The United States Cybersecurity and Infrastructure Security Agency (CISA), along with the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre and other security and law enforcement partners, has released new cyber security guidance for critical infrastructure operators.
CI Fortify – Advice for isolating vital systems aligns with CISA’s CI Fortify initiative and is designed to assist critical infrastructure entities prepare to isolate their operational systems in the event of a crisis or cyber security incident.
“State-sponsored cyber threat actors are increasingly targeting critical infrastructure for pre-positioning,” CISA and its partners said in a 28 July update.
“By physically isolating vital OT and enabling systems, CI operators and defenders can disrupt adversaries, contain attacks in progress and rebuild compromised systems.”
The guidance includes practical step-by-step long-term advice alongside temporary solutions for organisations that cannot physically isolate their systems. The latter, however, remains the best advice to keep systems secure.
Sean MacKirdy, area vice-president of national security at Fortune 500 firm Elastic, said the guidance is a “continued evolution in how our Five Eyes cyber security leaders are framing critical infrastructure security”.
“Effective isolation depends on effective visibility – knowing what to isolate, when and how to preserve the communications that keep critical services running. Isolating vital OT systems can impact business processes and any automated processes will most likely need to be completed manually during the period of isolation,” MacKirdy said.
“This is where broad, unified IT infrastructure visibility becomes a strategic capability rather than a nice to have.”
MacKirdy added that where citizens may be directly impacted by critical infrastructure outages, accelerated threat detection and containment should be a key priority.
“CI Fortify emphasises that preparation is key. CI operators should be building isolation and recovery capabilities now by ingesting and correlating logs, endpoint telemetry, network data and alerts across both IT and OT environments, helping defensive cyber teams map the dependencies between IT and OT support systems,” MacKirdy said.
“By having full visibility into this security data, organisations establish a baseline, making anomalies far easier to spot during periods of heightened threat.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.
David Hollingworth
David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.