US and Australian agencies publish playbook for cutting critical systems off in a crisis

New joint guidance tells power, water and transport operators how to run in isolation when a cyberattack or geopolitical crisis forces the plug to be pulled.

ThreatVectr Newsdesk· 4 min read
An industrial control room with AI dashboards and outdated equipment
Share

Key points

  • CISA, the Australian Cyber Security Centre, the FBI and international partners released joint guidance called CI Fortify aimed at critical infrastructure operators.
  • The document tells organisations how to cut vital operational systems off from other networks and keep them running alone for an extended period.
  • It walks operators through spotting critical systems, mapping how they connect to everything else, and putting hard separation points in place.
  • The guidance is a response to rising cyber threats against services like power, water, transport and healthcare.
  • No specific incident, group or ransom demand is named; this is preventive advice, not a breach notification.

A group of Western cyber agencies has published a step-by-step guide for keeping the lights on, literally, when a cyberattack hits critical services.

The document is called CI Fortify: Advice for isolating vital systems. It comes from the US Cybersecurity and Infrastructure Security Agency, known as CISA, and the Australian Signals Directorate's Australian Cyber Security Centre, working with the FBI and international partners.

The target audience is narrow but important: the companies that run power grids, water plants, ports, railways, pipelines and hospitals. In plain terms, the operators of the machinery that keeps modern life ticking.

What is the guidance actually telling operators to do?

It tells them to plan, in advance, how to disconnect their most vital equipment from the rest of the corporate network and the internet, then keep that equipment running on its own for a long stretch.

That matters because most critical services today are tangled up with ordinary IT. The control system for a water treatment plant might share a network with the email server, the billing database and a supplier's remote maintenance tool. If criminals get into any one of those, they can often reach the rest.

CI Fortify asks operators to work through three practical jobs. Identify which systems are truly vital, not just important. Map every connection into and out of them. Then build clear cut-off points, so those systems can be sealed off quickly and cleanly if something goes wrong.

Why publish this now?

Because attacks on critical infrastructure have kept climbing, and Western governments are openly worried about both criminal ransomware crews and state-backed hackers positioning themselves inside utilities.

Ransomware, which is malicious software that scrambles a victim's files until a payment is made, has already hit hospitals, pipelines and local water utilities in recent years. Separately, US officials have repeatedly warned that hackers linked to China and Russia have been quietly burrowing into energy and transport networks, apparently to be ready to cause disruption in a future crisis.

The CISA cybersecurity advisories page frames CI Fortify as advice for exactly that kind of scenario: a serious cyber incident, or a geopolitical flare-up, where an operator might have to yank vital systems off the wider network and run them manually for days or weeks.

What does this mean for ordinary customers?

Nothing changes today. There is no breach, no stolen data, no ransom demand attached to this announcement. It is guidance aimed at the engineers and executives who run essential services.

The practical upside, if operators follow it, is that a future cyberattack on a utility is less likely to cascade into a full outage. A water company that has rehearsed cutting its treatment plant off from its office network stands a much better chance of still delivering clean water while it cleans up an intrusion.

If you want a rough sense of the shape of the advice, it looks like this:

Step What operators are asked to do
1. Identify List the systems whose failure would stop essential services
2. Map Document every network link, remote access route and dependency
3. Separate Build and test physical or logical cut-off points
4. Sustain Plan to operate in isolation for an extended period

The agencies are not promising this will stop every attack. They are trying to make sure that when one lands, the damage stops at the fence.

© 2026 Threat Vectr