US and Australia Publish Joint Playbook for Cutting Critical Infrastructure Off From Cyber Attack
New guidance tells power plants, water utilities, and other essential services how to keep running even when their networks are under attack or must be disconnected entirely.

Key points
- The United States and Australia jointly released guidance telling critical-infrastructure operators how to isolate operational technology systems during a cyber attack.
- OT, the computers and control systems that physically run equipment such as pumps and power grids, is distinct from ordinary office IT.
- The document covers both the isolation steps and how to keep essential services running for an extended period without normal network connections.
- No specific incident triggered the release, though ransomware attacks on industrial targets have risen sharply over the past three years.
What did the two governments actually publish?
A joint advisory from the US and Australia tells operators of critical infrastructure exactly how to cut their control systems off from outside networks when a cyber attack begins, then keep those systems running alone.
The guidance centres on OT, short for operational technology: the hardware and software that directly controls physical processes. When ransomware, malicious software that locks files and demands payment to restore access, hits an OT network, the consequences reach beyond lost data. Taps can run dry. Hospital generators can go dark.
The document lays out steps for network isolation, meaning deliberately disconnecting a facility's control systems from the internet and corporate networks so attackers can't spread further or send commands. It then addresses how a site can keep operating in that isolated state, because simply pulling the plug isn't an option when a city's water supply is at stake. We covered the same joint publication on 28 July 2026, and our 16 July story on ageing industrial control systems explains why isolation is harder in practice than any checklist suggests.
Why does this matter right now?
Ransomware gangs have increasingly shifted attention toward industrial targets. Attacks on critical infrastructure aren't just about extortion money; they create public-safety pressure that operators argue forces faster payment. SecurityWeek noted the guidance specifically addresses this pressure point by giving sites a credible plan to operate without paying.
Several prominent ransomware groups, including ones operating under the Ransomware-as-a-Service model where criminal developers rent their attack tools to affiliates in exchange for a cut of ransoms, have listed water authorities and energy firms on their public leak sites in recent years.
| Sector | Why OT isolation matters |
|---|---|
| Water and wastewater | Treatment chemicals controlled by OT; wrong doses harm public health |
| Electricity generation | Grid-control systems; outages cascade across hospitals and homes |
| Oil and gas pipelines | Pressure and valve systems; safety risk if tampered with |
| Manufacturing | Production lines; ransomware can halt output for weeks |
The guidance names no triggering incident. It's a standing instruction manual that facility managers can rehearse before an attack arrives. That's the point: a plan rehearsed is worth ten plans filed in a drawer.
What should ordinary people take from this?
You won't notice anything from this guidance directly. What it means in practice is that the operators keeping your taps and lights working now have an official checklist for the moment attackers try to hold those services hostage.
If your area experiences a utility disruption tied to a cyber attack, the usual advice holds: keep a few days of bottled water on hand, know where your circuit breaker is, and follow local emergency services rather than social media.



