Advice for isolating vital systems

Multi-national CI Fortify Guidance at a Glance

Four governments just advised critical infrastructure operators to prepare to isolate their most important OT systems. Here’s what that means, who should care, and what to do about it.

Take the 7 point check3 mins · 7 questions

In response to persistent threats, CI operators should have the capability to isolate vital OT and enabling systems from all other networks to ensure continuity of critical services.

CI Fortify, page 4

4governments
16pages

Joint advice issued on July 28, 2026

US: CISA and FBIAustraliaUKCanada

Key take aways

Physical isolation is the most effective form of protection

CI Fortify, page 7

Isolation points must be built into vital systems in advance

CI Fortify, page 7

Non-OT dependencies break isolation. Replace them locally

CI Fortify, page 8

Does this impact you?

The guidance is written for the owners, operators and cyber defenders of any critical service, and for the peers and utilities they depend on

Energy & powerWater and wastewaterDefence and militaryOil and gasManufacturingTransport and railChemicalsMining

What is isolation?

“Physical separation refers to infrastructure independence, while isolation refers to the ability to disconnect systems and continue operating independently when required.”

CI Fortify, page 8

Isolation Advice from the guidance

Critical Infrastructure

1

Reduce non-OT dependencies through localised capabilities or IT rapid recovery

2

Physically separate and isolate vital OT and enabling systems

Distributed CI

1

If possible, use dedicated communications paths, such as fibre pairs or CWDM wavelengths

2

Implement strong encryption over untrusted and shared communications links

Isolation measures

Consider unidirectional gateways and/or a cross-domain solution for continuous isolation of critical and non-critical networks.

The critical path to isolation

1

Identify vital systems and networks

The minimum set needed to deliver the critical service

2

Identify critical customers

Dependent critical infrastructure, such as military infrastructure and lifeline services. Set a service delivery target based on their needs

3

Identify common levels of criticality and trust for networks and hosts

Group hosts into zones that share criticality and threat exposure

4

Map connections to vital systems and identify potential isolation points

Record every interconnection: corporate systems, vendor remote access, untrusted networks, cloud and peer utilities. Note how each one transits, and mark the isolation points

5

Build effective separation and isolation points

Isolation points between critical and non critical networks prevents attacks pivoting into critical systems

6

Create and test an isolation plan

Trigger criteria set in advance. Test periodically. Keep an offline copy

Isolation, ranked

Strongest to weakest, as the guidance ranks them

Physical isolation

Most effective

“Physical isolation of vital OT and enabling systems is the most effective form of protection and is likely to trigger manual processes and interrupt system-to-system communication for its duration.”

CI Fortify, page 7

Requires no connectivity and no shared infrastructure with any other network. Plan for how you will run that way for an extended period.

Unidirectional gateways, data diodes and cross domain solutions

High assurance

“Data diodes and cross domain solutions (CDS) provide a means of transferring data between critical and non-critical networks with a high assurance of protection, if appropriately designed, configured and maintained, which exceed standard network gateway architectures.”

CI Fortify, page 12

Some data flows can continue during a period of extended isolation. Seek advice from organisations with expertise in deploying them.

Graduated isolation

Reduces attack surface

“A graduated approach must still have total isolation of vital OT and enabling systems as the target state.”

CI Fortify, page 10

Access to OT is progressively removed as the threat environment deteriorates, with trigger criteria defined in advance.

VLANs, MPLS and IP access lists

Minimally effective

“CI operators must not rely on these interim measures as a long-term solution for a fully segregated operations network.”

CI Fortify, page 13

An interim measure on the journey to physical or cryptographic isolation. MPLS gives no assurance of segregation and is not secure by default

“The end state must be to enable the continued operation of critical services in a state of isolation.”

CI Fortify: Advice for isolating vital systems, page 7

Are your operations isolatable?

Find out where you stand in 5 minutes with this self assessment

Take the 7 point check

Go deeper on isolation technology

Data diodes and unidirectional gateways compared, and where each one fits

Get the guide

Walk through real applications in our live webinar

Keeping OT Going When IT Goes Dark, with Andrew Ginter on Sept 29th

Save my spot!