Validated Containment Architectures are here. →Explore

Executive Summary

On July 28, 2026, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with international partners, released the 'CI Fortify – Advice for Isolating Vital Systems' guidance. This document provides critical infrastructure organizations with practical steps to isolate essential operational technology (OT) and supporting systems from other networks during cyber incidents or periods of heightened threat. The guidance emphasizes identifying critical systems, mapping their connections, and implementing effective separation points to ensure continuity of essential services during disruptions.

The release of this guidance underscores the increasing cyber threats targeting critical infrastructure sectors. State-sponsored actors and cybercriminals are increasingly focusing on these sectors to conduct espionage or prepare for disruptive cyber activities. Implementing the recommended isolation strategies is vital for organizations to enhance their resilience and maintain operational continuity in the face of evolving cyber threats.

Why This Matters Now

The 'CI Fortify' guidance is crucial in the current landscape of escalating cyber threats against critical infrastructure. With state-sponsored actors and cybercriminals increasingly targeting these sectors, implementing effective isolation strategies is essential to safeguard essential services and national security.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The 'CI Fortify' guidance aims to help critical infrastructure organizations isolate vital operational technology and supporting systems from other networks during cyber incidents or periods of increased cyber threat, ensuring continuity of essential services.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial access may have been constrained by enforcing strict access controls and segmenting internet-facing services from critical infrastructure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing least-privilege access and segmenting OT systems from other network areas.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement would likely be constrained by monitoring and controlling east-west traffic between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control channels may have been detected and disrupted by providing comprehensive visibility and control over network traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts could have been limited by enforcing strict egress policies and monitoring outbound traffic.

Impact (Mitigations)

The attacker's ability to disrupt critical services would likely be reduced by limiting their access to essential systems and enforcing strict segmentation.

Impact at a Glance

Affected Business Functions

  • Operational Technology (OT) Management
  • Critical Service Delivery
  • Incident Response
  • Business Continuity Planning
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

n/a

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within the network.
  • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts.
  • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic.
  • Establish Multicloud Visibility & Control to detect anomalous activities across environments.
  • Apply East-West Traffic Security to secure internal communications and prevent unauthorized access.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image