CISA and Australia's cyber agency have released a detailed operational guide for physically isolating critical infrastructure during cyberattacks, with urgent lessons for India's power, water and telecom sectors.

CISA, Australia Unveil New Guidance on Isolating Systems Mid-Cyberattack

The420 Web Correspondent
8 Min Read

The United States Cybersecurity and Infrastructure Security Agency and Australia’s Cyber Security Centre have jointly released a detailed operational guide urging power grids, water treatment facilities, telecommunications networks and other critical infrastructure operators to plan, rehearse and execute the physical isolation of vital systems before a cyberattack forces them to improvise under pressure. Released on 28 July, the guidance titled “CI Fortify: Advice for Isolating Vital Systems” was developed in coordination with the FBI and other international Five Eyes partners and represents one of the most specific public documents either government has produced on the operational mechanics of protecting industrial control infrastructure during an active cyber incident.

The timing of the guidance is not coincidental. State-sponsored threat actors, particularly Chinese groups tracked as Volt Typhoon and Salt Typhoon, have spent years embedding themselves in critical infrastructure networks across the United States, United Kingdom, Canada, Australia and beyond, in what Western intelligence agencies assess as pre-positioning for disruptive attacks during a future geopolitical crisis or military conflict. Volt Typhoon remained undetected inside at least one US critical infrastructure network for five years. Salt Typhoon compromised major US telecommunications providers including AT&T, Verizon and Lumen, gaining access to law enforcement wiretap systems. These are not theoretical scenarios. They are documented incidents in which attackers had already achieved the access required to cause severe disruption, and chose not to trigger it yet.

For India, which operates a rapidly expanding digital infrastructure across power, water, rail, telecommunications and banking sectors and which has seen documented intrusion attempts against its critical systems from state-linked actors, the CISA-ACSC guidance carries direct and pressing relevance. India’s Computer Emergency Response Team, known as CERT-In, and the National Critical Information Infrastructure Protection Centre have frameworks for incident response, but a public operational blueprint of this specificity for physical isolation procedures does not yet exist in the Indian context.

What the Guidance Actually Recommends

The core argument of the CI Fortify document is that isolation planning must happen before an attack, not during one. Organisations that attempt to determine how to disconnect vital systems while an intrusion is actively underway face compounded risks: attackers may already have positioned themselves to prevent or monitor disconnection attempts, and the operational pressure of a live incident dramatically increases the likelihood of errors that leave critical systems partially exposed.

The agencies recommend that critical infrastructure entities first identify the minimum systems and networks required to continue delivering a critical service. Organisations should then document every connection between those systems and corporate networks, remote-access services, cloud environments, internet-facing infrastructure, vendors and contractors, and other critical infrastructure operators. They should also determine where those connections can be disabled or physically disconnected, and account for the manual processes, communication failures, and loss of external resources that isolation may trigger.

The guidance introduces a graduated isolation model, ranging from the most stringent physical isolation, in which vital systems are completely disconnected and share no network or computing infrastructure with non-critical systems, to administrative network controls using VLANs and access-control lists as temporary measures. Physical isolation is described as the most effective form of protection, but the agencies acknowledge it may not be practical for organisations that depend on internet-facing services, carrier networks or geographically distributed facilities. In those environments, strengthened network boundaries, dedicated encrypted communications links and the removal of unnecessary dependencies on corporate systems are recommended alongside the ability to rapidly rebuild systems if required.

Isolation plans should also define who can authorise each step, the conditions that would trigger it, which systems must remain available, and how operations will continue without normal network connectivity.

Why India Cannot Treat This as Somebody Else’s Problem

India has had direct experience with the category of threat the CISA guidance is designed to address. In October 2020, a cyber intrusion linked to a Chinese state-sponsored group caused a major power outage in Mumbai, knocking out electricity to the Brihanmumbai Electric Supply and Transport grid, the Bombay Stock Exchange and several hospitals. A subsequent analysis by threat intelligence firm Recorded Future identified pre-positioned malware in the networks of seven Indian State Load Despatch Centres and two Indian ports, suggesting a sustained effort to map and infiltrate energy and logistics infrastructure.

AIIMS Delhi suffered a ransomware attack in November 2022 that paralysed hospital operations for over two weeks, exposing the vulnerability of healthcare infrastructure to cyber disruption. The Indian Railway Catering and Tourism Corporation has experienced multiple data breach incidents. Each of these cases illustrates the same vulnerability the CISA guidance is designed to address: critical services whose continuity depends on digital infrastructure that has not been tested for its ability to operate in isolation.

India’s National Critical Information Infrastructure Protection Centre maintains a list of protected sectors and coordinates cybersecurity frameworks with operators of essential services. CERT-In issues directives and advisories, including the mandatory six-hour breach reporting rule introduced in 2022. But the gap between regulatory frameworks and operational preparedness at the facility level, specifically the ability of a power substation operator or a water treatment plant to physically disconnect from broader networks within minutes of an attack being detected, remains significant across many sectors.

The Specific Vulnerabilities the Guidance Targets

The agencies warn that isolation also introduces its own risks, including systems falling behind on security updates, reduced monitoring capacity, and increased use of removable media to transfer data between isolated and non-isolated systems. Organisations must therefore prepare not only to disconnect vital systems, but also to operate, monitor and update them manually until they can eventually reconnect.

The guidance specifically flags the danger of partial testing, in which organisations verify that individual systems can be isolated without testing whether the complete isolation of a facility’s vital systems reveals hidden shared infrastructure or dependencies. A firewall that appears to separate operational technology from corporate networks may in practice share a management interface, a logging server or an authentication system with non-critical infrastructure, meaning an attacker with access to the corporate network retains a pathway into the supposedly isolated environment.

The document recommends keeping a secure offline or printed copy of the isolation plan so that it remains accessible even if corporate network access is disrupted during an attack, a detail that reflects how completely the guidance is grounded in the realities of active incident response rather than normal operating conditions. For Indian critical infrastructure operators and regulators, the document provides a practical framework for the kind of pre-emptive operational resilience planning that cybersecurity experts have been recommending for years and that state-sponsored intrusion campaigns are increasingly making urgent.

Stay Connected