Security News

Cybersecurity news aggregator

đź“°
INFO News SecurityWeek

US, Australia Release OT Isolation Guidance for Critical Infrastructure

  • What: US and Australia release OT isolation guidance for critical infrastructure
  • Impact: Helps critical infrastructure operators improve cyber resilience
Read Full Article →

ICS/OT US, Australia Release OT Isolation Guidance for Critical Infrastructure The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. By Ionut Arghire | July 29, 2026 (6:58 AM ET) Flipboard Reddit Whatsapp Whatsapp Email The US cybersecurity agency CISA and Australia’s Cyber Security Centre (ACSC) have published joint guidance detailing how critical infrastructure (CI) organizations can isolate vital OT and supporting systems. Aimed at boosting cyber resilience, the CI Fortify – Advice for isolating vital systems guidance also includes details on how these systems can be operated in isolation for long periods, to ensure the continuity of critical services in case of disruption or crisis. The document is designed to help OT owners, operators, and cybersecurity teams improve their preparedness, response, and recovery. “In response to persistent threats, CI operators should have the capability to isolate vital OT and enabling systems from all other networks to ensure continuity of critical services. Isolating vital OT and enabling systems can disrupt the ability of malicious cyber actors to achieve their goal, contain active incidents, and allow for safe rebuilding of compromised systems,” the guidance reads. CI organizations should start by identifying all systems and networks supporting critical services, as well as customers that depend on critical infrastructure. Next, they should identify the common levels of criticality and trust for systems and networks, and determine how they should be grouped in segments and zones to manage risk and apply controls better. Advertisement. Scroll to continue reading. After identifying and classifying vital systems and networks, organizations should identify and record the connections between them and other systems, such as non-critical corporate systems, vendor remote access, untrusted networks, cloud environments, and peer critical networks. For each connection, critical technical information should be documented and periodically updated. “It is important to note that isolating systems will trigger manual processes and interrupt system-to-system communication. This can impact connections to upstream dependencies and peers, such as other utilities and scheduler or dispatch operators. Organizations should identify and work through critical dependencies with impacted peers and partners as part of their isolation planning,” the guidance reads. CI operators should also build effective separation and isolation points between critical and non-critical services and networks, to limit threat actors’ ability to reach vital systems. These isolation points also help with containment and remediation and limit the impact an intrusion has on operations. “Planned physical separation of vital systems from all other networks and systems is a pre-requisite for physical isolation. Organizations must build physical isolation points into their vital systems to enable the capability to operate in a state of isolation from all other networks and systems,” the guidance reads. Finally, organizations should create, test, and review a graduated plan for isolation that enables them to progressively isolate pathways to vital systems while maintaining business continuity. CI operators are also advised to monitor the effectiveness of the isolation mechanisms throughout the isolation period, to ensure that no connection between critical and non-critical networks occurs. CISA and ACSC also detail the operational and security risks that adopting CI Fortify introduces, such as a lack of patching, reduced external visibility, and an increased risk of infection via removable media, and advise organizations to account for them when operating in isolation. Additional resources for CI operators can be found on CISA’s CI Fortify: Strengthening Resilience Across Critical Infrastructure page. Related: NIST Opens Updated IoT Security Guidance to Public Review Related: CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk Related: G7 Countries Release AI SBOM Guidance Related: Global Cyber Agencies Issue AI Security Guidance for Critical Infrastructure OT Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Hush Security Raises $30 Million for AI Agent Governance Google Adopts New Threat Actor Naming System Unpatched Fastjson Vulnerability Exploited in Attacks Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day New GitHub, PyPI Policies Boost Supply Chain Security PTC Windchill Vulnerability Exploited in Ransomware Campaign Beelzebub Raises $3.4 Million for Hacker-Trapping Platform Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials Latest News OpenAI’s Rogue AI Ventured Beyond Hugging Face Spur Raises $200 Million for IP Intelligence Platform JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks ShinyHunters Claims Ernst & Young Hack Cyera Acquiring Oasis Security in $1 Billion Deal Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe OT Security Startup Frenos Raises $1.52 Million Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer. John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox. Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer. More People On The Move Expert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email

Share this article