Executive Summary
In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Australian Cyber Security Centre (ACSC) and other international partners, released the 'CI Fortify – Advice for isolating vital systems' guidance. This document provides critical infrastructure organizations with strategies to isolate essential operational technology (OT) systems from less secure networks during cyber incidents, ensuring the continuity of essential services. The guidance emphasizes proactive planning, including identifying vital systems, documenting network connections, and establishing isolation points to prevent lateral movement by threat actors.
The release of this guidance underscores the increasing targeting of critical infrastructure by state-sponsored threat actors and cybercriminals. Recent incidents, such as the prolonged undetected presence of the Chinese Volt Typhoon group in U.S. critical infrastructure networks, highlight the urgent need for organizations to enhance their cyber resilience by preparing to isolate vital systems effectively.
Why This Matters Now
With the rising frequency and sophistication of cyberattacks on critical infrastructure, the 'CI Fortify' guidance provides timely strategies for organizations to protect essential services by isolating vital systems during incidents, thereby mitigating potential disruptions and ensuring operational continuity.
Attack Path Analysis
State-sponsored actors exploited vulnerabilities in internet-facing devices to gain initial access to critical infrastructure networks. They escalated privileges by leveraging stolen credentials and exploiting misconfigurations. The attackers moved laterally within the network, targeting operational technology systems. They established command and control channels using compromised routers to proxy traffic. Sensitive data was exfiltrated through covert channels. The attack culminated in disruptive actions against critical services.
Kill Chain Progression
Initial Compromise
Description
State-sponsored actors exploited vulnerabilities in internet-facing devices to gain initial access to critical infrastructure networks.
MITRE ATT&CK® Techniques
Valid Accounts
External Remote Services
Exploitation of Remote Services
Application Layer Protocol
Impair Defenses
Network Denial of Service
Service Stop
Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Network Segmentation
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
State-sponsored APT groups like Salt Typhoon compromised major telecoms infrastructure, requiring zero trust segmentation and encrypted traffic controls for critical communications systems.
Utilities
Water treatment facilities and electrical systems face operational technology isolation requirements during state-sponsored attacks, demanding egress security and anomaly detection capabilities.
Government Administration
CISA guidance targets federal infrastructure protection against Chinese APT groups, necessitating multicloud visibility and east-west traffic security for sensitive government networks.
Transportation
Transportation infrastructure repeatedly targeted by Volt Typhoon requires hybrid connectivity security and Kubernetes protection for modern containerized control systems and operational technology.
Sources
- CISA shares advice on isolating vital systems during cyberattackshttps://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/Verified
- China-backed Volt Typhoon hackers have lurked inside US critical infrastructure for ‘at least five years’https://techcrunch.com/2024/02/07/china-backed-volt-typhoon-hackers-have-lurked-inside-us-critical-infrastructure-for-at-least-five-years/Verified
- Chinese state hackers infect critical infrastructure throughout the US and Guamhttps://arstechnica.com/information-technology/2023/05/chinese-state-hackers-infect-critical-infrastructure-throughout-the-us-and-guam/Verified
- Chinese hackers targeting U.S. critical infrastructurehttps://www.techtarget.com/searchsecurity/news/366538556/Chinese-hackers-targeting-US-critical-infrastructureVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to exploit vulnerabilities, escalate privileges, and move laterally within the network, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities in internet-facing devices would likely be constrained, reducing the likelihood of initial access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network would likely be constrained, reducing the reach to operational technology systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the effectiveness of compromised routers.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing data loss.
The attacker's ability to disrupt critical services would likely be constrained, reducing operational impact.
Impact at a Glance
Affected Business Functions
- Energy Distribution
- Water Treatment
- Transportation Systems
- Telecommunications Infrastructure
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive operational data and network credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy East-West Traffic Security to monitor and control internal communications.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Establish Multicloud Visibility & Control to detect and respond to anomalous activities.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.



