Originally published on CyberNetSec.
Executive Summary
On July 30, 2026, a coalition of cybersecurity agencies from the Five Eyes intelligence alliance (U.S., U.K., Australia, Canada, New Zealand) and other international partners released joint guidance titled 'CI Fortify – Advice for Isolating Vital Systems.' This document provides a practical framework for Critical Infrastructure (CI) operators to enhance their resilience by isolating their most critical Operational Technology (OT) systems. The guide's primary objective is to ensure that essential services can continue to function safely, even if the broader corporate IT network is compromised in a significant cyber event. The guidance emphasizes identifying critical systems, mapping all network connections, and implementing robust separation to enable sustained, isolated operations.
Regulatory Details
'CI Fortify' is advisory guidance, not a binding regulation. However, it represents a consensus view from the leading cybersecurity authorities of the Five Eyes nations. As such, it will serve as a de facto standard and best practice benchmark for CI operators globally. Regulators in these countries will likely incorporate the principles of 'CI Fortify' into their sector-specific requirements for energy, water, transportation, and other critical industries. Adherence to this guidance will be seen as a key indicator of a mature cybersecurity posture for any CI organization.
Affected Organizations
The guidance is explicitly aimed at all owners and operators of critical infrastructure. This includes, but is not limited to, organizations in the following sectors:
- Energy (Electricity, Oil & Gas)
- Water and Wastewater Systems
- Transportation Systems
- Healthcare and Public Health
- Manufacturing
- Communications
- Government Facilities
Compliance Requirements
To align with the 'CI Fortify' guidance, CI operators need to implement a structured program focused on resilience through isolation. The key requirements include:
- System Identification: Identify the most vital OT systems—those that are absolutely essential for maintaining the safe, continuous delivery of services.
- Connection Mapping: Conduct a thorough analysis to map every single network connection to and from these vital systems. This includes connections to the IT network, the internet, third-party vendors, and other OT segments.
- Isolation & Separation: Implement technical controls to enforce the logical and physical separation of these vital systems. This involves re-architecting networks to eliminate unnecessary connections and strictly controlling all remaining data flows through firewalls and unidirectional gateways.
- Resilience Planning: Develop and test incident response and business continuity plans that assume a complete loss of the IT network. The plans must detail how the vital OT systems will continue to operate in an isolated mode for an extended period.
Implementation Timeline
There is no mandated timeline for implementation. However, given the escalating threats against critical infrastructure (such as the recent attacks on Minnesota water utilities), CI operators are expected to begin assessing their posture against this guidance immediately. Regulators may begin asking for implementation plans in the near future.
Compliance Guidance
- Start Small: Begin by identifying a single, vital process and the OT systems that support it. Use this as a pilot project for applying the 'CI Fortify' principles.
- Assume Breach: Design your OT network architecture with the assumption that the IT network is already compromised. Ask the question: 'If our corporate network is down, can we still safely operate our essential function?'
- Use the Purdue Model: The guidance aligns with established industrial control system security frameworks like the Purdue Enterprise Reference Architecture, which provides a model for segmenting IT and OT networks.
- Test and Drill: Regularly test your ability to operate in an isolated mode. These drills will identify gaps in your plans, tools, and training that need to be addressed.
Top comments (0)