ProBackend
advanced persistent threats apts
1 minute ago6 min read

AI Cybersecurity Threats: CISA and Australia Urge Critical Infrastructure Isolation Plans

CISA, ACSC, and FBI released joint guidance urging critical infrastructure operators to prepare isolation plans for vital OT systems ahead of state-sponsored attacks, detailing physical and graduated isolation strategies.

AI Cybersecurity Threats: CISA and Australia Urge Critical Infrastructure Isolation Plans

The U.S. and Australian governments just dropped something that should make every critical infrastructure operator sit up and pay attention. CISA, the FBI, and Australia's ACSC published joint guidance titled CI Fortify – Advice for isolating vital systems, and it's blunt about what's coming: state-sponsored hackers are already inside your networks, and they might not be there for espionage. They're positioning for the moment when disruption becomes the objective.

The advisory came out July 28, 2026, and it's aimed squarely at organizations that operate water treatment plants, electrical grids, manufacturing facilities, transportation networks, and telecommunications infrastructure. These aren't theoretical scenarios. American Water deactivated systems after a cyberattack affecting over 14 million people. A Kansas water treatment facility went fully manual after compromise. Russian hacktivists have been actively hunting unsecured OT systems in water facilities. The window for preparation is closing.

Understanding the AI Cybersecurity Threats Landscape

State-sponsored threat actors don't just want access — they want persistence. The guidance frames this clearly: espionage establishes the foothold. Disruption is the endgame.

Take Volt Typhoon, the Chinese group that breached organizations across communications, energy, transportation, and water sectors back in early 2024. CISA, the FBI, and the NSA warned about it, along with other Five Eyes agencies. What made it particularly alarming? The hackers went undetected in at least one critical infrastructure network for five years. Five years. They weren't causing damage — they were waiting.

Then there's Salt Typhoon. Since 2011, this Chinese state-sponsored group has breached government, telecommunications, transportation, lodging, and military networks worldwide. They compromised AT&T, Verizon, and Lumen — major U.S. telecom providers — gaining access to sensitive communications and law enforcement wiretap systems. They exploited known vulnerabilities in edge networking devices — similar to the enterprise exposure seen in the LegacyHive zero-day vulnerability — and used compromised equipment and trusted connections to pivot deeper into other networks.

These aren't isolated incidents. They're a pattern seen across both nation-state intrusions and corporate attacks like the Fairlife ransomware breach and rapid encryption campaigns like Spirals ransomware. The guidance acknowledges that cybercriminals opportunistically target critical infrastructure operators for exactly the same reasons: the sensitivity of the data and the importance of the services make them attractive for data exfiltration or ransomware attacks designed to disrupt or destroy.

The new CI Fortify guidance flips the script. Instead of figuring out how to disconnect vital systems while an attack is actively unfolding, organizations should prepare these plans before something happens.

Core Concepts and Terminology

The advisory introduces several key concepts that operators should already understand — or at least start understanding now.

Vital systems are defined as the minimum operational technology (OT) and supporting systems needed to deliver a critical service. Think controlling water distribution, delivering electricity, or operating a telecommunications network. The guidance pushes organizations to identify exactly what "minimum" means for their operations, not what's convenient.

Isolation point refers to a predetermined location where connectivity between critical and non-critical networks or systems can be disconnected. The purpose? Contain the attack and prevent lateral movement into other vital systems.

Physical isolation means completely disconnecting vital systems so they no longer share network or computing infrastructure with non-critical systems. The guidance calls this the most effective form of protection. Period.

Graduated isolation involves gradually restricting access as the threat level increases. Block remote workers and vendors first. Then disconnect corporate networks and connected systems. Eventually, cut all external connections. It's a stepping-stone approach when full physical isolation isn't immediately feasible.

Administrative network controls — things like modifying VLANs, access-control lists, and routing — are useful as temporary protections, the guidance notes, but physical isolation should always be the ultimate goal.

Data diodes are specialized equipment that allow data to flow in only one direction. They reduce the risk that malicious traffic can travel in reverse.

Post-isolation monitoring involves checking routing tables, network traffic, and intrusion detection systems to verify that isolation controls remain effective. Administrators should also secure the network management zones used to administer routers, firewalls, and other network infrastructure so they're isolated from attackers.

Building Your Isolation Strategy

The guidance lays out a clear sequence of steps, and honestly, it's the kind of thing that sounds obvious until you realize half your organization hasn't done it yet.

First, identify the minimum systems and networks required to continue delivering a critical service. Not everything. Just what's essential.

Second, document every single connection those systems have to corporate networks, remote-access services, cloud environments, Internet-facing infrastructure, vendors and contractors, and other critical infrastructure operators. Every one. This isn't optional.

Third, figure out where those connections can be disabled or physically disconnected. Then account for the manual processes, communication failures, and loss of external resources or dependencies that isolation will trigger. You can't just pull the plug and hope for the best.

The guidance also stresses that isolation plans need to define who can authorize each step, the conditions that would trigger it, which systems must remain available, and how operations will continue without normal network connectivity. That last part is critical — and where most organizations fall short.

Physical isolation provides the best protection, sure. But the agencies acknowledge it may not be practical for organizations that depend on Internet-facing services, carrier networks, cloud services, or geographically distributed facilities. In those environments, operators are advised to strengthen OT network boundaries, use dedicated or encrypted communications links, remove unnecessary dependencies on corporate systems, and maintain the ability to rapidly rebuild systems.

Testing, Documentation, and What Comes After

Here's something the guidance emphasizes that most organizations get wrong: test the complete isolation of your vital systems regularly. Not individual systems. Complete isolation.

Why? Because partial tests may fail to identify shared infrastructure and other hidden dependencies that could cause problems when you actually need to activate the plan. You won't know your systems are more tightly coupled than you think until you try to separate them.

The guidance also recommends keeping a secure offline or printed copy of the isolation plan so it remains available if access to corporate network or storage servers gets disrupted. Yes, a physical copy. In a world where everything lives in the cloud, that's a radical idea — and one that makes perfect sense when your network is compromised.

After systems are isolated, operators should continue monitoring network traffic, routing information, and management systems to ensure that unauthorized or accidental connections haven't restored access between critical and non-critical networks.

But here's the catch — and it's a big one. The agencies warn that isolation introduces its own risks. Systems fall behind on security updates. Monitoring gets reduced. There's increased use of removable media to transfer data between systems. Organizations must prepare not only to disconnect vital systems but also to operate, monitor, and update them manually until they can eventually reconnect.

It's not a silver bullet. It's a tradeoff. And you need to understand those tradeoffs before you make the decision to isolate.

What This Means for 2026 and Beyond

The CI Fortify guidance isn't just another advisory that gets filed and forgotten. It's a response to a clear and present danger. State-sponsored actors are already inside critical infrastructure networks. They've been there for years. And they're ready to cause damage when the time is right.

The question for critical infrastructure operators isn't whether to prepare isolation plans. It's whether they can do it quickly enough.

The guidance from CISA, ACSC, and the FBI is clear: stop treating isolation as an emergency response and start treating it as a preparedness requirement. Test it. Document it. Practice it. Because when the attack comes, you won't have time to figure out how to disconnect your vital systems from the rest of the network.

AI Cybersecurity Threats: CISA and Australia Urge Critical Infrastructure Isolation Plans

More blogs