CISA Publishes CI Fortify Guidance for OT Isolation

CISA Urges OT Isolation in New 'CI Fortify' Critical Infrastructure Guide

INFORMATIONAL
July 29, 2026
July 30, 2026
5m read
Policy and ComplianceIndustrial Control SystemsRegulatory

Related Entities(initial)

Organizations

Australian Cyber Security Centre (ACSC)CISACanadian Centre for Cyber Security (CCCS)NCSC-UK

Products & Tech

Critical InfrastructureOperational Technology (OT)

Full Report(when first published)

Executive Summary

On July 28, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with its international partners—the Australian Cyber Security Centre (ACSC), the UK's National Cyber Security Centre (NCSC-UK), and the Canadian Centre for Cyber Security (CCCS)—published joint guidance for Critical Infrastructure (CI) operators. The guidance, titled “CI Fortify – Advice for Isolating Vital Systems,” provides a strategic framework for organizations to plan, prepare for, and execute the isolation of their vital Operational Technology (OT) systems from corporate Information Technology (IT) networks. This initiative is a direct response to the escalating threat of disruptive cyberattacks from both nation-state actors and cybercriminals targeting essential services. The guidance strongly recommends physical separation as the most robust defense and provides a model for maintaining critical functions even when under attack.


Regulatory Details

The CI Fortify guidance is not a legally binding regulation but rather a set of strong recommendations and best practices. It provides a structured approach for CI operators to enhance their resilience against high-impact cyber events.

The core components of the framework include:

  1. Identify Vital Systems: Organizations must first identify the absolute minimum set of OT assets and systems required to provide their most critical services to the public (e.g., maintaining water pressure, generating electricity).
  2. Map Dependencies: Thoroughly map all communication paths, data flows, and dependencies for these vital systems, including connections to IT networks, the internet, and third-party vendors.
  3. Establish an Isolation Strategy: Develop a pre-planned strategy for isolating these vital systems during a crisis. The guidance presents a spectrum of isolation options, from full physical separation to logical segmentation using cryptographic controls.
  4. Practice and Maintain: The plan must be regularly tested, practiced, and updated. It is not a one-time project but an ongoing capability that must be maintained.

Affected Organizations

This guidance is aimed at owners and operators of critical infrastructure across all sectors, with a particular focus on those that rely heavily on OT and Industrial Control Systems (ICS). This includes, but is not limited to:

  • Energy (Electric Grid, Oil & Gas)
  • Water and Wastewater Systems
  • Transportation Systems
  • Manufacturing
  • Healthcare
  • Telecommunications

Compliance Requirements

While not a mandate, the guidance outlines specific technical and procedural controls that organizations should implement:

  • Physical Isolation: The guidance strongly advocates for creating a true "air gap" by using dedicated infrastructure (e.g., separate fiber pairs) and eliminating any shared components between OT and IT networks.
  • Cryptographic Enclaves: Where complete physical isolation is not feasible, organizations should use strong cryptographic methods like IPsec or MACsec to create secure, logically isolated enclaves for OT traffic.
  • Secure Remote Access: All remote access to the OT environment must be strictly controlled, monitored, and disabled by default. When needed, it should be enabled only for specific, time-bound sessions through a secure jump host.
  • Incident Response and Recovery Plan: The isolation plan must be integrated into the organization's broader incident response and disaster recovery plans. This includes procedures for operating in a degraded, isolated state and for safely reconnecting systems after a threat has been neutralized.

Implementation Timeline

There is no formal deadline for implementation. However, CISA and its partners are urging CI operators to begin adopting these principles immediately due to the current threat landscape. The guidance is intended to be a foundational document for long-term strategic planning and investment in OT security and resilience.


Impact Assessment

For many CI organizations, implementing this guidance will require significant strategic, operational, and financial investment.

  • Architectural Changes: Many organizations will need to re-architect their networks to achieve the recommended level of segmentation, moving away from the historically flat networks where IT and OT were interconnected for convenience.
  • Resource Allocation: This will require budget for new hardware (firewalls, switches), software (secure remote access solutions), and personnel with expertise in both cybersecurity and industrial control systems.
  • Operational Disruption: The process of identifying and isolating systems can be complex and may require planned downtime. It will also change long-standing workflows for operators and maintenance staff.
  • Improved Resilience: The long-term impact is a significant improvement in resilience. An organization that can successfully isolate its vital systems can continue to provide essential services to the public even while its corporate IT network is dealing with a major ransomware attack or other compromise.

Compliance Guidance

  1. Start with a Crown Jewel Analysis: Begin by following the CI Fortify model to identify your most critical processes and the vital systems that support them.
  2. Conduct a Network Architecture Review: Analyze your current network architecture to identify all connection points between your IT and OT environments. Pay close attention to undocumented or forgotten links.
  3. Develop a Phased Implementation Plan: Create a multi-year roadmap. Start with high-impact, low-cost measures like strengthening firewall rules and implementing secure remote access. Then, plan for larger architectural projects like full network segmentation.
  4. Tabletop Exercises: Regularly conduct incident response exercises that specifically simulate a scenario requiring OT isolation. This will test your plan and train your staff on the procedures.

Timeline of Events

1
July 28, 2026
CISA and international partners publish the "CI Fortify – Advice for Isolating Vital Systems" guidance.
2
July 29, 2026
This article was published

Article Updates

July 30, 2026

Severity increased

Update clarifies 'CI Fortify' guidance is from Five Eyes nations, explicitly including New Zealand, and emphasizes its likely adoption as a de facto regulatory standard.

The updated information clarifies that the 'CI Fortify' guidance was issued by the Five Eyes intelligence alliance, explicitly naming New Zealand as a participating nation alongside the U.S., U.K., Australia, and Canada. The new report also places a stronger emphasis on the guidance's regulatory impact, stating it will likely serve as a de facto standard and be incorporated into sector-specific requirements, indicating a higher expectation for adherence. Additionally, new compliance advice such as 'Assume Breach' and 'Use the Purdue Model' are introduced.

July 30, 2026

Five Eyes nations, including New Zealand, officially endorse 'CI Fortify' guide, highlighting its de facto standard status.

The 'CI Fortify' guidance has been officially endorsed by the Five Eyes intelligence alliance, explicitly including New Zealand alongside the U.S., U.K., Australia, and Canada. This joint backing elevates the guide's status, positioning it as a de facto standard for critical infrastructure operators globally. Regulators are expected to integrate its principles into sector-specific requirements, driven by escalating threats like recent attacks on Minnesota water utilities. The update reinforces the urgency for CI operators to adopt these resilience measures.

Timeline of Events

1
July 28, 2026

CISA and international partners publish the "CI Fortify – Advice for Isolating Vital Systems" guidance.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CI FortifyCISACritical InfrastructureICS SecurityNetwork SegmentationOT Security

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.