Cyber Agencies Urge Infrastructure to Isolate Vital Systems

Cyber Agencies Urge Infrastructure to Isolate Vital Systems

The recent surge in sophisticated cyberattacks targeting national energy grids and water treatment facilities has forced a radical rethink of traditional digital defense strategies among global security agencies. As of early 2026, the international community has shifted its focus from purely preventative measures to a strategy centered on operational resilience and system isolation. This transition is formally encapsulated in the CI Fortify initiative, a collaborative effort led by the Australian Signals Directorate’s Australian Cyber Security Centre, the United States Cybersecurity and Infrastructure Security Agency, and their counterparts in the United Kingdom, Canada, and New Zealand. The core philosophy of this guidance acknowledges that even the most robust firewalls can eventually be bypassed by state-sponsored actors or advanced ransomware groups. Therefore, critical infrastructure operators must now possess the technical capability to sever connections between their most vital operational technology environments and broader corporate networks without causing a total service failure. This approach ensures that even if an attacker gains control over a company’s administrative email servers or cloud storage, the machinery that delivers electricity, clean water, and emergency communications remains secure and functional. By prioritizing the ability to operate in a disconnected state, organizations can contain the spread of malicious software and buy precious time for forensic teams to neutralize threats in non-essential areas of the digital ecosystem.

1. Pinpoint the Most Essential Assets

Identifying what constitutes an essential asset requires a departure from traditional information technology inventorying and an embrace of mission-critical engineering principles. Organizations are now directed to conduct exhaustive audits to determine the absolute minimum set of control systems, communication tools, and safety equipment required to maintain core operations. This process involves stripping away non-essential features that rely on external data feeds and focusing exclusively on the primary mechanical and electronic triggers that govern service delivery. For instance, an electric utility must identify the specific relays and transformers that are required to keep the lights on for residential areas, even if billing systems or customer-facing applications are offline. By establishing these hard baselines, engineers can create a blueprint for a lean, defensible environment that prioritizes survival over administrative efficiency. It is a fundamental shift in perspective that treats the network not as a unified whole, but as a collection of modular components where the most vital gears are protected by the thickest digital walls. This granular understanding allows for more precise isolation, ensuring that only the most vulnerable or non-critical sectors are cut off while the heart of the infrastructure keeps beating.

Beyond just mechanical systems, the identification process must incorporate specific performance goals and the needs of high-priority external stakeholders. Security agencies emphasize that isolation planning cannot happen in a vacuum; it must account for the minimum amount of service—whether it be water pressure or megawatt-hours—that must be maintained to prevent societal instability. Operators are tasked with mapping their service outputs to critical customers like hospitals, emergency response centers, and military installations. If an incident occurs, the isolation strategy must facilitate the prioritization of these clients, ensuring that limited resources are diverted to where they are most needed. This stage of planning also involves assessing the human element, specifically the staff required to operate systems manually or in a degraded digital state. Decision-makers must ask whether they have enough technicians on hand to manage local consoles if the central remote-access platform is intentionally disabled. By integrating social and medical priorities into the technical isolation plan, infrastructure providers ensure that their response to a cyber crisis does not inadvertently trigger a wider humanitarian emergency. This comprehensive approach transforms cybersecurity from a back-office concern into a cornerstone of national safety and public health.

2. Uncover and Resolve Hidden Technical Ties

One of the most significant hurdles to successful system isolation is the existence of hidden dependencies—deep-seated technical connections that link industrial machinery to administrative networks. In many modern facilities, industrial control systems have become quietly reliant on corporate technology for fundamental services such as user authentication, data logging, and even time synchronization. For example, if a water treatment plant’s local controllers rely on a centralized Active Directory server located in a corporate office for login permissions, severing the network connection would effectively lock operators out of their own equipment. These hidden links often go undocumented for years, only becoming apparent during a system failure or an audit. The CI Fortify guidance mandates a thorough investigation into these cross-domain dependencies to ensure that an intentional disconnection does not inadvertently cause a self-inflicted blackout. Engineers must trace every software handshake and heartbeat signal that crosses the boundary between the corporate business side and the industrial operational side. Only by unearthing these invisible tethers can an organization begin to build a truly independent and resilient operational zone that is capable of standing on its own when the rest of the company is under siege.

Once these dependencies are mapped, the focus must shift toward building local, redundant versions of essential services within the secure operational zones. This means implementing dedicated industrial versions of identity management, domain controllers, and backup repositories that exist entirely behind the isolation boundary. For instance, instead of relying on a global Network Time Protocol server, a power station might install its own GPS-linked clock to provide the precise timestamps required for synchronized grid operations. Similarly, backup strategies must be redesigned so that mission-critical data is stored locally and can be restored without needing to traverse a potentially compromised corporate backbone. This localized infrastructure serves as a lifeboat for the system’s digital functions, providing all the necessary air and sustenance to keep the operational technology environment running autonomously for days or even weeks. While building these parallel systems involves significant upfront costs and maintenance efforts, the investment is justified by the near-certainty that a major cyber incident will eventually sever communication with the main headquarters. In the current landscape of 2026, the ability to operate off-grid digitally is no longer a luxury but a mandatory requirement for any organization tasked with managing the lifeblood of a modern nation.

3. Chart Every Network Pathway

Creating a comprehensive catalog of every single entry and exit point in an industrial network is a painstaking but indispensable requirement for modern infrastructure security. In the current era of hyper-connectivity, many operational technology environments are riddled with unofficial connections that have been added over time for the convenience of vendors, maintenance crews, or remote analysts. These pathways often include cellular gateways for turbine monitoring, satellite links for remote pump stations, and even temporary Wi-Fi hotspots used during construction phases. The new guidance insists that every one of these portals be documented with surgical precision, including the exact hardware used, the specific protocols allowed, and the physical location of the connection. Without a complete map of these backdoors, any attempt at isolation will be incomplete, leaving an attacker with multiple pathways to bypass the main disconnect switch. This inventorying process must be treated as a living document, updated in real-time as new equipment is installed or service contracts are renewed. By maintaining a high-fidelity map of the digital perimeter, security teams can ensure that when the order to isolate is given, no forgotten satellite dish or vendor laptop provides a persistent foothold for a malicious actor.

Furthermore, every documented connection must be assigned a clear owner and a specific justification for its existence within the operational environment. It is not enough to simply know that a connection exists; the security team must understand who manages the credentials for that link and how to reach the authorized personnel in the event of an emergency. For example, if a third-party vendor has a persistent virtual private network connection for software updates, there must be a pre-established protocol for disabling that link instantly without waiting for the vendor’s permission. The guidance also recommends labeling these pathways based on their risk level and the trustworthiness of the external entity on the other end. Connections to government-audited partners might be treated differently than links to generic cloud-based analytics platforms. This administrative layer of network mapping creates a clear hierarchy of control, allowing for a more nuanced and organized approach to disconnection. When a crisis unfolds, the confusion of the moment is mitigated by the existence of a clear, authoritative master list that tells defenders exactly where to pull the plugs. This level of preparation ensures that the isolation process is a deliberate, controlled maneuver rather than a frantic scramble through dark server rooms and remote utility poles.

4. Adopt a Scaled Response Strategy

Effective cyber resilience rejects the notion that isolation is a binary choice, favoring instead a graduated response that scales with the severity of the threat. Agencies suggest that organizations develop a multi-tiered plan that allows them to dial back connectivity in stages, rather than jumping immediately to a total shutdown which could have massive economic consequences. The first tier of such a strategy might involve merely disabling remote access for administrative staff and non-essential contractors while keeping the primary data pipes open. This reduces the attack surface without impacting the flow of information that helps run the plant. If the threat escalates or an intrusion is detected within the corporate network, the second tier would involve a logical separation where firewalls are set to their most restrictive policies, blocking all but the most critical traffic between the IT and OT worlds. This measured approach allows the organization to continue functioning with near-normal efficiency while significantly hardening its defenses. It provides a way to respond to suspicious reconnaissance without overreacting and causing self-inflicted service interruptions that might be exactly what the attacker intended to provoke.

The final stage of this scaled strategy is total isolation, an emergency posture where the operational environment is completely severed from all external networks, including the internet and the corporate headquarters. For this to work seamlessly, leadership teams must agree upon specific, measurable triggers for each stage of the response before a crisis ever occurs. These triggers might be based on the type of malware detected, the identity of the target system, or a directive from national security agencies. By pre-authorizing these actions, organizations avoid the paralyzing delays that occur when technical staff have to seek board-level approval during the heat of a fast-moving ransomware attack. The decision to sever connections is a monumental one, carrying risks of its own, and it should be backed by a clear legal and operational framework that protects the individuals making the call. This strategic foresight ensures that the response is both rapid and proportionate, preventing a minor localized infection from turning into a nationwide catastrophe. In the high-stakes environment of 2026, having a well-defined playbook for escalation is what separates organizations that recover quickly from those that suffer prolonged and devastating outages.

5. Prioritize Hardware-Based Partitioning

While software-based security measures such as virtual local area networks and traditional firewalls are useful, they are increasingly viewed as insufficient against the most advanced persistent threats. The CI Fortify guidance places a strong emphasis on hardware-based partitioning as the gold standard for protecting the most sensitive segments of critical infrastructure. This involves physical separation, where the most vital control systems are housed on their own dedicated routers, switches, and server racks that do not share any physical components with the general corporate network. In a physical partition, there is no shared management software that an attacker could exploit to jump from a compromised email server to a water pump controller. This physical segmentation provides a layer of security that is nearly impossible to bypass through remote code execution alone. While this approach is more expensive and complex to manage than virtual partitioning, it provides a level of certainty that software-defined perimeters simply cannot match. For systems that manage the core safety and stability of a nation’s resources, the extra cost of dedicated hardware is a necessary premium for genuine peace of mind and operational continuity.

For scenarios where absolute physical isolation is not feasible due to the need for high-speed data exchange, the guidance recommends the use of high-assurance hardware such as unidirectional security gateways or data diodes. These specialized devices allow data to flow in only one direction—usually from the secure industrial zone out to the corporate network for monitoring—while physically preventing any signals from traveling back in the opposite direction. This creates a one-way street that protects the industrial systems from incoming malware or unauthorized commands while still allowing the business to receive the data it needs for reporting and analysis. Furthermore, even within these partitioned zones, agencies advocate for the use of strong, hardware-encrypted communication channels to prevent lateral movement by an intruder who might have gained physical access to the facility. This layered hardware defense strategy creates a fortress within a fortress architecture that assumes the software layer will eventually fail. By grounding security in the physical reality of cables and circuits, infrastructure operators can create a resilient environment that is much harder for a remote adversary to manipulate or destroy. This shift toward hardware-centric defense reflects a growing recognition that in the digital realm, the physical world remains the ultimate anchor of security.

6. Conduct Full-Scale Disconnection Drills

The most sophisticated isolation plan is essentially worthless if it has never been tested under realistic conditions to ensure it actually functions as intended. International cyber agencies are now calling for regular, full-scale disconnection drills that simulate a total digital blackout of external services. These exercises are designed to identify the unknown unknowns—the unexpected failures that occur when a system is suddenly deprived of its usual network connections. For instance, a drill might reveal that an automated safety valve requires an external cloud-based license check to open, or that staff members do not know the physical locations of the manual override switches. By conducting these tests in a controlled environment, organizations can refine their procedures and fix technical glitches before a real attacker forces their hand. These drills should involve not just the IT team, but the entire operational staff, including plant managers, safety officers, and physical security personnel. This whole-of-business approach ensures that everyone knows their role when the digital world goes dark, turning a potentially chaotic event into a practiced and professional routine that minimizes downtime and maximizes safety.

A critical component of these drills is the verification of offline resources and the effectiveness of manual backup procedures. In an era where almost all technical documentation is stored in the cloud or on shared corporate drives, an isolated system can leave technicians unable to act if they cannot access blueprints, manual logs, or recovery scripts. The guidance strongly suggests maintaining updated, printed copies of all isolation protocols and emergency contact lists in physical red folders at key locations throughout the facility. Additionally, digital copies of essential software and configuration files should be kept on immutable, offline storage media that can be accessed without a network connection. Drills should specifically test whether staff can restore a system using only these offline tools within a reasonable timeframe. This focus on manual readiness acknowledges that the ultimate backup to a failed digital system is a well-trained human armed with the right physical tools and information. By practicing for the worst-case scenario, infrastructure providers build a culture of preparedness that extends beyond the digital realm, ensuring that they can maintain their duty to the public regardless of the state of the global internet. This rigorous testing regime is the only way to transform a theoretical plan into a reliable defensive capability.

7. Secure the Environment After Separation

Once a vital system has been successfully isolated from the broader network, the security challenge does not end; rather, it shifts toward maintaining the integrity of the now-sealed environment. Defenders must immediately implement rigorous monitoring to ensure that no leakage is occurring between the isolated zone and the potentially compromised exterior. This involves checking for unauthorized wireless signals, forgotten cellular modems, or even physical cables that might have been surreptitiously run between server rooms. In an isolated state, the operational technology environment becomes a closed ecosystem, and any digital entry point—no matter how small—represents a massive risk. Security teams are advised to use portable network sniffers and specialized auditing tools to scan for any outbound traffic that might indicate a persistent threat is still trying to communicate with an external server. Furthermore, the internal logs of the isolated system must be reviewed with extra scrutiny, as any unusual activity can no longer be dismissed as common network traffic. This period of isolation is a high-stakes quarantine where the goal is to prove that the environment is truly clean and under the full control of the authorized operators.

Maintaining security in an isolated state also requires a specialized approach to malware hygiene, particularly regarding the use of removable media like USB drives. Because the system can no longer receive automatic security patches or antivirus updates from the cloud, it becomes more vulnerable to infections brought in by well-meaning technicians. The guidance mandates the use of dedicated cleaning stations—standalone computers used to scan and scrub any external drive before it is allowed to touch the isolated network. Even when the crisis has passed and the decision is made to reconnect to the internet, the process must be treated as a high-risk operation. Reconnection should never be a simple matter of plugging back in; it requires a phased approach where traffic is slowly reintroduced and monitored for any signs of re-infection or dormant malware waking up. A full security review of the entire infrastructure, including a search for modified system files or new administrative accounts created during the breach, must be completed before returning to normal operations. This cautious approach ensures that the act of coming back online does not undo all the hard work spent protecting the system during the isolation period, providing a final layer of insurance against a persistent adversary.

8. Elevate Resilience to Executive Leadership

The ability to maintain critical services during a cyber crisis is fundamentally a business and governance challenge that requires the active involvement of senior executives and boards of directors. For too long, cybersecurity has been relegated to the basement, treated as a technical cost center rather than a core component of corporate strategy. The new guidance makes it clear that the ultimate responsibility for isolation decisions and the resulting service impacts rests with the highest levels of leadership. This means that executives must be deeply involved in defining the budget for the necessary hardware, the hiring of specialized security staff, and the procurement of redundant communication systems. They must also engage in strategic discussions about the financial trade-offs of isolation, such as the potential loss of revenue from billing systems versus the reputational and legal risks of a total system failure. By elevating these technical requirements to the boardroom, organizations ensure that cyber resilience is woven into the very fabric of the company’s long-term planning and risk management frameworks. This top-down support provides the political and financial resources that technical teams need to implement the robust and often expensive isolation measures required to survive.

Beyond budgeting and planning, the most critical role of leadership is determining the chain of command and the ultimate authority to pull the plug during a rapidly evolving intrusion. There must be no ambiguity about who has the power to disconnect a multi-billion-dollar infrastructure asset from the world, and this authority must be legally and operationally protected. Senior leaders participated in tabletop exercises alongside their technical teams to understand the pressure and the high-stakes trade-offs involved in these decisions. This shared understanding fostered a culture of trust and rapid communication, which was essential when every second counted during a state-sponsored cyberattack. The conclusion of these organizational efforts saw a marked shift in how infrastructure entities viewed their role as guardians of public safety. Leaders recognized that their digital choices had direct physical consequences for millions of people, leading to more robust investment in offline backups and manual control capabilities. By prioritizing operational survival over continuous connectivity, these organizations successfully transitioned to a more resilient posture that was better suited for the complexities of the modern threat landscape. These actions ensured that even in the face of unprecedented digital aggression, the essential services that power society remained resilient, secure, and ready to withstand the challenges of the coming decade.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later