← Blog · · df00tech

CISA and Australia Urge Critical Infrastructure to Plan for OT Isolation During Cyberattacks

security-news advisory

What happened

CISA, alongside Australian government partners, has published new guidance advising critical infrastructure operators to prepare in advance for isolating vital operational technology (OT) systems in the event of a cyberattack or other major disruption, according to a report from BleepingComputer.

The advisory reportedly focuses on planning ahead of time so that essential systems can be segmented or taken offline quickly without causing cascading failures to physical processes, rather than reacting improvisationally during an active incident.

Why it matters for defenders

Critical infrastructure environments (energy, water, manufacturing, and similar sectors) often run OT and industrial control systems where uncoordinated isolation can itself cause safety or availability problems. Guidance like this signals that regulators view isolation readiness as a gap many organizations currently have — meaning incident responders are frequently forced to improvise network segmentation decisions live, under pressure, with incomplete documentation of dependencies.

Organizations that operate or oversee converged IT/OT environments, including asset owners, MSSPs, and OT security teams, are the most directly affected by this guidance.

What defenders should watch for or do now

  • Review and document IT/OT network architecture, including data flows and dependencies between business systems and control systems, so isolation boundaries are known ahead of an incident.
  • Validate that segmentation controls (firewalls, data diodes, VLAN boundaries) can actually be enforced or tightened on short notice without requiring vendor involvement.
  • Establish and rehearse a documented isolation runbook — who has authority to trigger it, what systems get isolated first, and how safety-critical processes are maintained during isolation.
  • Test communication and monitoring continuity plans for the period when isolated OT segments may have reduced visibility from central SOC tooling.
  • Incorporate isolation drills into tabletop exercises alongside incident response and business continuity planning.

Developing story

This item is based on a single news report and reflects government guidance rather than a specific incident, vulnerability, or confirmed attack. Details of the full advisory's technical recommendations were not covered in the source material reviewed. For the original reporting, see BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.