Critical infrastructure operators now have a playbook for the worst-case scenario: disconnect your industrial systems from the internet, corporate networks, cloud services, and vendor remote access—and keep water flowing, power humming, and trains running. A joint guidance released by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), and international partners on July 28, 2026, outlines how to isolate vital operational technology (OT) and maintain a safe minimum service for an extended period during a national-level cyber crisis.

The document, titled CI Fortify – Advice for isolating vital systems, moves beyond traditional incident response. It does not treat network isolation as a last-resort emergency cable-pull. Instead, it demands that operators engineer isolation in advance, prove that critical functions can survive without the digital dependencies most sites have accumulated over decades, and rehearse the process until it becomes a practiced capability.

What the Guidance Actually Says

At its core, the 14-page document is a practical implementation framework. It walks organizations through a structured path: identify the smallest set of systems and networks required to deliver a critical service, map every connection that ties those systems to the outside world, design separation points, and then test and document the ability to operate in a disconnected state. CISA and its partners are not simply advising better firewalls. They are asking a far harder question: can your most essential operations run if you lose corporate identity systems, cloud management tools, vendor remote support, shared storage, centralized DNS, external time synchronization, carrier networks, and even normal communications with suppliers?

The guidance explicitly positions isolation as a method to maintain service continuity, contain active incidents, disrupt an attacker’s ability to pivot, and create a safer environment for rebuilding compromised systems. It also introduces a graduated approach—rather than a binary “connected or air-gapped” switch, operators are told to define trigger criteria and progressively remove pathways into vital OT as the threat environment worsens. An illustrative sequence for an electrical transmission operator starts with disabling remote-worker access and ends with full isolation of the OT environment.

Notably, the document acknowledges that complete physical separation may be infeasible for geographically distributed infrastructure or operations that must communicate externally. In those cases, it pushes for hardened boundaries, dedicated communications paths, and strong cryptographic protections run on independently managed encryption devices—because carrier services, the guidance warns, should be treated as untrusted and potentially hostile.

What This Means for Your Organization

If you run a water plant, manufacturing shop, pipeline, or power substation, the message is unambiguous: your resilience planning must assume that in a severe incident, you will lose every external connection on which daily operation now depends. The guidance sets a high bar, aligning with Australia’s earlier CI Fortify target of maintaining isolated vital OT for three months while also preparing to fully rebuild those systems.

For Windows administrators and infrastructure architects, the implications are immediate and uncomfortable. Many OT environments rely heavily on shared enterprise Windows services—Active Directory for authentication, Group Policy, DNS resolution, DHCP, SQL Server for historians, Hyper-V or VMware for virtualization, file servers for configuration backups, and centralized patch management. A single domain controller or DNS forwarder that services both the corporate LAN and an industrial control network can become the invisible thread that unravels an isolation plan. The guidance specifically calls out Active Directory, DNS, DHCP, PKI, certificate services, and time synchronization as common sources of dependency that must be documented and addressed.

Security teams will need to lead the dependency-mapping effort, but they cannot do it alone. Plant engineers, operations staff, and IT admins must collectively decide what “minimum viable service” means—not every system is vital. A corporate reporting portal is nice to have, but a modest Windows application server hosting an engineering utility or local authentication role might be essential. The guidance mandates identifying critical customers and setting a measurable service-delivery target (e.g., 15 million gallons of water per day), then working backward to find every system, network segment, and human role required to hit that target.

How We Got Here: From Cyber Threats to Resilience Planning

This guidance didn’t appear in a vacuum. It is the latest piece of the broader CI Fortify initiative, kicked off by Australia’s ACSC in 2025, which first articulated the idea that critical infrastructure must be able to isolate vital OT and enabling systems for an extended period and then rapidly rebuild them. The U.S. and international partners have now deepened that concept into a technical specification.

The threats driving this shift are well documented: state-sponsored actors probing critical infrastructure for pre-positioning, ransomware groups targeting industrial operators for extortion, and the growing realization that conventional perimeter defenses cannot keep motivated adversaries out of complex OT/IT converged environments. The guidance reflects a sober assessment that an intrusion may not be detectable before it escalates. Therefore, organizations must be prepared to sever digital connections on short notice without causing operational chaos.

Six Actions to Take Now

CISA’s advice is most valuable when translated into immediate work streams. Here is how to start.

1. Define your minimum viable service. Assemble operations and engineering leaders and force a concrete definition of what must keep running and for which dependent customers. Use metrics: water volume, electrical load, patients served. This becomes the North Star for every isolation decision.

2. Map every dependency, especially Windows infrastructure. Create a living diagram of all interconnections between vital OT and the outside world. Go beyond TCP/IP routes—document dependencies on Active Directory, DNS forwarders, network time sources, certificate enrollment points, virtualization management planes, file shares, and licensed software that requires cloud activation. Record owners, failover paths, and restoration time objectives.

3. Design true isolation points. Start by distinguishing between physical separation (no shared infrastructure) and logical isolation (which can be changed by a misconfig or compromised admin credential). Where full separation isn’t possible, deploy dedicated encryption devices for carrier links, use data diodes for one-way telemetry outflows, and harden management interfaces. The guidance squarely warns against relying on VLANs as a permanent solution—they can be bypassed if the control plane is compromised.

4. Build a graduated isolation playbook. Write clear trigger criteria tied to incident severity levels, and predefine steps that can be executed by authorized personnel. Example steps include disabling specific VPN groups, blocking remote management protocols at designated boundaries, suspending vendor accounts, transitioning to local authentication, and disabling cloud synchronization. Every step must be reversible and auditable.

5. Test isolation under realistic conditions—and test all vital systems. CISA explicitly recommends testing isolation of every vital system periodically, not just a convenient subset. An exercise must prove that minimum service targets are met, safety controls behave correctly, manual workflows are staffed, essential credentials and tools remain accessible offline, and the organization can detect accidental reconnections. Store secure offline hard copies of plans and procedures; online repositories may be unavailable during an incident.

6. Plan for reconnection as a security event. Isolation is not the end. Reconnecting a previously isolated environment can reintroduce threats, overwrite local configurations, or restore vulnerable remote-access paths. Define an authority model, a staged restoration sequence, and a validation process that includes traffic monitoring, credential review, and configuration comparison.

What’s Next

Expect this guidance to influence regulatory expectations and audit frameworks for critical infrastructure sectors. The Department of Homeland Security’s performance-based cybersecurity directives already push operators toward resilience metrics, and CI Fortify provides a concrete template. Organizations that ignore it risk more than a security incident—they may face penalties for failing to meet due-care standards. For Windows-centric shops, the real challenge will be untangling years of organic IT/OT convergence, and doing so before a crisis forces the issue. The guidance’s most urgent lesson: the time to discover your true dependencies is not at 2 a.m. on the night of a nation-state attack.