CISA Publishes CI Fortify Guidance for OT Isolation

CISA Urges OT Isolation in New 'CI Fortify' Critical Infrastructure Guide

INFORMATIONAL
July 29, 2026
5m read
Policy and ComplianceIndustrial Control SystemsRegulatory

Related Entities

Organizations

CISA Australian Cyber Security Centre (ACSC)NCSC-UKCanadian Centre for Cyber Security (CCCS)

Full Report

Executive Summary

On July 28, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with its international partners—the Australian Cyber Security Centre (ACSC), the UK's National Cyber Security Centre (NCSC-UK), and the Canadian Centre for Cyber Security (CCCS)—published joint guidance for Critical Infrastructure (CI) operators. The guidance, titled “CI Fortify – Advice for Isolating Vital Systems,” provides a strategic framework for organizations to plan, prepare for, and execute the isolation of their vital Operational Technology (OT) systems from corporate Information Technology (IT) networks. This initiative is a direct response to the escalating threat of disruptive cyberattacks from both nation-state actors and cybercriminals targeting essential services. The guidance strongly recommends physical separation as the most robust defense and provides a model for maintaining critical functions even when under attack.


Regulatory Details

The CI Fortify guidance is not a legally binding regulation but rather a set of strong recommendations and best practices. It provides a structured approach for CI operators to enhance their resilience against high-impact cyber events.

The core components of the framework include:

  1. Identify Vital Systems: Organizations must first identify the absolute minimum set of OT assets and systems required to provide their most critical services to the public (e.g., maintaining water pressure, generating electricity).
  2. Map Dependencies: Thoroughly map all communication paths, data flows, and dependencies for these vital systems, including connections to IT networks, the internet, and third-party vendors.
  3. Establish an Isolation Strategy: Develop a pre-planned strategy for isolating these vital systems during a crisis. The guidance presents a spectrum of isolation options, from full physical separation to logical segmentation using cryptographic controls.
  4. Practice and Maintain: The plan must be regularly tested, practiced, and updated. It is not a one-time project but an ongoing capability that must be maintained.

Affected Organizations

This guidance is aimed at owners and operators of critical infrastructure across all sectors, with a particular focus on those that rely heavily on OT and Industrial Control Systems (ICS). This includes, but is not limited to:

  • Energy (Electric Grid, Oil & Gas)
  • Water and Wastewater Systems
  • Transportation Systems
  • Manufacturing
  • Healthcare
  • Telecommunications

Compliance Requirements

While not a mandate, the guidance outlines specific technical and procedural controls that organizations should implement:

  • Physical Isolation: The guidance strongly advocates for creating a true "air gap" by using dedicated infrastructure (e.g., separate fiber pairs) and eliminating any shared components between OT and IT networks.
  • Cryptographic Enclaves: Where complete physical isolation is not feasible, organizations should use strong cryptographic methods like IPsec or MACsec to create secure, logically isolated enclaves for OT traffic.
  • Secure Remote Access: All remote access to the OT environment must be strictly controlled, monitored, and disabled by default. When needed, it should be enabled only for specific, time-bound sessions through a secure jump host.
  • Incident Response and Recovery Plan: The isolation plan must be integrated into the organization's broader incident response and disaster recovery plans. This includes procedures for operating in a degraded, isolated state and for safely reconnecting systems after a threat has been neutralized.

Implementation Timeline

There is no formal deadline for implementation. However, CISA and its partners are urging CI operators to begin adopting these principles immediately due to the current threat landscape. The guidance is intended to be a foundational document for long-term strategic planning and investment in OT security and resilience.


Impact Assessment

For many CI organizations, implementing this guidance will require significant strategic, operational, and financial investment.

  • Architectural Changes: Many organizations will need to re-architect their networks to achieve the recommended level of segmentation, moving away from the historically flat networks where IT and OT were interconnected for convenience.
  • Resource Allocation: This will require budget for new hardware (firewalls, switches), software (secure remote access solutions), and personnel with expertise in both cybersecurity and industrial control systems.
  • Operational Disruption: The process of identifying and isolating systems can be complex and may require planned downtime. It will also change long-standing workflows for operators and maintenance staff.
  • Improved Resilience: The long-term impact is a significant improvement in resilience. An organization that can successfully isolate its vital systems can continue to provide essential services to the public even while its corporate IT network is dealing with a major ransomware attack or other compromise.

Compliance Guidance

  1. Start with a Crown Jewel Analysis: Begin by following the CI Fortify model to identify your most critical processes and the vital systems that support them.
  2. Conduct a Network Architecture Review: Analyze your current network architecture to identify all connection points between your IT and OT environments. Pay close attention to undocumented or forgotten links.
  3. Develop a Phased Implementation Plan: Create a multi-year roadmap. Start with high-impact, low-cost measures like strengthening firewall rules and implementing secure remote access. Then, plan for larger architectural projects like full network segmentation.
  4. Tabletop Exercises: Regularly conduct incident response exercises that specifically simulate a scenario requiring OT isolation. This will test your plan and train your staff on the procedures.

Timeline of Events

1
July 28, 2026
CISA and international partners publish the "CI Fortify – Advice for Isolating Vital Systems" guidance.
2
July 29, 2026
This article was published

MITRE ATT&CK Mitigations

The core recommendation of the guidance is to physically or logically segment OT networks from IT networks.

Strictly control and limit all network communication between IT and OT environments.

Use a data historian in a DMZ as a one-way data transfer mechanism from OT to IT, preventing direct IT-to-OT connections.

Implement secure, monitored, and strictly controlled remote access solutions for any required OT access.

Timeline of Events

1
July 28, 2026

CISA and international partners publish the "CI Fortify – Advice for Isolating Vital Systems" guidance.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CISAOT SecurityICS SecurityCritical InfrastructureNetwork SegmentationCI Fortify

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.