Multi-national CI Fortify Guidance at a Glance
Four governments just advised critical infrastructure operators to prepare to isolate their most important OT systems. Here’s what that means, who should care, and what to do about it.
In response to persistent threats, CI operators should have the capability to isolate vital OT and enabling systems from all other networks to ensure continuity of critical services.
CI Fortify, page 4
Joint advice issued on July 28, 2026
Key take aways
Physical isolation is the most effective form of protection
CI Fortify, page 7
Isolation points must be built into vital systems in advance
CI Fortify, page 7
Non-OT dependencies break isolation. Replace them locally
CI Fortify, page 8
Does this impact you?
The guidance is written for the owners, operators and cyber defenders of any critical service, and for the peers and utilities they depend on
What is isolation?
“Physical separation refers to infrastructure independence, while isolation refers to the ability to disconnect systems and continue operating independently when required.”
CI Fortify, page 8
Isolation Advice from the guidance
Critical Infrastructure
Reduce non-OT dependencies through localised capabilities or IT rapid recovery
Physically separate and isolate vital OT and enabling systems
Distributed CI
If possible, use dedicated communications paths, such as fibre pairs or CWDM wavelengths
Implement strong encryption over untrusted and shared communications links
Isolation measures
Consider unidirectional gateways and/or a cross-domain solution for continuous isolation of critical and non-critical networks.
The critical path to isolation
Identify vital systems and networks
The minimum set needed to deliver the critical service
Identify critical customers
Dependent critical infrastructure, such as military infrastructure and lifeline services. Set a service delivery target based on their needs
Identify common levels of criticality and trust for networks and hosts
Group hosts into zones that share criticality and threat exposure
Map connections to vital systems and identify potential isolation points
Record every interconnection: corporate systems, vendor remote access, untrusted networks, cloud and peer utilities. Note how each one transits, and mark the isolation points
Build effective separation and isolation points
Isolation points between critical and non critical networks prevents attacks pivoting into critical systems
Create and test an isolation plan
Trigger criteria set in advance. Test periodically. Keep an offline copy
Isolation, ranked
Strongest to weakest, as the guidance ranks them
Physical isolation
Most effective
“Physical isolation of vital OT and enabling systems is the most effective form of protection and is likely to trigger manual processes and interrupt system-to-system communication for its duration.”
CI Fortify, page 7
Requires no connectivity and no shared infrastructure with any other network. Plan for how you will run that way for an extended period.
Unidirectional gateways, data diodes and cross domain solutions
High assurance
“Data diodes and cross domain solutions (CDS) provide a means of transferring data between critical and non-critical networks with a high assurance of protection, if appropriately designed, configured and maintained, which exceed standard network gateway architectures.”
CI Fortify, page 12
Some data flows can continue during a period of extended isolation. Seek advice from organisations with expertise in deploying them.
Graduated isolation
Reduces attack surface
“A graduated approach must still have total isolation of vital OT and enabling systems as the target state.”
CI Fortify, page 10
Access to OT is progressively removed as the threat environment deteriorates, with trigger criteria defined in advance.
VLANs, MPLS and IP access lists
Minimally effective
“CI operators must not rely on these interim measures as a long-term solution for a fully segregated operations network.”
CI Fortify, page 13
An interim measure on the journey to physical or cryptographic isolation. MPLS gives no assurance of segregation and is not secure by default
“The end state must be to enable the continued operation of critical services in a state of isolation.”
CI Fortify: Advice for isolating vital systems, page 7
Are your operations isolatable?
Find out where you stand in 5 minutes with this self assessment
Go deeper on isolation technology
Data diodes and unidirectional gateways compared, and where each one fits
Walk through real applications in our live webinar
Keeping OT Going When IT Goes Dark, with Andrew Ginter on Sept 29th