACSC, the FBI, and international allies issued joint CI Fortify guidance urging critical infrastructure operators to prepare emergency plans for disconnecting vital operational technology during cyberattacks.
-
Advanced nation-state threat groups like Volt Typhoon and Salt Typhoon actively target vulnerable energy, water, and telecommunications networks to position themselves for disruptive attacks.
-
The guidance recommends mapping all network connections, establishing physical or graduated isolation points, deploying data diodes, and regularly testing full-scale offline operations.

International cybersecurity authorities recently issued detailed technical advice urging critical infrastructure operators to prepare for emergency network isolation. The joint advisory helps essential service providers disconnect vital operational technology from corporate networks and public internet connections during major cyberattacks.
Government leaders emphasize that utility providers must maintain essential public services even while operating in complete isolation. The guidance titled CI Fortify, Advice for isolating vital systems, marks a joint initiative between Western intelligence partners.
The Cybersecurity and Infrastructure Security Agency led the publication alongside international defense allies. Agencies that support this activity include the Australian Cyber Security Centre, which is linked with the Australian Signals Directorate, as well as the Federal Bureau of Investigation and the National Security Agency.
Operational technology includes specialized technological hardware and software that the authorities use for regulating vital industrial processes. These control systems control municipal drinking water facilities, electric power grids, manufacturing production lines, regional transportation systems, and telecommunication infrastructure.
Experts in the field of cyber defense warn that state-sponsored hacker groups commonly gain access to industrial systems for long-term espionage. Foreign operatives on the lookout for intelligence want to have already-installed access to create damage during some future crisis or military conflicts. Financially motivated cybercriminals also aggressively target critical infrastructure assets to extort large ransom payments from utility operators.
Government security teams emphasize that utility executives must construct clear isolation procedures before active crisis situations erupt. Dark web-enabled crime takes many forms. Indian police recently busted a drug ring that used the dark web to target students.
Disconnecting essential control systems during an ongoing ransomware outbreak creates severe operational confusion without prior planning. The official playbook helps security teams isolate infected network zones quickly while maintaining continuous public utility delivery.
Escalating Cyber Threats Target Global Critical Infrastructure
Cyber intelligence campaigns that are backed by states have repeatedly penetrated essential civilian infrastructure networks over recent years. Two years ago, international cyber defense agencies warned that the Chinese state-sponsored threat group Volt Typhoon breached major utility providers.
Similarly, Chinese hackers have established unobserved access to certain key infrastructure networks for many years. Federal intelligence authorities have warned of state-sponsored cybercriminals who are ready to hack the energy network during potential military clashes.
Another advanced Chinese hacking collective tracked as Salt Typhoon compromised major telecommunications providers worldwide. The intrusion impacted major telecommunications giants, allowing threat actors to intercept sensitive communications and access official law enforcement wiretap systems.
Foreign operatives routinely exploit unpatched software vulnerabilities in edge networking hardware to pivot deeper into internal control networks.
Water treatment infrastructure faces continuous cyber targeting from both nation-state actors and opportunistic hacktivist groups. Also, in October two years ago, American Water deactivated internal digital systems following a major network intrusion to contain lateral movement.
Around that same period, a Kansas water treatment plant switched to manual operations after intruders compromised computer controls. Consequently, pro-Russian hacktivists actively scan the public internet for unsecured operational technology components to disrupt municipal water distribution systems.
Core Technical Steps for Implementing Emergency System Isolation
The CI Fortify framework instructs critical infrastructure operators to identify the absolute minimum equipment necessary to deliver basic services. Engineering staff must map every digital connection linking vital industrial controllers to corporate networks, remote access portals, cloud environments, and vendor platforms.
Moreover, operators must locate pre-determined isolation points where technical teams can physically sever network cables or block data traffic instantly. In addition, organizations must establish clear manual operating protocols to handle temporary communication outages and lost vendor support.
Federal guidelines define physical isolation as the total disconnection of vital control assets from shared computing infrastructure. Physical disconnects provide the strongest defense against spreading malware infections.
However, operators can also implement graduated isolation by systematically restricting external connections as threat levels rise. Security administrators first disable vendor remote access links, then sever corporate network bridges, and finally cut all remaining external internet connections.
Facilities can deploy specialized hardware devices, called data diodes to enforce single-direction data transfers. Usually, data diodes allow the outgoing information to transmit to a monitoring station while eliminating any possibility of incoming data into the network.
Therefore, malicious traffic cannot traverse single-direction physical diodes into isolated control environments. Network engineers can also apply administrative controls like virtual local area network rules and access control lists as temporary protective boundaries.
Managing Operational Hazards and Maintaining Isolated Networks
Disconnecting operational technology from external digital networks introduces distinct maintenance challenges and operational risks for industrial site managers. Isolated control networks miss routine software security updates, leaving known system vulnerabilities exposed to localized threats.
Further, site engineers face reduced visibility over distributed equipment, increasing reliance on physical site inspections and manual data collection. Besides, staff members often use USB drives to transfer engineering files manually, creating new malware infection routes.
Organizations must establish comprehensive post-isolation monitoring routines to confirm that severed network connections remain completely inactive. Security personnel must review the traffic routes and the status of the devices to catch unauthorized intrusion attempts.
Also, network administrators must protect their management systems to avoid unauthorized changes to the firewall settings during containment efforts. Isolation plans must clearly define authorization roles, emergency trigger thresholds, and backup communication channels for operational staff.
Federal agencies urge infrastructure operators to conduct full-scale network isolation drills regularly rather than testing isolated equipment components. Partial isolation tests fail to reveal hidden network dependencies, shared hardware resources, or unmapped vendor connections.
Facilities must also maintain printed physical copies of emergency operational manuals in secure local cabinets. Physical documentation ensures engineering teams retain access to critical operational procedures when central corporate storage servers go offline.