CISA and ACSC Release CI Fortify Guidance for Critical Infrastructure Isolation
CISA and the Australian Cyber Security Centre have jointly released CI Fortify, a new guidance document offering practical steps for critical infrastructure organizations to isolate vital systems during cyber incidents.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), has issued new guidance titled "CI Fortify – Advice for isolating vital systems." This joint release, supported by the Federal Bureau of Investigation and other international partners, aims to equip critical infrastructure (CI) organizations with actionable strategies to enhance their resilience against escalating cyber threats.
The core of the CI Fortify guidance focuses on the critical need for operational technology (OT) and enabling systems within CI environments to be capable of isolation. The document provides practical steps for organizations to disconnect these vital systems from all other networks during a disruption or crisis, allowing them to operate autonomously for extended periods. This capability is crucial for maintaining essential services even when broader network infrastructure is compromised.
Key recommendations within the guidance include a systematic approach to identifying which systems are truly critical. Organizations are advised to meticulously map all connections and dependencies between these vital systems and the rest of their IT and OT environments. This detailed understanding is the foundation for effectively planning and implementing separation points.
Implementing these separation points is presented as a critical defensive measure. The guidance outlines methods for creating robust air gaps or logical separations that can be activated quickly when a cyber incident or geopolitical crisis escalates. The goal is to minimize the potential attack surface and prevent threats from spreading from IT networks into sensitive OT environments.
By adopting the principles outlined in CI Fortify, critical infrastructure operators can significantly reduce the potential impact of cyberattacks and other disruptions. The ability to isolate vital systems ensures that essential services, such as power, water, and transportation, can continue to function, thereby safeguarding public safety and national security.
The guidance is particularly relevant in the current threat landscape, which is characterized by increasingly sophisticated state-sponsored attacks and the potential for widespread disruption. CI Fortify provides a proactive framework for organizations to prepare for and respond to such events, moving beyond reactive measures to build inherent resilience into their operational frameworks.
Organizations are encouraged to review the CI Fortify guidance and integrate its recommendations into their existing incident response and business continuity plans. The collaborative nature of the guidance, involving multiple international agencies, underscores the global importance of securing critical infrastructure against a shared threat.
Ultimately, CI Fortify serves as a vital resource for critical infrastructure entities seeking to bolster their defenses and ensure the continuity of essential services in an increasingly volatile digital and geopolitical environment. The guidance emphasizes that preparedness through isolation is a key strategy for maintaining operational integrity.