CI Fortify – Advice for Isolating Vital Systems (CISA/ASD Joint Guidance)
First seen Jul 29, 2026 · Updated Jul 29, 2026
CISA and the Australian Cyber Security Centre, alongside the FBI and international partners, released joint guidance titled 'CI Fortify' to help critical infrastructure organizations isolate vital operational technology and enabling systems during disruptions or crises. The guidance is a proactive best-practice advisory rather than a response to a specific active threat, focusing on network mapping, segmentation, and sustained isolated operations.
Technical Analysis
This is a defensive guidance document, not a disclosed vulnerability or active exploitation event; it provides a framework for identifying critical OT and IT-enabling systems, mapping interdependencies and network connections, and establishing separation points to allow isolated operation during cyber incidents or geopolitical crises. The guidance addresses architectural risks common in converged IT/OT environments, such as excessive network flatness, undocumented dependencies, and lack of tested isolation procedures. No specific CVEs, malware, or exploitation techniques are referenced. Organizations running AI agents or LLM-based automation within OT/critical infrastructure environments (e.g., agents used for monitoring, anomaly detection, or SCADA interfacing) should ensure these agent systems and their credentials/API access are included in isolation planning, since agent connectivity to external services or cloud LLM APIs could become an unmanaged bridge across intended segmentation boundaries during a crisis.
Affected Systems
Operational technology (OT) environments, industrial control systems (ICS), SCADA systems, and IT systems that support or enable critical infrastructure operations, particularly those with interconnections to broader enterprise or external networks
Indicators of Compromise
- None (this is a best-practice advisory document, not an incident report)
Remediation Steps
- 1
Identify critical systems
Inventory and classify vital OT and enabling systems required to maintain essential operations during a crisis.
- 2
Map network connections
Document all data flows, dependencies, and connections between critical systems and other networks, including any AI/agent tooling with external API access.
- 3
Implement separation points
Design and deploy segmentation controls (firewalls, air gaps, data diodes) that allow critical systems to be isolated on demand.
- 4
Test isolated operation
Conduct exercises to validate that critical systems can operate independently for extended periods without external connectivity.
- 5
Include automation and agent systems in planning
Ensure any AI agents, automation scripts, or LLM-integrated tools used in OT/IT environments are accounted for in isolation and credential-management plans.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.