Cybersecurity authorities have released new guidance urging critical infrastructure operators to isolate vital operational technology systems from other networks as state-sponsored actors and cybercriminals increasingly target essential services. The CI Fortify Guide provides detailed steps for separating OT and enabling systems to help operators maintain continuity of critical services during cyber incidents, whether from espionage campaigns, ransomware attacks, or pre-positioned access for future disruption.
The guidance addresses a persistent threat landscape where malicious actors routinely target critical infrastructure for data exfiltration, extortion, or to establish footholds for destructive attacks during crises. By isolating vital systems, operators can limit attackers' ability to achieve their objectives, contain active incidents, and support safe rebuilding of compromised systems. The approach recognizes that both nation-state actors seeking strategic advantage and profit-motivated criminals pose significant risks to infrastructure operators.
The CI Fortify Guide outlines a six-step process for effective network isolation. Operators must first identify minimum systems and networks required to deliver critical services, then determine common levels of criticality and trust across networks, map all connections to vital systems, build separation and isolation points, and create and test comprehensive isolation plans. The guidance emphasizes documenting connections between critical networks and non-critical corporate systems, vendor remote access points, untrusted networks, cloud environments, and peer critical networks, including technical details about system owners, third-party providers, information flows, and recovery objectives.
Physical isolation of vital OT and enabling systems represents the most effective protection, though the guidance acknowledges this may require manual processes and interrupt system-to-system communication. Where complete physical separation proves operationally infeasible, particularly for internet-facing services or geographically dispersed sites, operators should strengthen and secure OT boundaries that must remain connected. The guidance recommends graduated isolation approaches that progressively remove pathways into vital OT as threat environments worsen, moving from disabling remote worker access through isolating connections before reaching complete isolation of vital systems.
Operators should define trigger criteria for each isolation step in advance and link them to incident response plans, while regularly testing isolation procedures across all vital systems rather than individual components to reveal hidden dependencies. Following isolation, organizations must monitor whether controls remain effective and watch for unauthorized reconnections between critical and non-critical networks using routing tables, network traffic analysis, and intrusion detection systems. The guidance warns that isolation can introduce risks including systems falling out of patch cycles and reduced external visibility, recommending that operators maintain capabilities to rapidly rebuild vital systems and consider cross-domain solutions for secure information transfer where physical separation cannot be achieved.
Source: https://thecyberexpress.com/ci-fortify-guide-for-critical-systems/


