> Back to All Posts

CISA Critical Infrastructure Guidance: Plan the Cutoff Now

CISA Critical Infrastructure Guidance

Water treatment plants, power grids, and telecom networks run on equipment that predates the modern internet. Most of it now connects to corporate systems, cloud platforms, and outside vendors anyway. The new CISA critical infrastructure guidance addresses that reality head on. Rather than promising to keep intruders out, it asks operators a harder question: can you disconnect fast enough to keep the service running?

The advisory goes by the name “CI Fortify – Advice for isolating vital systems.” CISA produced it alongside the FBI, the Australian Signals Directorate’s Australian Cyber Security Centre, and several international partners. Together, they want operators to decide where the disconnection points sit long before an attacker forces the decision.

What the Advisory Asks Operators to Do

The core instruction sounds simple, but the work behind it is substantial. Each organization must identify the smallest possible set of systems needed to keep delivering its service. Everything else counts as optional during a crisis.

Then comes the mapping exercise. Teams need to document every link between those vital systems and the rest of the environment. That includes corporate networks, remote access tools, cloud services, internet-facing infrastructure, contractors, and neighbouring utilities. Each link also needs a defined point where someone can sever it.

CISA and its partners push teams to think past the moment of disconnection, too. What manual processes take over? Which communication channels drop out? Who supplies the data and parts that normally arrive over the network? Answering those questions mid-attack wastes time nobody has.

How the CISA Critical Infrastructure Guidance Defines Isolation

The advisory sets out a shared vocabulary so operators and executives can plan without talking past each other. These are the terms that matter most:

  • Vital systems. The minimum operational technology needed to deliver a critical service, such as controlling water distribution or keeping electricity flowing.
  • Isolation point. A predetermined place where critical and non-critical networks can be split apart, blocking an attacker from moving sideways.
  • Physical isolation. Complete disconnection, with no shared network or computing infrastructure. The agencies rate this as the strongest form of protection.
  • Graduated isolation. A staged retreat. Operators first cut off remote workers and vendors, then corporate networks, then external connections.
  • Administrative controls. Changes to VLANs, access control lists, and routing. These help temporarily, but they should not replace a physical break.
  • Data diode. Hardware that permits traffic in one direction only, so nothing malicious travels back the other way.

Once a plan exists, testing decides its value. The advice is to rehearse full isolation rather than checking systems one at a time. Partial tests hide shared infrastructure and quiet dependencies, and those surprises surface at the worst possible moment.

Why the Warning Arrives Now

State-backed groups have spent years quietly settling into these networks. In February 2024, Five Eyes agencies confirmed that the Chinese group Volt Typhoon had breached communications, energy, transportation, and water organizations. Investigators found the intruders had gone undetected inside one network for five years.

Salt Typhoon, another Chinese state-linked group, has worked through government, telecom, transport, lodging, and military targets since at least 2021. The group reached major U.S. carriers including AT&T, Verizon, and Lumen, gaining access to sensitive communications and law enforcement wiretap systems. Unpatched edge devices gave the hackers their entry point, and trusted connections carried them deeper.

Water utilities have taken repeated hits as well. American Water, which serves more than 14 million people, shut down parts of its environment after an attack in October 2024. A Kansas treatment facility reverted to manual operations around the same period. Pro-Russian hacktivists, meanwhile, keep scanning for exposed control systems at smaller water sites.

When Full Disconnection Is Not Realistic

Physical isolation works best, yet plenty of operators cannot achieve it. Carrier networks, cloud dependencies, internet-facing services, and sites spread across a region all make a clean break impractical.

For those environments, the CISA critical infrastructure guidance offers a fallback. Harden the boundaries around operational technology. Use dedicated or encrypted links for essential traffic. Strip out any reliance on corporate systems that is not truly needed. Above all, keep the ability to rebuild systems quickly.

Governance matters just as much as engineering. A plan should name who authorizes each stage, what conditions trigger it, which systems must stay live, and how operations continue without normal connectivity. Storing an offline or printed copy protects the plan when file servers go dark.

The Trade-Offs of Running Isolated

Cutting the cord solves one problem and creates others. Isolated systems fall behind on patches. Monitoring coverage thins out. Staff start moving data on USB drives, which reintroduces risk through the back door.

So the guidance frames isolation as a mode of operation, not a single action. Operators have to run, watch, and update those systems by hand until reconnection becomes safe. Post-isolation checks on routing tables, traffic flows, and intrusion detection confirm that no forgotten link has quietly restored the bridge.

Final Thoughts

The premise behind this CISA critical infrastructure guidance deserves attention well beyond utility control rooms. Regulators now assume attackers will get in, so the measure of resilience becomes containment speed rather than perimeter strength.

That thinking scales down. Home networks, small businesses, and remote workers all benefit from knowing which connections they can drop without losing anything essential. Segmentation, encrypted links, and reduced exposure are the same principles at a smaller size. Utilities are simply the ones with a public deadline.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.