CISA unveils a six-step blueprint for isolating critical infrastructure during cyberattacks
Most IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in a way that maximizes security and minimizes disruption.

Most IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in a way that maximizes security and minimizes disruption.
The short version
- Now, several global agencies are offering a step-by-step action plan, CI Fortify .
- “The end state must be to enable the continued operation of critical services in a state of isolation,” the guide emphasized.
- A six-step guide for locking down systems Cyber actors, particularly state-sponsored ones, are increasingly targeting operational technology (OT) systems to perform espionage or disrupt critical infrastructure such as power and water distribution.
What happened
As a result, some organizations have been forced to take their systems completely offline; for instance, this week CAF Bank suspended its online services due to a third-party software vulnerability, thus preventing the charities it serves from paying staff . Also this week, Minnesota Water Utilities’ OT services were disrupted in a coordinated cyberattack .
Why it matters
Assigning different degrees of criticality means segmenting networks, hosts, and systems into different zones based on their nature and threat exposure.
Summary by Nerd News Network. Read the full article at Network World via the links above and below.
