← All stories
● Covered by 2 sources · 2 reportsMedium impact2 neutral

CISA and ACSC Release Guidance for Isolating Critical Infrastructure OT Systems During Attacks

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CISA and ACSC released joint guidance for critical infrastructure.
  • Guidance focuses on isolating OT systems during cyberattacks.
  • Aims to ensure continuity of essential services.
  • Addresses threats from state-sponsored cyber actors.
  • OT includes systems for water, electricity, manufacturing, transport.

New Guidance for Critical Infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Cyber Security Centre (ACSC) have published new guidance titled "CI Fortify – Advice for isolating vital systems." This document provides recommendations for critical infrastructure organizations on how to prepare for and execute the isolation of vital operational technology (OT) systems during cyberattacks or other major disruptions.

The guidance was developed in collaboration with the FBI and other international partners. Its primary goal is to help organizations maintain essential services by disconnecting critical OT and associated systems from corporate, internet-facing, and other less-trusted networks.

Understanding Operational Technology

Operational technology encompasses hardware and software used to monitor or control processes in various critical sectors. This includes systems for water treatment, electrical grids, manufacturing machinery, transportation networks, and telecommunications infrastructure.

The guidance emphasizes the importance of being able to operate these systems in isolation for extended periods to ensure continuity of critical services even when other networks are compromised.

Addressing Persistent Threats

The agencies highlight that state-sponsored threat actors routinely target critical infrastructure. These attacks often aim for espionage or to establish access that could be used for disruptive or destructive actions during a crisis or military conflict.

By isolating vital OT systems, organizations can disrupt malicious actors' ability to achieve their objectives, contain active incidents, and safely rebuild compromised systems.

Steps for Preparedness

The guidance advises critical infrastructure organizations to begin by identifying all systems and networks that support their critical services, as well as the customers dependent on this infrastructure. This foundational step is crucial for developing an effective isolation strategy.

The document is designed to assist OT owners, operators, and cybersecurity teams in improving their overall preparedness, response capabilities, and recovery processes in the face of cyber threats.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The US Cybersecurity and Infrastructure Security Agency (CISA) and Australia’s Cyber Security Centre (ACSC) have issued joint guidance for critical infrastructure organizations on how to isolate vital Operational Technology (OT) systems. This guidance aims to enhance cyber resilience and ensure continuity of critical services during disruptions by detailing methods for operating these systems in isolation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Cyber Security Centre (ACSC) have issued new guidance for critical infrastructure organizations on isolating operational technology (OT) systems during cyberattacks. This guidance aims to help organizations maintain essential services by disconnecting vital systems from less trusted networks, addressing the increasing threat of state-sponsored attacks on critical infrastructure.