Executive Summary
On July 28, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with international partners, released the 'CI Fortify – Advice for Isolating Vital Systems' guidance. This document provides critical infrastructure organizations with practical steps to isolate essential operational technology (OT) and supporting systems from other networks during cyber incidents or periods of heightened threat. The guidance emphasizes identifying critical systems, mapping their connections, and implementing effective separation points to ensure continuity of essential services during disruptions.
The release of this guidance underscores the increasing cyber threats targeting critical infrastructure sectors. State-sponsored actors and cybercriminals are increasingly focusing on these sectors to conduct espionage or prepare for disruptive cyber activities. Implementing the recommended isolation strategies is vital for organizations to enhance their resilience and maintain operational continuity in the face of evolving cyber threats.
Why This Matters Now
The 'CI Fortify' guidance is crucial in the current landscape of escalating cyber threats against critical infrastructure. With state-sponsored actors and cybercriminals increasingly targeting these sectors, implementing effective isolation strategies is essential to safeguard essential services and national security.
Attack Path Analysis
An adversary exploited a misconfigured internet-facing service to gain initial access to the critical infrastructure network. They then escalated privileges by exploiting a vulnerability in the operational technology (OT) systems. Utilizing these elevated privileges, the attacker moved laterally across the network to access vital systems. They established command and control channels to maintain persistent access and exfiltrated sensitive data. Finally, the adversary disrupted critical services, causing significant operational impact.
Kill Chain Progression
Initial Compromise
Description
The adversary exploited a misconfigured internet-facing service to gain unauthorized access to the critical infrastructure network.
MITRE ATT&CK® Techniques
Block Operational Technology Message
Block Operational Technology Message: Command Message
Block Operational Technology Message: Reporting Message
Block Communications
Block Communications: Serial COM
Block Communications: Ethernet
Block Communications: Wi-Fi
Denial of Control
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Boundary Protection
Control ID: SC-7
PCI DSS 4.0 – Restrict Inbound and Outbound Traffic
Control ID: 1.2.1
NYDFS 23 NYCRR 500 – Limitations on Data Retention
Control ID: 500.13
DORA – ICT Risk Management Framework
Control ID: Article 5
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Identity
Control ID: Pillar 1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical infrastructure isolation guidance directly targets utilities' operational technology systems, requiring zero trust segmentation and encrypted traffic controls for vital system protection.
Oil/Energy/Solar/Greentech
Energy sector operational technology networks need immediate isolation capabilities and multicloud visibility controls to prevent lateral movement during escalating cyber threats.
Transportation
Transportation infrastructure requires robust east-west traffic security and threat detection systems to maintain essential services during geopolitical crises and cyber incidents.
Telecommunications
Telecom networks face Salt Typhoon threats requiring encrypted traffic controls, egress security enforcement, and secure hybrid connectivity for critical communication infrastructure protection.
Sources
- CI Fortify – Advice for isolating vital systemshttps://www.cisa.gov/resources-tools/resources/ci-fortify-advice-isolating-vital-systemsVerified
- CISA launches critical infrastructure cyber resilience initiativehttps://www.techtarget.com/healthtechsecurity/news/366642825/CISA-launches-critical-infrastructure-cyber-resilience-initiativeVerified
- CISA’s “CI Fortify” Initiative Signals New Expectations for Critical Infrastructure Resilience: What Operators and Vendors Need to Knowhttps://www.crowell.com/en/insights/client-alerts/cisas-ci-fortify-initiative-signals-new-expectations-for-critical-infrastructure-resilience-what-operators-and-vendors-need-to-knowVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained by enforcing strict access controls and segmenting internet-facing services from critical infrastructure.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing least-privilege access and segmenting OT systems from other network areas.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be constrained by monitoring and controlling east-west traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels may have been detected and disrupted by providing comprehensive visibility and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could have been limited by enforcing strict egress policies and monitoring outbound traffic.
The attacker's ability to disrupt critical services would likely be reduced by limiting their access to essential systems and enforcing strict segmentation.
Impact at a Glance
Affected Business Functions
- Operational Technology (OT) Management
- Critical Service Delivery
- Incident Response
- Business Continuity Planning
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Establish Multicloud Visibility & Control to detect anomalous activities across environments.
- • Apply East-West Traffic Security to secure internal communications and prevent unauthorized access.



