CI Fortify: six steps to isolate vital OT systems in a crisis

The Australian Signals Directorate (ASD) published the CI Fortify guidance on 28 July 2026, developed with international partners. The guidance explains how organisations can isolate vital operational technology (OT) and enabling systems from all other networks during cyber incidents or periods of increased cyber threat. The purpose ASD states is the ability to maintain critical services during a crisis or a service disruption. The audience is OT owners and operators, and the cyber defenders who protect them. The guidance points to equivalent introductory material from CISA in the United States, NCSC in the United Kingdom and the Canadian Centre for Cyber Security.

What happens technically

Operational technology is the set of systems that control physical processes, for example in power supply, water treatment and industrial plants. CI Fortify describes what ASD calls the critical path to isolation, and it consists of six steps. The first step is to identify the vital systems and networks, meaning the minimum set required to deliver the critical service. The second step is to identify critical customers, such as military infrastructure and lifeline services, and to set a service delivery target based on their needs. The third step groups hosts and systems into zones with a common level of criticality and threat exposure. The fourth step maps and records every point of interconnection between the critical networks and everything else, including corporate systems, vendor remote access, the internet, cloud environments and peer critical networks. The fifth step builds the separation and isolation points themselves. The sixth step creates and tests an isolation plan.

ASD distinguishes physical separation from isolation. Physical separation means that OT networks share no active infrastructure with other networks, neither switches, routers, repeaters, multiplexers nor compute elements. Isolation is the ability to disconnect and keep operating independently. What breaks in practice is the dependencies, and the guidance names them: common identity services, name resolution and address assignment, shared virtualisation, shared storage, backup and time synchronisation drawn from corporate or internet sources. ASD requires such dependencies to be reduced and eliminated, otherwise the critical service stops the moment the connection is cut. Administrative controls such as VLANs and MPLS are described as minimally effective and only as an interim measure, and ASD writes that MPLS provides no assurance of segregation. Where physical isolation is not feasible, the guidance points to dedicated fibre pairs or dedicated CWDM wavelengths, and to strong encryption performed by a dedicated device rather than the encryption built into OT equipment. Once isolation is in force, routing tables and traffic flows must be monitored so that unintended reconnection is detected. ASD also names the price: systems fall out of patch, external visibility is reduced, and removable media becomes a larger infection route.

mapped connectionsCorporate and internetvendors, peer networksIsolation pointcut in a crisisconnection cutVital OT systemsrunning without other networkslocal directory, time and backup
Figure: The isolation point sits between the mapped connections and the vital OT systems, and it assumes that directory, time and backup services exist locally.

What this means for you if you own or operate OT networks

If you work in power, water, transport or industry, you will recognise the problem, but not necessarily the cost. Most Norwegian OT environments are built for efficient operation, not to stand alone. Remote monitoring, central sign-in and vendor remote access are exactly what keeps your operating costs down. Those are the same connections you have to be able to sever. Our assessment is that the mapping in the fourth step is the work most organisations are missing, and that it carries value on its own. If you do not know which connections enter your critical network, you cannot cut them in a controlled way either.

If your organisation is covered by NIS2, this lands in the middle of the continuity and crisis management requirements in Article 21. The ability to isolate is a concrete way of demonstrating that the requirement is met. ASD's admission that full physical isolation is not always achievable matters for Norwegian conditions. Many facilities are spread across long distances and depend on leased communications links. Your work then shifts from separation to hardening the boundary around OT, and to encryption across links you do not own. The graduated plan is also a point worth taking to your board. Isolation is not a single switch, but a series of steps with defined trigger criteria, and those criteria have to be decided before the crisis arrives.

Berigo recommends

  • Map and document every point of interconnection into the critical networks, including vendor remote access, cloud services and connections to peer organisations. Keep the list current through change management.
  • Find the dependencies that make isolation impossible today, typically directory services, name resolution, time synchronisation and backup, and build local replacements inside the OT network.
  • Create a graduated isolation plan with defined trigger criteria, and tie it to the incident response plan. The criteria are decided before the crisis, not during it.
  • Exercise the plan, and exercise the isolation of all vital systems at once. Testing a single system will not reveal the dependencies between systems.
  • Keep a hard copy of the isolation plan as well, and plan for how the organisation will handle missing updates and reduced visibility for as long as the isolation lasts.

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch