CISA and the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), in collaboration with the Federal Bureau of Investigation, have released CI Fortify — a resource package providing advice on isolating vital systems within critical infrastructure environments.
This guidance addresses operational technology (OT) environments where isolation strategies can reduce attack surface and contain compromise. The release signals coordinated international recognition that air-gapping and network segmentation remain foundational to infrastructure resilience, particularly as cyber threats against industrial control systems and SCADA networks continue to evolve.
For preparedness professionals, the significance lies in official validation of isolation protocols as a defensible posture. Rather than treating segmentation as optional hardening, CISA and ACSC are positioning it as a core control architecture. This suggests both agencies view the threat environment as requiring more than perimeter defense alone.
The low severity classification reflects the nature of the signal itself — guidance, not an active incident or vulnerability exploit. However, the joint U.S.-Australia coordination and focus on OT environments indicates these authorities are tracking persistent pressure on industrial systems and energy infrastructure.
Critical infrastructure operators, facility managers, and enterprise security teams should treat CI Fortify as a baseline reference for network design decisions, particularly for systems controlling physical assets, energy distribution, or safety-critical functions. Organizations running legacy OT systems without segmentation face compounding risk as threat actors continue to develop industrial control system exploits.
The release emphasizes that isolation is not a binary choice — partial segmentation, monitored air-gaps, and unidirectional data flows all provide meaningful protection when implemented alongside monitoring and incident response capability.

