Key Takeaways
- Critical infrastructure operators can't prevent every cyberattack, but knowing how to fortify and isolate vital OT systems while under attack allows them to keep delivering essential services while disconnected.
- Published July 28, 2026 , and led by Australia's ASD's ACSC, CI Fortify is joint guidance co-sealed by agencies across the Five Eyes countries (Australia, Canada, New Zealand, the UK and the U.S.) that provides a detailed, six-step path to OT isolation readiness.
- Effective isolation requires advance planning, tested separation points, clear decision authority, and security monitoring that keeps working when cloud or external connectivity is unavailable.
- Nozomi Networks supports CI Fortify on both sides of the isolation line: Guardian on-prem sensors provide local visibility and detection when the cloud isn't reachable, and Vantage provides centralized, remote visibility wherever an approved cloud connection remains.
Anyone who has boarded up ahead of a hurricane already knows the lesson at the heart of modern critical infrastructure security: some threats can't be prevented, only outlasted. You don't stop the force of nature; you engineer to endure it. Storm shutters and strapped-down roofs, generators on standby, go-bags packed. Prepare in the calm, because there is no negotiating with the crisis once it arrives. None of that stops the storm. All of it means essential life keeps functioning when the storm arrives anyway.
That's exactly the mindset behind CI Fortify, one of the most important pieces of critical infrastructure guidance to come out of the Five Eyes countries this year, and a mindset the operational technology (OT) community everywhere needs to internalize fast.
What Is CI Fortify? Resilience Over Prevention
CI Fortify is joint government guidance, published July 28, 2026, that gives critical infrastructure operators practical steps to isolate vital OT and enabling systems from all other networks during a cyber incident or crisis, and to keep delivering essential services while disconnected.
The guidance, CI Fortify: Advice for Isolating Vital Systems, was led by the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) and issued jointly with the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the United Kingdom's National Cyber Security Centre (NCSC-UK), the Canadian Centre for Cyber Security (CCCS), and New Zealand's National Cyber Security Centre (NCSC-NZ).
One point of accuracy worth making up front: the participating countries are the Five Eyes countries, but this isn't a Five Eyes intelligence assessment. It is public, unclassified defensive cybersecurity guidance jointly issued by national cybersecurity and security agencies across Australia, the United States, the United Kingdom, Canada, and New Zealand. Five Eyes began as a signals-intelligence arrangement and has since grown to include broader intelligence cooperation, but that's not what this is. This is actionable advice meant to be implemented by defenders and operators, not a threat briefing.
The premise is refreshingly blunt. State-sponsored actors are no longer just knocking on the door. Some are already inside, quietly pre-positioning. U.S. agencies have documented adversaries like Volt Typhoon sitting undetected in critical infrastructure networks for years, in some cases as long as five, in a pattern they assessed as consistent with pre-positioning for disruptive or destructive activity during a major crisis or conflict.
The geopolitical backdrop matters, but the point does not depend on any prediction. Western agencies have consistently tied this pre-positioning to the possibility of a future crisis or conflict, and public readiness debates have attached dates and milestones to adversary capabilities. None of that amounts to a planned attack or a date on the calendar, and guidance like CI Fortify doesn't need one. Pre-positioning requires only quiet options, established in advance, ready to disrupt essential services if a crisis ever comes. That's precisely why operators can't assume they will keep every attacker out.
CI Fortify leads naturally to a blunter operational question, one every critical infrastructure operator should have to answer:
If you had to isolate your vital OT systems in the next ten minutes, cutting them off from corporate IT, the internet, cloud services, and third-party vendors, could you? And could you keep delivering your essential service while disconnected, for days or weeks, not hours?
That's the hurricane question, applied to cyber. Not “how do I keep the storm from ever forming,” but “when it hits, can I keep the lights on.”
CI Fortify lays out a six-step path to get there:
- Identify vital systems: the minimum OT and enabling systems required to keep the critical service running.
- Identify critical customers and upstream dependencies.
- Set criticality and trust levels across networks and hosts.
- Map every connection into your vital systems: corporate IT, vendor remote access, cloud platforms, internet-facing services, and other operators.
- Build separation and isolation points in advance, with authorization and trigger criteria defined before the incident, not improvised during it.
- Create and test a graduated isolation plan that progressively cuts connectivity as the threat escalates: remote workers and vendors first, then corporate connectivity, then connected systems and external links, with the most vital systems fully isolated as the target state.
The agencies are candid that physical isolation is the most effective form of protection, a full air gap being the purest example, but complete physical separation is impractical for most modern operators that depend on carrier networks, cloud services, geographically distributed facilities, and outside support. So the real deliverable is the capability to isolate quickly and, just as important, to keep operating in that isolated state for an extended period; the companion Australian CI Fortify program benchmarks the ability to run vital systems in isolation for up to three months.
And that capability has to be tested. An untested isolation plan can take down the very things operators need in a crisis: safety systems, authentication, engineering workflows, time synchronization, logging, communications. Exercises should validate the technical steps, the decision process, the staffing model, the manual alternatives, and the conditions for restoring connectivity. A plan that has never been rehearsed is a plan you'll be improvising during the storm.
Which raises the point that too many isolation plans miss entirely.
The Piece Everyone Forgets: OT Security Visibility During Isolation
Here’s the trap. Isolation is only useful if you can still defend the environment once you’ve pulled up the drawbridge. But for a lot of organizations, the moment they sever the internet and cloud connections, their security tooling goes dark right along with the attacker's command-and-control channel. They isolated the plant and blinded their selves in the same motion.
It’s the equivalent of boarding up your house for the storm and then discovering the flashlights don't work. You did the hard part and still lost the ability to function anyway.
The guidance itself anticipates this: CI Fortify specifically calls for post-isolation checks, including routing-table inspection, network-flow monitoring, and intrusion detection. If your monitoring depends entirely on external connectivity, disconnecting a facility blinds the security team at exactly the moment visibility matters most. You lose current asset information, anomaly detection, forensic evidence, and even confirmation that the isolation controls themselves are working, right when you also need to distinguish malicious behavior from the unusual traffic that comes with running in a degraded state.
Resilient security means your visibility and detection survive the isolation event, no matter where the failure happens, and no matter where your people are standing when it does. Decide in advance which telemetry must remain available locally, how logs and evidence will be retained, which management functions can operate offline, and how data will synchronize when connectivity returns.
Guardian and Vantage: Security on Both Sides of the Isolation Line
This is where resilient architecture stops being a slogan and becomes a design decision. The goal is straightforward: your security operations should keep running whether or not the cloud is reachable, and whether your people are inside the fence or working from home.
Inside an isolated facility: your Nozomi Guardian sensors keep working. Guardian is deployed on-premises and does its core work locally: asset visibility, network monitoring, anomaly and threat detection, and analysis of what is actually happening on the wire. Those core functions do not depend on a live cloud connection, and Guardian can run in fully on-premises and even air-gapped deployments. So when a facility cuts external connectivity as part of graduated isolation, it doesn't have to go dark. Defenders on-site keep local visibility and detection through the event. Some things that ride on upstream connectivity, like certain threat-intelligence updates or cloud synchronization, will pause until connectivity returns, but the local monitoring and detection loop keeps running. You isolate, and you stay sighted.
Where approved connectivity remains: Vantage gives you the centralized, remote view. Vantage is our cloud platform, and it aggregates data from connected sensors so authorized people, an analyst at home, an incident responder in another city, a leader in the emergency operations center, can see the environment without standing on the plant floor. The honest caveat matters here: Vantage can only show what can reach it. If a site is placed into complete physical isolation, new live telemetry does not cross that boundary, and it shouldn't, because that is the entire point of isolation. Remote visibility depends on a communications path being deliberately and safely retained, whether that is normal connectivity outside a crisis or an approved one-way or segmented path engineered for it.
So skip the absolutes. The point isn't that cloud visibility magically survives a full air gap. It is that a resilient architecture gives defenders options on both sides of the isolation boundary: local monitoring built to survive disconnection, and centralized cloud visibility wherever approved connectivity remains. Isolation should not automatically mean blindness, and with the sensing done locally, it doesn't have to.
That's what operating in isolation for an extended period actually requires: not just the ability to cut the cord, but the confidence that cutting it does not cost you your eyes.
One Set of Guidance, Five Countries
The guidance is coordinated internationally, but each country brings its own institutions, terminology, resilience programs, and reporting lines that operators actually work through. If you operate across borders, or answer to regulators in more than one of these jurisdictions, it helps to know which door is which:
The guidance itself is shared. What changes country to country is the institutions, terminology, and reporting structures operators use to apply it. So wherever you operate, map the advice back to your own national agency and regulator.
CI Fortify Checklist: Questions to Answer Before You Have to Isolate
CI Fortify provides the framework, but every critical infrastructure site is different, and it raises questions only local operators can answer. Put these to your own team, in the calm, before the season starts:
- What minimum level of service must we sustain, and for which customers?
- Which OT, safety, identity, engineering, communications and support systems are truly vital?
- Do we have an accurate map of every connection into those systems?
- Who can authorize isolation, and what events trigger each stage?
- Can operators use manual or alternative control paths if normal systems are unavailable?
- Will local monitoring, logging and evidence collection continue after disconnection?
- How long can the site operate without cloud services, vendor access or normal supply-chain support?
- When did we last test the plan under realistic conditions?
Every unanswered question on that list is a finding. Close it now and it costs a project; find it mid-incident and it costs the service.
CI Fortify FAQ
Who published CI Fortify?
CI Fortify: Advice for Isolating Vital Systems was published July 28, 2026. The effort was led by the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) and issued jointly with CISA and the FBI in the United States, NCSC-UK, the Canadian Centre for Cyber Security, and NCSC-NZ.
Does CI Fortify require a full air gap?
No. The agencies note that physical isolation is the strongest protection but impractical for many modern operators. The guidance instead calls for pre-built separation points and a graduated isolation plan that progressively cuts connectivity as a threat escalates, using isolation methods appropriate to each architecture.
How long should operators prepare to run in isolation?
The guidance emphasizes operating in isolation for an extended period, and the companion Australian CI Fortify program sets a concrete benchmark: the ability to isolate vital OT and enabling systems for up to three months while maintaining critical services.
What happens to security monitoring during isolation?
That depends on the architecture. Monitoring that relies on cloud or external connectivity goes dark when connectivity is cut, which is why CI Fortify calls for post-isolation checks like network-flow monitoring and intrusion detection. On-premises sensing, such as Nozomi Guardian, continues local asset visibility and threat detection inside an isolated site, while a cloud platform like Vantage provides centralized visibility wherever an approved communications path remains.
Summary: Prepare in the Calm
Anyone who has watched a hurricane, a cyclone, or a fire front bear down knows the drill by heart: the time to prepare is never during the storm. Nobody goes looking for the generator when the power is already out, and nobody writes a survival plan when the sky has already turned orange. Preparation happens in the calm, so that when the storm hits, the response is muscle memory.
CI Fortify is telling critical infrastructure operators the same thing, in the same spirit. No operator will prevent every intrusion. Capable adversaries have pre-positioned inside critical infrastructure and waited, sometimes for years, for a moment that may never come but that they intend to be ready for. So build for the moment you have to disconnect, and make sure that when you do, you can still see, still detect, and still deliver your essential service.
At Nozomi Networks, that's the whole point of how we are built: local sensing that survives disconnection, and centralized visibility wherever approved connectivity remains. Isolation should be a control you can reach for, not a switch that turns off your own defenses.
When the storm hits, you should still be able to see. Build for that.

.webp)




