CISA presents a six-step guide to isolate critical infrastructure during cyber attacks

Share

Key Points

  • Six‑step blueprint from CISA helps isolate critical infrastructure during cyberattacks.
  • Guide stresses zero connectivity between OT and non‑OT networks and dedicated encryption over carrier links.
  • IT admins and OT operators should map vital systems, build isolation points, and test the plan regularly.

What is changing

CISA, together with Five Eyes partners, released the CI Fortify guide that outlines a six-step guide for locking down vital systems when an attack occurs. The steps start with identifying the minimum set of systems needed to keep essential services running and mapping all connections to those systems. It also urges organizations to record technical details such as firewall rules, router settings, and VPN configurations for each interconnection.

The guide calls for creating zero connectivity between OT networks and any non‑OT infrastructure, meaning no shared switches, routers, or compute resources. It also advises using a dedicated encryption device over carrier links instead of relying on built‑in OT encryption, and recommends encrypting Layer 2 and Layer 3 services while disabling unnecessary services.

Why it matters

This advice matters most to IT admins and OT engineers who manage power, water, or other critical services in enterprise environments. They will need to document interconnections, apply VLANs or MPLS segmentation, and regularly test isolation procedures to avoid surprise downtime. They should also examine shared services such as Active Directory, DNS, and certificate authority systems that could affect isolation.

Following the blueprint can improve operational continuity during an incident, though the effort is greatest for organizations with large, distributed OT footprints where full physical isolation may not be feasible. In those cases, strong encryption and dedicated paths become the practical fallback. A gradual approach that first cuts remote worker jump‑host access, then corporate remote links, and finally full OT separation helps maintain business continuity while reducing risk.

Share your experiences implementing isolation steps in the comments below.

Read the original source.


Discover more from Windows Mode

Subscribe to get the latest posts sent to your email.