The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Australia’s Cyber Security Centre (ACSC), the FBI, and international partners have published new guidance urging critical infrastructure (CI) operators to prepare, before an incident occurs, to isolate vital operational technology (OT) from corporate and internet-facing networks.

The advisory, titled “CI Fortify: Advice for Isolating Vital Systems,” targets organizations that run OT used to monitor or control essential processes such as water treatment, electrical distribution, manufacturing, transportation, and telecommunications. The agencies warn that state-sponsored actors routinely target this infrastructure both for espionage and to pre-position access that could be leveraged for disruptive or destructive attacks during a future crisis or military conflict.

The guidance directly references recent nation-state activity. CISA and Five Eyes partners previously disclosed that China-linked Volt Typhoon actors remained undetected inside at least one critical infrastructure network for five years, positioning for potential disruption. Separately, Salt Typhoon, another China-linked group, has breached telecommunications, government, transportation, lodging, and military networks globally since at least 2021, including major U.S. telecom providers, by exploiting known vulnerabilities in edge networking devices and pivoting through trusted connections.

Water infrastructure has also been a recurring target. American Water, which serves more than 14 million customers, deactivated systems following a 2024 cyberattack, and a Kansas water treatment facility switched to manual operations after a compromise. Officials have also flagged pro-Russian hacktivists actively scanning for unsecured OT at water utilities and other CI operators.

What the guidance recommends

Rather than improvising isolation during an active incident, CI Fortify calls on organizations to plan ahead by:

  • Identifying the minimum systems and networks required to sustain a critical service
  • Mapping every connection between those systems and corporate networks, remote access services, cloud environments, internet-facing infrastructure, vendors, and other CI partners
  • Determining where those connections can be physically or logically disconnected
  • Accounting for the manual processes, communication gaps, and loss of external dependencies that isolation would trigger

The advisory introduces standard terminology for planning purposes, including “vital systems” (the minimum OT needed to deliver a critical service) and “isolation points” (predetermined locations where connectivity between trusted and untrusted networks can be severed to contain an attack).

The joint effort reflects a broader push by CISA and international partners to harden critical infrastructure resilience against both opportunistic cybercriminal extortion and sustained nation-state targeting.