The US agency CISA has released the guidance “CI Fortify” together with Australia’s ACSC, the FBI, and international partners.
It is meant to help critical infrastructure operators disconnect vital OT systems from the internet and corporate networks in a targeted way during a crisis. The background is repeated attacks by state-sponsored groups such as Volt Typhoon and Salt Typhoon, which, according to the agencies, remained undetected for years in critical infrastructure networks, including at major US telecommunications providers. Water utilities have also already been affected, including American Water and a water treatment facility in Kansas. The guidance is meant to help organizations prepare before an incident occurs, rather than improvising while one is already underway.
CISA: Physical and graduated isolation
The guidance recommends first identifying the minimum systems needed for a critical service and documenting all their connections to corporate networks, cloud services, vendors, and the internet. As the most effective protection, the guidance names complete physical separation, or alternatively a graduated isolation in which access is restricted step by step depending on the threat level. Where physical isolation is not practical, for example due to cloud dependencies, the agencies advise hardened network boundaries and dedicated connections.
Regular testing and operating in an isolated state
Isolation plans should be tested in full on a regular basis, since partial tests often fail to reveal hidden dependencies. The guidance also recommends keeping an offline copy of the plan, as well as the ability to operate, monitor, and update systems manually during isolation until a secure reconnection is possible.
(red)