Validated Containment Architectures are here. →Explore

Executive Summary

In July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Australian Cyber Security Centre (ACSC) and other international partners, released the 'CI Fortify – Advice for isolating vital systems' guidance. This document provides critical infrastructure organizations with strategies to isolate essential operational technology (OT) systems from less secure networks during cyber incidents, ensuring the continuity of essential services. The guidance emphasizes proactive planning, including identifying vital systems, documenting network connections, and establishing isolation points to prevent lateral movement by threat actors.

The release of this guidance underscores the increasing targeting of critical infrastructure by state-sponsored threat actors and cybercriminals. Recent incidents, such as the prolonged undetected presence of the Chinese Volt Typhoon group in U.S. critical infrastructure networks, highlight the urgent need for organizations to enhance their cyber resilience by preparing to isolate vital systems effectively.

Why This Matters Now

With the rising frequency and sophistication of cyberattacks on critical infrastructure, the 'CI Fortify' guidance provides timely strategies for organizations to protect essential services by isolating vital systems during incidents, thereby mitigating potential disruptions and ensuring operational continuity.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The 'CI Fortify' guidance aims to help critical infrastructure organizations prepare to isolate vital operational technology systems from less secure networks during cyber incidents, ensuring the continuity of essential services.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to exploit vulnerabilities, escalate privileges, and move laterally within the network, thereby reducing the overall blast radius.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit vulnerabilities in internet-facing devices would likely be constrained, reducing the likelihood of initial access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the scope of unauthorized access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement within the network would likely be constrained, reducing the reach to operational technology systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the effectiveness of compromised routers.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing data loss.

Impact (Mitigations)

The attacker's ability to disrupt critical services would likely be constrained, reducing operational impact.

Impact at a Glance

Affected Business Functions

  • Energy Distribution
  • Water Treatment
  • Transportation Systems
  • Telecommunications Infrastructure
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive operational data and network credentials.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within the network.
  • Deploy East-West Traffic Security to monitor and control internal communications.
  • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Establish Multicloud Visibility & Control to detect and respond to anomalous activities.
  • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image