Decoding the world of cybersecurity

Operational safety sets the boundary for OT isolation

International guidance urges critical operators to prepare emergency isolation while accounting for the monitoring, communications, and support services required to continue operating safely.

Operational safety sets the boundary for OT isolation
Summary
  • CI Fortify guidance recommends identifying vital systems and preparing physical or cryptographic isolation methods.
  • Operators must map connections involving suppliers, cloud services, carriers, remote access, and corporate infrastructure.
  • Isolation plans must preserve essential operations while accounting for lost visibility, manual processes, delayed updates, and difficult reconnection.

Critical-infrastructure operators are being advised to prepare the physical and cryptographic means to isolate vital operational systems during severe cyber incidents, while preserving the services needed to keep physical processes safe.

The Australian Signals Directorate’s Australian Cyber Security Centre published the international CI Fortify guidance on 28 July. Developed with international partners and drawing on UK National Cyber Security Centre material, it sets out how operators can separate essential operational technology and supporting systems from other networks.

The guidance begins with identification of the minimum systems required to deliver a critical service. Operators are then asked to map every connection involving corporate systems, vendors, contractors, managed service providers, cloud environments, carriers, internet access, and peer infrastructure.

Emergency isolation is frequently described as a direct containment action, although industrial systems rely on communications that may be essential to safe operation. Disconnecting a network can remove telemetry, alarms, remote engineering support, identity services, certificate validation, time synchronisation, or information exchanged with another utility.

The boundary used during an incident may consequently differ from the boundary shown in a conventional network diagram. An operator may need to remove general internet access while retaining a controlled local engineering connection, or disable a supplier’s route without interrupting communications between sites.

The guidance recommends physical separation for the most vital systems where feasible, while recognising that complete disconnection may not work for geographically dispersed or internet-dependent infrastructure. Strong encryption and dedicated communications paths can support isolation where shared carrier networks remain unavoidable.

Operating after the boundary closes

Preparation requires a service-level definition of what remains essential. A system may support normal productivity without being required during a crisis, while a small service such as time synchronisation or alarm forwarding may be indispensable to safe operation.

Operators need to establish how long manual and degraded processes can be sustained. A facility may operate locally for several hours but require remote specialists, laboratory results, replacement parts, or central scheduling before several days have passed.

Isolation controls also need protection from the attacker. Network automation, software-defined networking, firewalls, and orchestration platforms may enforce separation, but the control plane becomes a target if the same compromised administrative environment can alter its policy.

Physical management interfaces, dedicated administrative zones, and privileged workstations can reduce that exposure. Where carriers or third parties support the management path, strong cryptographic controls and clear restrictions on remote administration are required.

The guidance recommends graduated isolation so that access can be removed in stages as the threat develops. Remote-worker connections may be disabled first, followed by local remote access, corporate links, lower-priority peer connections, and eventual complete isolation of the most vital systems.

Trigger points should be agreed before an incident and connected to operational authority. Plant managers, engineers, security teams, suppliers, and executive leadership need a common understanding of who can order isolation and which service consequences are acceptable at each stage.

Testing must cover the full set of vital systems rather than one device or network segment. Partial exercises may miss shared storage, identity, cooling, power, backup, or communications dependencies that appear only when the wider environment is disconnected.

An isolated environment develops new risks over time. Systems may stop receiving patches, external monitoring may disappear, and staff may rely more heavily on removable media. Reconnection can reintroduce malware or restore an access route before the organisation has validated the rebuilt systems.

European operators can incorporate the guidance into resilience work already required by critical-infrastructure and sector regulation. An isolation procedure confined to the network team will not address the safety, workforce, supplier, continuity, and regulatory decisions needed to operate for an extended period without normal connectivity.

×