Risk management

Six steps to isolate critical OT systems and ensure continuity of service

August 4, 2026
10 min read

Key Insights:

  • American (CISA, FBI), Canadian, Australian and Kiwi government cyber security agencies have released joint guidance titled CI Fortify
  • A six step process helps critical infrastructure (CI) organisations take practical steps to isolate vital operational technology
  • The aim is to minimise operational disruption and be able to operate in isolation for an extended period
  • By following the guidance, companies can identify critical systems, map connections and implement effective separation points
  • The aim is to ensure nation states are prepared to handle escalating cyber threats as geopolitical crises continue to grow.

Six steps to identify and protect critical systems

The global FVEY partner agencies have just released new guidance for critical infrastructure operators as attacks on CNI providers in some parts of the world have been escalating.

State-sponsored cyber actors routinely target critical infrastructure to pre-position for disruptive and destructive effects in the event of crisis or conflict with power and water sectors threatened.

Many providers also hold significant data on customers and thus cybercriminals may seek to extort victims via data exfiltration or by conducting ransomware attacks to take out services or cause harm.

By identifying and isolating key systems, these companies can improve both their risk position and chances of continuing to service key customers without major impacts to delivery.

Effective isolation plans also help to contain incidents and provide time to restore and recover assets.

Critical path for safety

The guidance provides an easy to follow 'critical path to isolation':

FVEY guidance on isolating and protecting CNI

Distilled down into a simple to follow pathway, there are six stages to work through:

  1. Identify vital systems and networks
  2. Identify critical customers
  3. Identify common levels of criticality and trust for networks and hosts
  4. Map connections to vital systems and identify potential isolation points
  5. Build effective separation and isolation points
  6. Create and test an isolation plan

Get ready to secure a Minimum Viable Company

OT operators begin by identifying the systems and networks that support the critical service(s). These become the minimum set of systems and networks required to deliver services, sometimes referred to by resilience experts as a Minimum Viable Company (MVC).

Nominated lifeline services and existing SLAs may help to ensure all key customers and supporting technologies have been mapped.

In a mature organisation undertaking active risk management, a properly segmented network, hosts and systems may have already been grouped into segments and zones with a common level of criticality, and similar threat exposure to provide zones and trust boundaries to defend.

Get ready to isolate (and invest)

The challenge then is to identify points of interconnection between these high trust zones and non-critical operations, cloud services, DMZs or bastion hosts that enable remote vendor access.

Documenting architectures and connectivity, understanding dependencies is a key activity as isolating systems may trigger manual processes and interrupt system-to system communication across boundaries.

Documenting any possible impact through severing connections to upstream and downstream dependencies, an organisation can be sure to know what may fail and/or require a workaround.

Organisations must then build physical isolation points to protect these vital systems and enable the capability to operate in a state of isolation from all other networks and systems.

CI operators must assess and eliminate dependencies between their OT and non-vital OT systems to ensure physical isolation does not create any unforeseen performance issues resulting in the outage of the critical service

With connectivity and shared infrastructure across vital systems and non-vital systems a problem, the FVEY partners note that achieving this capability will require time and resource investment.

FVEY isolation measures to fortify your business

A how to guide to isolate and test

The report provides substantial practical advice on how to implement physical separation and isolation readiness for operators that may have assets spread across a broad regional or national footprint, guidance that touches on Layer 2 and 3 services and effective encryption practices.

Planning then to activate these controls is key and a graduated approach is suggested to ensure any isolation plan is aligned with the business mission and functional requirements.

A graduated plan then balances the risk impact against the disruptive impact of shutting down connections and isolating services with trigger criteria set out and agreed in the company IR plan. An example graduated response is provided:

  1. Disable remote vendor OT access
  2. Disable on-premises remote access to OT environments
  3. Isolate all connections between non-OT and OT environments
  4. Isolate lower priority connections between peer OT environments.
  5. Isolate the critical OT environment and all vital systems completely

Testing these plans and triggers is critical and the procedure must continue to be validated on a regular basis.

Mitigating isolation risks

The US-led cyber security guidance acknowledges the potential for isolation risks and allows for half measures where total isolation cannot be realistically (or affordably) achieved.

Adopting isolation measures does of course introduce possible new operational and security risks including systems falling out of patch, reduced external visibility and the increased risk of infected removable media affecting a system where USBs are used to move files across air gaps.

Hardening the IT/OT boundary may be the only pragmatic option if full isolation cannot be delivered.

All up, it's a useful reminder for critical infrastructure operators of the need to revisit evolving cyber risks and plan accordingly. The six isolation steps may take time to work through fully, but they can help refresh institutional knowledge, revise documentation and ensure that plans are made to respond accordingly.

Read the full guide at CI Fortify - Advice for isolating vital systems.

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo